Skip to content
Assurance OS

Docs

Gate your first AI release.

Quickstart for Assurance OS: sign up, register an AI system, create an API key, add the release gate to CI, read the decision, and verify a signed evidence pack.

1Sign up

Create a free workspace. The Free plan needs no card and gates one AI system.

2Register an AI system

Open Systems and add the AI feature you want to gate. Answer the obligation questionnaire; it suggests a risk class and the obligations that likely apply, and a person confirms them. Then attach evidence: model cards, evaluation runs, data contracts and approvals.

Copy the system ID from the system page. CI uses it as SYSTEM_ID.

3Create an API key

In Settings → API keys, create a key for CI. It is shown once. Store it as a CI secret named ASSURANCE_API_KEY, and set ASSURANCE_URL to your workspace URL.

4Add the gate to CI

Use the GitHub Actions job, or call the endpoint from any CI that can run curl.

.github/workflows/ai-release-gate.yml

name: AI release gateon: [push, pull_request]jobs:  gate:    runs-on: ubuntu-latest    steps:      - name: Check Assurance OS release gate        env:          API_KEY: ${{ secrets.ASSURANCE_API_KEY }}          GATE: ${{ vars.ASSURANCE_URL }}/api/v1/ci/release-gate          SYSTEM_ID: ${{ vars.ASSURANCE_SYSTEM_ID }}        run: |          res=$(curl -fsS -H "X-Api-Key: $API_KEY" "$GATE?systemId=$SYSTEM_ID")          echo "$res" | jq -r .content          exit "$(echo "$res" | jq -r .exitCode)"

5Read the decision

The response carries decision, a list of blockers naming what is missing, and an exitCode the job exits with.

{  "systemName": "Claims Triage AI",  "decision": "PASS",  "blockers": [],  "evalScore": 92,  "evidenceCoverage": 100,  "dataContractStatus": "HEALTHY",  "riskClass": "HIGH",  "exitCode": 0,  "content": "Release gate PASS — no blockers."}
  • PASS = 0All mandatory controls satisfied.
  • REVIEW = 2Non-blocking warnings or pending approvals.
  • BLOCKED = 1Missing evidence, failed evaluations, open breaches or missing approvals.

6Export and verify a pack

Export the evidence pack from the system page, or call GET /api/v1/systems/{systemId}/evidence-pack. Each JSON pack carries contentSha256 and an RS256 signature. Public keys are at /.well-known/jwks.json on your workspace host.

Anyone holding the pack can check it, with no account:

import json, sys, urllib.requestfrom jose import jws            # pip install python-jose pack = json.load(open(sys.argv[1]))jwks = json.load(urllib.request.urlopen(sys.argv[2]))header = jws.get_unverified_header(pack["signature"])key = next(k for k in jwks["keys"] if k["kid"] == header["kid"])claims = json.loads(jws.verify(pack["signature"], key, algorithms=["RS256"]))assert claims["contentSha256"] == pack["contentSha256"], "hash mismatch"print("signature valid for system", claims["systemId"], "generated", claims["generatedAt"])

A valid signature proves Assurance OS produced the pack and it was not edited after export. It is not a legal certification.

7Using evgraph locally

evgraph is our open-source (BSD-3-Clause) governance-evidence checker. Run it on your laptop or in CI without an account, before or alongside the hosted gate. It reports what evidence exists, is missing or disagrees; it does not give a compliance verdict.

pip install evgraph evgraph-cli # Check that a model card, approval and deployment record agreeevgraph scan model_card.json approval.json deployment.json --format markdown # Same check as a CI gate: exit code 1 on unmet evidence, --strict also trips on inconclusive findingsevgraph scan-promotion \  --model-card model_card.json \  --approval approval.json \  --deployment deployment.json \  --format sarif --gate --strict > evgraph-promotion.sarif

Output formats: json, markdown, sarif and oscal.

Before AI ships, prove it is ready.

Free plan, no card. Gate your first AI system in CI today, or explore the live demo workspace.