FOR YOUR TECHNICAL TEAM

We sit in the path. Here is what that means.

Privacy, security, availability, and latency — answered directly, including the one we cannot answer yet.

Where the software runs

Everything runs inside your environment. Your applications call TokenMark™, TokenMark™ calls your model provider, and the sealed records are written to your storage. Nothing crosses to us.

your applications → TokenMark™ → model provider ↓ sealed records → your storage ✕ nothing to us

Privacy

Prompt and response content never leaves your environment and never reaches us. What the system produces is a sealed record containing one-way fingerprints, identifiers, and counts — content cannot be recovered from it. Those records stay in your custody. There is no telemetry, no usage reporting, and no phone-home of any kind.

Record hygiene

The sealed records, receipts, and exit reports the system emits carry only the metadata they need to be verified — identifiers, timestamps, one-way fingerprints, and the signatures themselves. They are constructed deliberately: no toolchain fingerprints, no authoring strings, no incidental fields that leak how or where a record was produced. What the artifact discloses is exactly what an auditor needs and nothing beyond it, and the field set is documented so your team can confirm it. This is hygiene on our own output — not inspection of yours.

Scope, stated plainly. This is the one thing adjacent to “cleaning up AI output” that TokenMark™ does — and it applies only to the records TokenMark™ itself produces. TokenMark™ does not read, scan, filter, or alter your model’s responses, and it does not add to or remove marks from them. Scanning response content for malware or handling third-party provenance marks would require reading payloads — which the attester, by construction, cannot do. Those are separate concerns for a separate layer, kept out of the attestation domain on purpose.

Security

Bound sessions

In August 2026, commodity infostealer malware on user machines lifted active login sessions from a major AI platform. Nothing was cracked; a string was copied. The copied sessions were replayed to drain paid usage, and the operator’s remedy was the only one available to it — sign everyone out and strip stored payment methods. When the credential is the identity, the account is the smallest thing you can suspend. That is the bearer problem, and it is a construction fault, not a user error.

The portfolio standard behind this, AW-SEC-001, is provided to pilots and design partners under NDA.

Availability

If the optimization path fails, requests pass straight through unmodified and the event is recorded. Your workload never depends on TokenMark™ being healthy. Removing it is the same one-line change that installed it — no migration, no data to extract.

Latency

We are inline, so we add some. We have not published a number, because we have not yet measured it on production traffic. The first design-partner pilot measures overhead at p50, p95, and p99 and publishes it alongside the savings figure, against a pass/fail threshold agreed before the pilot starts.

A company selling proof does not get to estimate. When we have a measured number, we will publish it — including if it is worse than we hoped. Sealed savings. Proven, not promised.

Assurance posture

Request the full security package

HARDENING RECORD

Attacked by us, before anyone else

Every TokenMark™ build passes staged hostile reviews before it reaches a customer: an internal adversarial pass, an enterprise implementation-team pass, and an external-style red-team pass modeled on a top-tier security vendor’s playbook. Findings are not quietly fixed — each one is recorded in a QA log delivered with the software, with the fix site marked in code and a named regression test that keeps it fixed. A finding without all three is not closed (rule TM-CR-007).

What the record covers, by class: secrets never travel in shared or pinned artifacts — the policy file an auditor receives contains no secret material by design; every admin surface is served with strict browser hardening and constant-time credential checks behind a per-IP failure lockout; request targets and sizes are strictly validated; and every string an outside caller controls is sanitized and length-capped before it can enter the permanent ledger. Prompts and replies are never written, logged, or hashed individually — a rule enforced by test, not policy.

We publish the posture, not the exploit map — and the QA log itself, findings included, is available to customers and their security teams under NDA. A vendor that shows you its scars is telling you the review happened.

Programs & participation
NVIDIA InceptionMember
NIST Zero DraftsSubmissions filed
NIST AI 300-1Public comment
NIST NCCoEPost-Quantum Cryptography
Community of Interest
DOE Genesis MissionConsortium participant
Congressional Internet CaucusAdvisory Group — former member

Participation in an open public process is not endorsement. No agency, standards body, consortium or company listed here endorses Atom Works™, its products or its claims.