TokenMark™ cuts your AI model spend — and is built so it cannot misstate what it saved. Every savings figure is countersigned by an independent attester and verifiable by your own auditors, offline, without us.
Every vendor will tell you their AI is safe, governed, and auditable. None of them can tell you which agents are running inside your environment right now, who approved them, what they can reach, or what they cost. The free Agent Index™ answers that in an afternoon — read-only, inside your own VPC.
Grade your vendors — free assessment See a sample findings report
Your finance team approves this every month. Nobody in your building can check the second number — and the vendor's fee is a share of it.
This is not one bad vendor. Every AI cost vendor on the market works this way: they hold the meter, they set the baseline the savings are measured against, and they sign the record. There is no third party in the arrangement.
The industry has begun organizing around the first half of this problem. In August 2026 the Linux Foundation launched the Tokenomics Foundation with thirty member organizations to build open standards for AI economics — definitions, cost models, and token cost telemetry. That work establishes what to measure. TokenMark™ addresses whether the measurement can be checked by anyone other than the party reporting it.
Before anyone talks about verifying a savings figure, it is worth being concrete about what there is to save. Inference budgets leak in three places:
The same background material shipped again on every call in a conversation. You pay full price each time for text the model has already been given. On most bills this is the largest single line of recoverable spend.
Material retrieved and attached to a request that the answer never draws on. Retrieval systems are tuned to over-fetch, because missing something is worse than sending too much — and you are billed for all of it.
Requests that failed, timed out, or came back unusable and were run again. The first attempt is billed exactly like the one that worked.
TokenMark™ addresses the first and largest of these in two ways — by not sending what is not needed, and, with the wider Atom Works™ portfolio, by not paying twice for what has already been supplied. Our patent filings cover attested memory and restoration of withheld material by reference, so context can be returned to a later request without going back to the source and paying for it again.
One person initiates. A second person, with separate credentials, approves. The control is not that they promise to be careful — it is that the system will not let one person do both.
One system does the optimizing. A second system, with separate credentials, certifies the result. The first cannot produce the second signature — not by policy, the machine denies it.
TokenMark™ is separation of duties, applied to the AI bill. The party that performs a transaction should not be the only evidence of it — a principle your auditors already apply everywhere else in your business.
TokenMark™ installs with a single change — the API address your applications already use. From there, two strictly separated components do the work:
Intercepts each model request and removes the three leaks above: context already supplied, material the answer will not use, and duplicate work. Every piece of context is recorded first, so anything withheld can be restored on demand — nothing is silently lost, and restoring it costs a lookup rather than a second retrieval.
A separate service, under separate credentials, with its own keys. It independently re-checks every record and recomputes the savings figure from the record itself before countersigning. The gateway cannot produce this signature — the operating system denies it the key.
A verification tool your team runs on your own machines, offline, with no TokenMark™ service present. It confirms both signatures and recomputes the figures. If a record was altered, it fails — loudly.
Your invoice carries the record. You verify it before you pay it.
The architecture isn't a diagram — it's a reference implementation with real privilege separation, demonstrated live to design partners.
See how verification works, and what failure looks like →
Installed in your environment as two separated services. A deployment manifest proves the separation before any traffic flows — your team re-runs the check itself.
Pass-through mode. Your real traffic establishes a measured consumption baseline. No estimates, no models — metered fact.
Optimization on. Every request sealed and countersigned daily. Latency reported alongside savings, always.
Your engineers verify the full record set offline and the exit figure is drafted from verified records only. If the number doesn't survive your team, it was never a number.
The Self-Graded Stack — the same scoring defect appears at the model layer, the cost layer, and the agent layer. One structure, three instances.
Isn't AI spend a rounding error? — the strongest argument against us, taken seriously and answered.
Five questions to ask any AI cost vendor — including us. If a vendor can't answer the second one, nothing else matters.
What did you pay for context you never used? — an itemized estimate from your monthly bill. Modeled, not measured, and the countersignature line is blank on purpose.
Do not take our word for it — what the verifier does, what a failed record looks like, and how to obtain the tool and a sample record.
Testing a TokenMark™ record — six procedures your audit team can perform offline, without us present, and what the record does not assert.
Atom Works™ builds attestation infrastructure for AI — systems designed on one principle: the machine that acts cannot be the machine that vouches for the action.
The portfolio spans attested memory for AI inference, provenance for coding agents, and governed agent marketplaces, protected by an active patent program and engaged with federal standards work on AI accountability records. Those pieces are not adjacent products — the memory and provenance work is what lets TokenMark™ return withheld context by reference instead of re-retrieving and re-paying for it, and the attestation engine is shared across all of them.
TokenMark™ applies that architecture to the question every CFO is now asking: what are we actually paying for, and how would we know?
Design-partner evaluations, platform and OEM inquiries, and investor conversations — one door for all three.
Or write to sales@amem.law — open in Gmail.
The button opens your default mail app with a short template. Nothing is collected by this site.
TokenMark™ meters spend against each agent’s attested record — proof of what it actually did. If your agents cannot prove that yet, start with the free Agent Index™: it finds every agent running in your environment, read-only, inside your own VPC.
Find every agent — containers, scheduled jobs, serverless, workflows, robots, credential-holding scripts. Free, read-only, nothing leaves your network.
Issue creation records and countersign the work, so origin, authorization, and authority become provable to a third party.
TokenMark™ caps and settles spend against that attested record. An agent that cannot prove what it did cannot prove what it owes.
Participation in an open public process is not endorsement. No agency, standards body, consortium or company listed here endorses Atom Works™, its products or its claims.