AI SPEND ASSURANCE

Your AI vendors grade their own homework.
We take away the pen.

SEALED SAVINGS. PROVEN, NOT PROMISED.

TokenMark™ cuts your AI model spend — and is built so it cannot misstate what it saved. Every savings figure is countersigned by an independent attester and verifiable by your own auditors, offline, without us.

Do you even know which AI agents are running?

Start with the question nobody can answer

Grade your AI vendors. Do you even know which agents are running?

Every vendor will tell you their AI is safe, governed, and auditable. None of them can tell you which agents are running inside your environment right now, who approved them, what they can reach, or what they cost. The free Agent Index™ answers that in an afternoon — read-only, inside your own VPC.

WHAT A FIRST ASSESSMENT TYPICALLY RETURNS
Agents discovered11
Able to prove their origin and work7
Cannot prove anything — no approver, no purpose4
Annual spend by agents nobody owns$107,040
This is already happening at scale In August 2026 Cisco began rolling out a personal AI agent to all 90,000 of its employees — agents that act across mail, tickets and document stores on a stated objective, choosing their own model for each task. At that scale, “we govern our agents” stops being something any manual process can verify. Most enterprises will follow without Cisco’s in-house platform or budget.

Grade your vendors — free assessment See a sample findings report

START HERE

A real line on a real invoice.

INVOICE · YOUR CURRENT AI COST VENDOR · MARCH
Optimization fee — 20% of savings delivered $61,400
Savings the vendor reports it delivered$307,000
Verified by— that same vendor

Your finance team approves this every month. Nobody in your building can check the second number — and the vendor's fee is a share of it.

This is not one bad vendor. Every AI cost vendor on the market works this way: they hold the meter, they set the baseline the savings are measured against, and they sign the record. There is no third party in the arrangement.

The industry has begun organizing around the first half of this problem. In August 2026 the Linux Foundation launched the Tokenomics Foundation with thirty member organizations to build open standards for AI economics — definitions, cost models, and token cost telemetry. That work establishes what to measure. TokenMark™ addresses whether the measurement can be checked by anyone other than the party reporting it.

Where AI Spend Assurance sits inside tokenomics →

WHERE THE MONEY ACTUALLY GOES

Three leaks. One of them is much larger than the others.

Before anyone talks about verifying a savings figure, it is worth being concrete about what there is to save. Inference budgets leak in three places:

Resent context — the big one

The same background material shipped again on every call in a conversation. You pay full price each time for text the model has already been given. On most bills this is the largest single line of recoverable spend.

Unread spans

Material retrieved and attached to a request that the answer never draws on. Retrieval systems are tuned to over-fetch, because missing something is worse than sending too much — and you are billed for all of it.

Retried calls

Requests that failed, timed out, or came back unusable and were run again. The first attempt is billed exactly like the one that worked.

TokenMark™ addresses the first and largest of these in two ways — by not sending what is not needed, and, with the wider Atom Works™ portfolio, by not paying twice for what has already been supplied. Our patent filings cover attested memory and restoration of withheld material by reference, so context can be returned to a later request without going back to the source and paying for it again.

Estimate what these three cost you →

YOU ALREADY SOLVED THIS PROBLEM

Nobody lets the same person request and approve a wire.

In your finance function

One person initiates. A second person, with separate credentials, approves. The control is not that they promise to be careful — it is that the system will not let one person do both.

In your AI spend

One system does the optimizing. A second system, with separate credentials, certifies the result. The first cannot produce the second signature — not by policy, the machine denies it.

TokenMark™ is separation of duties, applied to the AI bill. The party that performs a transaction should not be the only evidence of it — a principle your auditors already apply everywhere else in your business.

THE PRODUCT

The doer cannot be the counter.

TokenMark™ installs with a single change — the API address your applications already use. From there, two strictly separated components do the work:

The Gateway — does the saving

Intercepts each model request and removes the three leaks above: context already supplied, material the answer will not use, and duplicate work. Every piece of context is recorded first, so anything withheld can be restored on demand — nothing is silently lost, and restoring it costs a lookup rather than a second retrieval.

The Attester — counts the saving

A separate service, under separate credentials, with its own keys. It independently re-checks every record and recomputes the savings figure from the record itself before countersigning. The gateway cannot produce this signature — the operating system denies it the key.

Your auditor — verifies both

A verification tool your team runs on your own machines, offline, with no TokenMark™ service present. It confirms both signatures and recomputes the figures. If a record was altered, it fails — loudly.

$ tokenmark-verify statement-2027-03.json --bundle policy.tmb VERIFIED digest=2e07003460a386e5... invariants re-executed: R-1, T-1, E-1, C-1, C-2 EXIT 0

Your invoice carries the record. You verify it before you pay it.

BUILT, NOT PROMISED

Running today. Refusing on cue.

The architecture isn't a diagram — it's a reference implementation with real privilege separation, demonstrated live to design partners.

# the gateway attempting to read the attester's signing key $ setpriv --reuid=tmgw --regid=tmgw --clear-groups cat /var/lib/tokenmark/attester/ed25519.key cat: /var/lib/tokenmark/attester/ed25519.key: Permission denied # verification of a sealed record, offline, no service running $ tokenmark-verify statement-2027-03.json --bundle policy.tmb both signatures valid · distinct privilege domains · invariants pass VERIFIED $ echo $? 0

See how verification works, and what failure looks like →

17/17conformance checks — tamper rejection, forged-record detection, unattested-record refusal
EACCESthe operating system denying the gateway's read of the attester key — the refusal, enforced below the software
EXIT 0independent offline verification by a party holding nothing but the record
0 telemetryruns entirely in your environment; prompt content never reaches us or anyone else
THE PILOT

Forty days to a number your auditors can recompute.

Deploy — days 1–5

Installed in your environment as two separated services. A deployment manifest proves the separation before any traffic flows — your team re-runs the check itself.

Baseline — days 6–10

Pass-through mode. Your real traffic establishes a measured consumption baseline. No estimates, no models — metered fact.

Measure — days 11–40

Optimization on. Every request sealed and countersigned daily. Latency reported alongside savings, always.

Verify — you, not us

Your engineers verify the full record set offline and the exit figure is drafted from verified records only. If the number doesn't survive your team, it was never a number.

WRITING

Why we think this is a category, not a feature.

Position paper

The Self-Graded Stack — the same scoring defect appears at the model layer, the cost layer, and the agent layer. One structure, three instances.

Briefing note

Isn't AI spend a rounding error? — the strongest argument against us, taken seriously and answered.

Buyer's checklist

Five questions to ask any AI cost vendor — including us. If a vendor can't answer the second one, nothing else matters.

Estimator

What did you pay for context you never used? — an itemized estimate from your monthly bill. Modeled, not measured, and the countersignature line is blank on purpose.

Verify it yourself

Do not take our word for it — what the verifier does, what a failed record looks like, and how to obtain the tool and a sample record.

For auditors

Testing a TokenMark™ record — six procedures your audit team can perform offline, without us present, and what the record does not assert.

THE COMPANY

A product of Atom Works™, Inc.

Atom Works™ builds attestation infrastructure for AI — systems designed on one principle: the machine that acts cannot be the machine that vouches for the action.

The portfolio spans attested memory for AI inference, provenance for coding agents, and governed agent marketplaces, protected by an active patent program and engaged with federal standards work on AI accountability records. Those pieces are not adjacent products — the memory and provenance work is what lets TokenMark™ return withheld context by reference instead of re-retrieving and re-paying for it, and the attestation engine is shared across all of them.

TokenMark™ applies that architecture to the question every CFO is now asking: what are we actually paying for, and how would we know?

CONTACT

Interested parties

Design-partner evaluations, platform and OEM inquiries, and investor conversations — one door for all three.

sales@amem.law

Or write to sales@amem.lawopen in Gmail.

The button opens your default mail app with a short template. Nothing is collected by this site.

Before you can control agent spend

You need to know which agents you have.

TokenMark™ meters spend against each agent’s attested record — proof of what it actually did. If your agents cannot prove that yet, start with the free Agent Index™: it finds every agent running in your environment, read-only, inside your own VPC.

1 · Index

Find every agent — containers, scheduled jobs, serverless, workflows, robots, credential-holding scripts. Free, read-only, nothing leaves your network.

2 · Attest

Issue creation records and countersign the work, so origin, authorization, and authority become provable to a third party.

3 · Meter

TokenMark™ caps and settles spend against that attested record. An agent that cannot prove what it did cannot prove what it owes.

Typical first finding: six figures a year spent by agents nobody owns. Four agents with no approver, no stated purpose, and live credentials to customer data. Free assessment · no procurement to start

Run the free agent assessment See a sample findings report

Programs & participation
NVIDIA InceptionMember
NIST Zero DraftsSubmissions filed
NIST AI 300-1Public comment
NIST NCCoEPost-Quantum Cryptography
Community of Interest
DOE Genesis MissionConsortium participant
Congressional Internet CaucusAdvisory Group — former member

Participation in an open public process is not endorsement. No agency, standards body, consortium or company listed here endorses Atom Works™, its products or its claims.