Exchange proof. Not paperwork.

Alliance Trust Networks

Cross-org trust as proof-exchange: verifiable attestations shared across the supply chain, checkable by any party without platform access, revocable by either side. Who you trust, and how you know.

Proof-exchange. Not document-exchange.

Your compliance boundary does not end at your infrastructure. Every subcontractor, cloud provider, and partner that touches your data extends it. The Redoubt Forge architecture specifies Alliance as its trust capability, built on one inversion: organizations exchange verifiable proof of posture, not documents about it. A letter asks to be believed. An attestation carries the material to check it.

The Document-Exchange Problem

Supply chain trust runs on documents. A prime contractor verifying a subcontractor's CMMC Level 2 posture sends a questionnaire and receives a letter. A healthcare partner confirming HIPAA technical safeguards gets a signed PDF. A FedRAMP boundary inherits risk from every external service inside it, and the inheritance is documented in attachments. Each document takes real effort to produce and real effort to review, and each describes exactly one moment: the moment it was written.

Nothing in the document verifies itself. Authenticity means a phone call. Currency means taking the date on the letterhead at face value, while evidence decays from the moment it is captured. A questionnaire answered in March circulates until the following March, and the posture it described drifts every week in between. The instrument is not merely slow. It is structurally unable to say anything about the present.

The architecture inverts the exchange. Alliance holds cross-org trust as proof-exchange, not document-exchange: what crosses the organizational boundary is a verifiable attestation of posture, shared under scoped, revocable entitlements rather than open-ended access. The composition is deliberate. Alliance is machine-readable attestation applied across organizations, and the posture inside that attestation is computed in Rampart, not asserted by whoever had time to answer the questionnaire.

The Inversion

A letter asserts. An attestation proves. The difference is precise: an attestation carries its own verification material, so the receiving party checks the mathematics instead of trusting the letterhead.

Attestation, Machine-Readable

For an attestation to be worth exchanging, it must survive three tests a PDF fails. It must be machine-readable, so the receiving party's tooling consumes it instead of a human re-keying it into a spreadsheet. It must be current, so it describes posture now rather than posture at the last audit. And it must be scoped, so the sharing party discloses what the relationship warrants and nothing more. OSCAL exists precisely to make compliance data machine-readable; most of what crosses supply chain boundaries today still is not.

The design specifies machine-readable attestation as a capability in its own right: cryptographically verifiable, selectively shareable posture attestation, OSCAL-native in both directions. Emit, so an attestation leaves as structured data a partner's tooling can parse. Ingest, so a partner outside the platform can still hand over machine-readable posture instead of a letter. And a live API rather than an export button. Currency comes from where the numbers originate: Rampart holds authorization as live state, a point-in-time assessment is a projection computed from that state, and the attestation Alliance shares is such a projection. Current because it is computed, not because someone remembered to update a document.

Checkable Without Us

An attestation is only as strong as the substrate beneath it. Here the substrate is the signed event spine, the platform's evidence chain: every compliance event is chain-hashed per organization with SHA-256, batches seal under Merkle checkpoints, and checkpoint roots are signed by hardware-backed keys that never leave their module, countersigned with independently signed time, and published to dual witnesses in write-once storage. Receipts and witnesses are what make an attestation checkable offline. Without them, a signed document is still just a document.

The exported artifact is an evidence bundle: canonical event bodies, per-event inclusion receipts carrying Merkle paths, consistency proofs across the covered span, and the published public keys. A seven-step verification algorithm recomputes every hash, checks every signature and timestamp, and compares roots against the witnesses; a failure names the exact broken link. No step requires platform access. The witnesses accept only monotonic history, so a forked record shown to different audiences is detectable by any verifier holding either copy, and a standards watch tracks the emerging IETF transparency-receipt shape so exported receipts stay interoperable as that format settles.

No Platform Access Required

The verification algorithm runs entirely offline against the bundle and the witness record. The partner checking an attestation needs no account, no API key, and no cooperation from Redoubt Forge. A trust exchange that requires the vendor's participation to verify is document-exchange with extra steps.

Selective Disclosure

Every supplier knows the disclosure dilemma: prove enough to be trusted, reveal no more than the relationship warrants. A bare score under-proves, and a serious counterparty will not accept it. A full evidence dump over-shares, sending internal hostnames, configurations, and open findings to a partner who needed none of them. Even a SOC 2 report, the closest thing to a standard disclosure instrument, is an annual document shared under NDA, not a live proof.

The architecture resolves the dilemma structurally. Attestation is selectively shareable by design, and the spine's elevation set carries selective-disclosure bundles: field-level salted-hash canonicalization, so a bundle ships with payload fields redacted while every hash still verifies. The receiving party confirms the claim is sealed in the log without reading what the sharing party withheld. A further step, zero-knowledge proofs that a compliance predicate holds over the sealed log without disclosing a single event, is a candidate for the Alliance design, not settled.

Bilateral by Design

Third-party risk programs treat trust as a steady state. The agreement is signed, the letter is filed, and the relationship exists until someone remembers to revisit it. Relationships do not behave that way. A subcontractor's posture degrades mid-contract. A partner's data access grows past what was originally scoped. The filing cabinet records neither event.

The trust-relationship design is bilateral and explicit. A relationship names the framework in scope and a visibility level the sharing party selects: an aggregate score, per-control status, or full detail with evidence metadata. Both parties confirm before anything is shared, and either party revokes at any time. The posture behind the shared signal is not self-reported; it derives from evidence Sentinel is designed to collect and Rampart to score. Thresholds belong to the relationship: when shared posture falls below the level a relationship declares, notification reaches both parties, and a critical breach can suspend the exchange itself.

Revocable, With a Record

Revocation ends the sharing, not the history. The spine is append-only, so what was shared, when, and under which visibility level stays answerable after the relationship ends: for disputes, for regulators, for the next negotiation. Trust is not permanent. The record of trust is.

Assessors as Scoped Actors

A formal assessment means handing an outsider, often a C3PAO, access to your compliance data, and the common instruments are blunt: screen-share sessions, exported binders, a shared drive that outlives the engagement. Worse, traditional platforms lock the assessment while the assessor reviews it, which penalizes exactly the team that keeps fixing findings mid-review. The authorization bottleneck is partly an access-model problem.

The design admits external assessors as scoped, time-boxed Actors with as-of evidence lenses. Actor is a precise term: every act on the platform carries a resolvable accountability chain in the event envelope, so an assessor's participation is attributable by construction, and access ends with the assessment instead of outliving it. The as-of lens is what removes the lock. The assessor's view is a projection of the event stream as of a chosen timestamp; the live Rampart view is a projection at now; both derive from the same log, with changes since the baseline rendered as a diff the assessor credits by advancing the baseline. And as-of answers are citable: each names the log range and sealed checkpoint that make it true, so anything the assessor relies on upgrades to a receipt on demand.

Frozen View, Live Work

Locking an assessment forces a team to choose between fixing and being credited. The as-of lens ends the choice: the assessor holds a stable baseline, the team keeps converging, and accepting recent fixes is a projection change, not a merge.

Trust Is a Live Signal

Compliance is heading toward continuous authorization, assessments that run as pipelines, and trust exchanged as a live signal instead of an annual document. Alliance is the design for that exchange: posture computed from one defended implementation, sealed into a verifiable record, and shared as proof any party can check without asking permission. The annual letter is document-exchange. The attestation is proof-exchange. The difference is the whole capability.