For Immediate Release
vCISO Lite Opens the Evidence Graph for Licensing — the Integrity Layer That Lets an Auditor, Insurer, or Acquirer Re-Derive Your Records Without Trusting You, Your Model Provider, or Your Cloud
The integrity layer under vCISO Lite's compliance, vendor-risk, diligence, and autonomous-agent work is now a standalone licensable product. Every consequential action becomes a grounded claim, checked against four independent relationships at once, sealed into a hash-chain and anchored to an external timestamp authority — a record a third party can recompute without taking the company's word. Available as a Library you run, Hosted by vCISO Lite, or Enterprise, with a five-spot Charter program at launch.
ATLANTA — September 10, 2026 — vCISO Lite today opened the Evidence Graph, the integrity layer underneath its compliance, vendor-risk, diligence, and autonomous-agent work, for licensing as a standalone product. The Evidence Graph turns every consequential action on the platform into a record a third party — an auditor, an insurer, an acquirer, even the vendor on the other side of an incident — can re-derive without trusting vCISO Lite, its model provider, or its cloud.
Most systems of record are written by the party under investigation. A log says what a service decided; it cannot say whether the decision was sound, and it asks the reader to believe the writer. The Evidence Graph was built for the opposite posture: it records not just that an action happened, but the grounding it rests on, checked against four independent relationships at once, sealed into a hash-chain, and anchored to an external timestamp authority. The proof does not depend on taking the platform’s word for anything.
“Every buyer who takes AI seriously ends up at the same wall: prove it to someone who has no reason to trust you,” said Yolonda Smith, founder of vCISO Lite. “A signed log doesn’t clear that wall, because a signature only tells you the bytes haven’t changed — not whether they were ever true. The Evidence Graph is our answer. A claim earns its place by agreeing with four independent neighbours at the same time, from sources that don’t answer to each other. Any one of those agreements is cheap to fake. All four together is the thing a forgery can’t hold. And an outsider can recompute the whole verdict without ever calling us.”
What’s in the release
The Evidence Graph is built on three ideas that ship together as one record format:
- Grounded claims. Every claim terminates in one of three roots — something observed and witnessed, a value computed deterministically from claims that already hold, or a prior decisionthat everything after it must stay consistent with. A claim that grounds in nothing, or in itself, isn’t a weak claim; the verifier names that condition and refuses it. Grounding is part of the claim, not metadata about it.
- Four independent relationships. Each claim is checked against its neighbourhood on four axes that answer to different sources: depth (is there a path back to the authority that permitted the work?), temporal (did that authority exist before the work, and does the ordering hold?), conditional (do the conditions the grant named actually resolve?), and behavioral (has this actor issued this verb before?). None of the four is an alert someone configured in advance; they stand around every claim already, so catching the next bad one never depends on having imagined it first.
- Coherence, then the seal. A claim is coherent when it agrees with all four neighbours at once. That simultaneous agreement is the forgery-resistance. The cryptographic seal — a hash-chain over the record, checkpointed and anchored to an external RFC 3161 timestamp authority — notarizes that the bytes have not changed since they were written, but the seal is necessary, not sufficient. The proof is the coherence, and it is what a stranger can re-derive.
What a refusal actually carries
The record format was proven on the platform’s own governed-agent harness. On August 17, 2026, in production, a coding agent proposed a destructive command against a live workload. The harness gate refused it on two named predicates — the verb was not inside the agent’s granted envelope, and the target environment was not the one the grant authorized — and the command never reached the cluster. This was an operator-run demonstration through vCISO Lite’s first-level agent-governance gate, not an autonomous interception; the point is not that a machine stopped an attack on its own, but what the refusal leaves behind.
The sealed refusal carries the grant the action was evaluated against, every failed predicate with its expected and actual values, the gate version, and a snapshot hash of the exact grant-and-action pair — everything a reviewer needs to recompute the verdict independently. What it does not carry is as important: no score, no confidence number, no model. The verdict is a computation over two documents, not a judgment that has to be believed.
How customers put it to work
Customers don’t operate the Evidence Graph directly — they run on it. It surfaces in the three places that matter to the people who don’t trust them:
- Every output carries its own proof. A control attestation, a vendor-risk finding, or a diligence pack arrives bound to the grounding it rests on, sealed and externally anchored. Nothing the customer hands out stands on vCISO Lite’s word.
- Governed agents, every action on the record. When an agent runs a compliance program under Trustworthy Autonomy™, every move it proposes is checked against its grant and sealed before it runs. The Evidence Graph is what makes each action provable rather than taken on faith.
- Third parties confirm without calling. Because the anchor is an independent timestamp authority rather than vCISO Lite’s database, an auditor, insurer, or acquirer can confirm a record existed and has not changed on their own — so the answer is never the company vouching for itself.
Licensing
The Evidence Graph is available to license in three shapes, so an organization can put it under its own program whether it wants to run the graph, have vCISO Lite run it, or build a program around it:
- Library — embed the SDK in your own stack and hold your own data; vCISO Lite never becomes its custodian. From $200,000 per year.
- Hosted — run on vCISO Lite infrastructure and operate nothing yourself, with integrity metered per sealed event. From $60,000 per year plus $0.03 per sealed event.
- Enterprise — for audit firms, standards bodies, regulators, and defense: dedicated infrastructure, contractual custody terms, and source escrow. From $500,000 per year.
A Charter program opens alongside the launch: the first five licensees take 50% off their first year, held for two years, in exchange for a named reference. Pricing and access requests are at vcisolite.com/evidence-graph.
Availability
The Evidence Graph landing page and licensing request-access flow are live today at vcisolite.com/evidence-graph. The integrity layer already underpins compliance, vendor-risk, and diligence outputs across the vCISO Lite platform, and is what Trustworthy Autonomy™ runs on. Organizations that want to license it for their own environment can request access from the landing page or by contacting the company directly.
About vCISO Lite
vCISO Lite is a compliance and cyber risk platform for growing companies that don’t have a full-time CISO. The platform helps customers close compliance gaps (SOC 2, ISO 27001, PCI DSS, HIPAA, and more), quantify cyber risk in the language their board and deal teams already speak, and — with Trustworthy Autonomy™ and now the Evidence Graph — hand operational responsibility to AI agents that prove every move they make. vCISO Lite is headquartered in Atlanta, Georgia. Learn more at vcisolite.com, read related product releases in the changelog, or explore the Evidence Graph.
Media Contact
Press & Analyst Inquiries
Yolonda Smith, Founder
[email protected]
###