Zero-knowledge proof that every piece of context injected into your AI prompt is a legitimate member of your corpus. Verifiable by you. Verifiable by your regulator. Trust the math, not us.
The fourth leg of XCALIBUR. Sits after AMPLIFY, before the response leaves the rail. Every injected corpus entry gets a Merkle inclusion proof. The whole certificate is signed under a post-quantum key.
The context injected into your prompt is a verified member of your committed corpus. Not fabricated. Not substituted. Provably yours.
The cryptographic boundary between tenants is enforced at proof generation. No other tenant's corpus can produce a valid proof against your commitment root.
Your original prompt content is hashed and bound into the certificate. The SHA3-256 commitment proves nothing was inserted, replaced, or modified before the LLM.
Attestation is a logging system. You trust their audit trail. You cannot independently verify corpus membership. Your regulator audits them — you don't verify the math.
No proof · trust requiredRAG frameworks inject context with no attestation layer. What went into the prompt is whatever the framework retrieved. No commitment, no proof, no receipt.
No attestationOn-chain attestation of identity claims. Not inference context. Not corpus membership. Not AI prompt integrity. Different problem, different layer.
Wrong layerMerkle-committed corpus. ML-DSA-65 signed root. Per-call inclusion proof. Caller-verifiable at public endpoint. No trust required. Post-quantum hardened. Patent Pending.
Only this existsAll paths under https://hivemorph.onrender.com. The proof verification endpoint is unauthenticated — auditors hit it directly.