Docs
Gate your first AI release.
Quickstart for Assurance OS: sign up, register an AI system, create an API key, add the release gate to CI, read the decision, and verify a signed evidence pack.
1Sign up
Create a free workspace. The Free plan needs no card and gates one AI system.
2Register an AI system
Open Systems and add the AI feature you want to gate. Answer the obligation questionnaire; it suggests a risk class and the obligations that likely apply, and a person confirms them. Then attach evidence: model cards, evaluation runs, data contracts and approvals.
Copy the system ID from the system page. CI uses it as SYSTEM_ID.
3Create an API key
In Settings → API keys, create a key for CI. It is shown once. Store it as a CI secret named ASSURANCE_API_KEY, and set ASSURANCE_URL to your workspace URL.
4Add the gate to CI
Use the GitHub Actions job, or call the endpoint from any CI that can run curl.
.github/workflows/ai-release-gate.yml
name: AI release gateon: [push, pull_request]jobs: gate: runs-on: ubuntu-latest steps: - name: Check Assurance OS release gate env: API_KEY: ${{ secrets.ASSURANCE_API_KEY }} GATE: ${{ vars.ASSURANCE_URL }}/api/v1/ci/release-gate SYSTEM_ID: ${{ vars.ASSURANCE_SYSTEM_ID }} run: | res=$(curl -fsS -H "X-Api-Key: $API_KEY" "$GATE?systemId=$SYSTEM_ID") echo "$res" | jq -r .content exit "$(echo "$res" | jq -r .exitCode)"5Read the decision
The response carries decision, a list of blockers naming what is missing, and an exitCode the job exits with.
{ "systemName": "Claims Triage AI", "decision": "PASS", "blockers": [], "evalScore": 92, "evidenceCoverage": 100, "dataContractStatus": "HEALTHY", "riskClass": "HIGH", "exitCode": 0, "content": "Release gate PASS — no blockers."}PASS = 0All mandatory controls satisfied.REVIEW = 2Non-blocking warnings or pending approvals.BLOCKED = 1Missing evidence, failed evaluations, open breaches or missing approvals.
6Export and verify a pack
Export the evidence pack from the system page, or call GET /api/v1/systems/{systemId}/evidence-pack. Each JSON pack carries contentSha256 and an RS256 signature. Public keys are at /.well-known/jwks.json on your workspace host.
Anyone holding the pack can check it, with no account:
import json, sys, urllib.requestfrom jose import jws # pip install python-jose pack = json.load(open(sys.argv[1]))jwks = json.load(urllib.request.urlopen(sys.argv[2]))header = jws.get_unverified_header(pack["signature"])key = next(k for k in jwks["keys"] if k["kid"] == header["kid"])claims = json.loads(jws.verify(pack["signature"], key, algorithms=["RS256"]))assert claims["contentSha256"] == pack["contentSha256"], "hash mismatch"print("signature valid for system", claims["systemId"], "generated", claims["generatedAt"])A valid signature proves Assurance OS produced the pack and it was not edited after export. It is not a legal certification.
7Using evgraph locally
evgraph is our open-source (BSD-3-Clause) governance-evidence checker. Run it on your laptop or in CI without an account, before or alongside the hosted gate. It reports what evidence exists, is missing or disagrees; it does not give a compliance verdict.
pip install evgraph evgraph-cli # Check that a model card, approval and deployment record agreeevgraph scan model_card.json approval.json deployment.json --format markdown # Same check as a CI gate: exit code 1 on unmet evidence, --strict also trips on inconclusive findingsevgraph scan-promotion \ --model-card model_card.json \ --approval approval.json \ --deployment deployment.json \ --format sarif --gate --strict > evgraph-promotion.sarifOutput formats: json, markdown, sarif and oscal.
Before AI ships, prove it is ready.
Free plan, no card. Gate your first AI system in CI today, or explore the live demo workspace.