The birth certificate,
not Big Brother.
We attest the count · Never the content
Provenance is in the news: AI labs have begun cryptographically marking what their models produce. TokenMark™ works on a different question — whether the bill is true — and answers it without reading, storing, or marking anything that moves through your gateway.
A certificate records that a fact occurred — sealed by a registrar who wasn't a party to the event — and then it goes in the drawer until your auditor asks. It doesn't watch. It doesn't follow. It attests, once, and it's yours.
What is signed. What is never seen.
- Token quantities, per call and per period
- Pruning ledger entries — hashes, not text
- Dual-rate savings statements
- Basis flags on every count: VERIFIED or PROVIDER_ASSERTED
- The countersignature on the gateway's record
- Prompt or response text
- Your documents, code, or data
- User identities or behavior
- Marks or watermarks on your output
- Retained payloads — content is not stored
The privilege-separated dual-domain architecture routes only counts and hashes to the attester — payload content does not cross the boundary. This is not a privacy promise in a terms-of-service document; it is the same separation that makes the count trustworthy. A domain that could read your content could also be tempted to grade it. Ours can do neither. Verifiable before deployment.
The industry just started signing what AI produces. Nobody signs what it costs.
TokenMark™ attests the count — never the content. No marks on your output, no payload inspection, zero-network receipts.
The gateway cannot sign its own record — by construction, verifiable before deployment.
TokenMark™ and the new era of signed AI records
Is attestation a form of surveillance?
No — the two are opposites. Surveillance watches behavior continuously, on behalf of someone else, without your consent. A certificate records a single fact — sealed by a registrar who wasn't a party to the event — at your request, for your benefit. TokenMark™ issues certificates: this quantity, this period, this savings statement, countersigned. Then it goes in the drawer until your auditor asks for it.
Is TokenMark™ the same as AI watermarking?
No. Watermarks address the question "did an AI produce this content?" TokenMark™ addresses "is this count of tokens, spend, and savings verifiable by a party that didn't generate it?" Different questions — but the same principle, now industry-wide: a record signed only by the party being measured isn't a record.
If model providers now sign provenance, why do I need TokenMark™?
Provenance metadata indicates a model was involved in producing a file. It says nothing about the quantity you were billed, the context resent on every turn, the retries you were charged for, or whether a claimed savings figure actually occurred. That is why every TokenMark™ count carries a basis flag — VERIFIED or PROVIDER_ASSERTED — and every exit report states the mix. Provider self-attestation is a starting point, not a proof.
Does TokenMark™ read or monitor our prompts and data?
No — and not merely as a matter of policy. The attester domain receives token counts and cryptographic hashes; payload content does not cross into it. There is no content inspection, no user tracking, and no marking of your output. Receipts are generated by a client-side tool designed to make zero network requests: the proof runs on your machine.
Does TokenMark™ add watermarks or metadata to what our AI produces?
No. TokenMark™ operates at the spend layer, not the content layer. Your model's output passes through unaltered — no marks, no injected metadata, no fingerprints. The only artifact that gets signed is the ledger of what the work cost.
Who sees the attested record?
You do. The countersigned savings statement is your document — built for your CFO, your auditor, your board. It contains quantities, rates, hashes, and signatures. It contains no content, and TokenMark™ does not share it with model vendors, routers, or any other party.
The criterion any vendor should have to pass
We believe AI spend records should be held to the same evidence standard as every other transaction an auditor examines. Here is the test, stated so that anyone — including our competitors — can be measured against it:
Independent attestation of AI usage records
Usage and spend records should be countersigned by a party that:
- Does not generate or route the workload it measures — separation of generation and attestation;
- Cannot alter the record after signing — tamper-evident, integrity-protected structures;
- States the basis of every quantity — independently verified, or provider-asserted;
- Can be checked before deployment — by architecture review, not post-hoc assurances.
A record signed solely by the party being measured should not, by itself, constitute audit evidence.
This is a proposed criterion. It has not been adopted by NIST, GAO, OMB, or any government body, and no affiliation or endorsement is implied. We have offered vendor-neutral versions of this language for consideration in public standards processes, with our commercial interest disclosed. TokenMark™ is built to pass this test — and we publish it because we think everyone should have to.