Every claim on this site carries a basis, a verification date and an expiry — so a stale claim shows as stale.
A trust vendor that overstates is finished, and there is no second attempt. This page is the ledger: what is proven, what is roadmap, what is still collecting data, and what is explicitly not claimed.
Get an Agent Trust Gap BriefThe claims ledger
Material product and evidence claims on this site — signing, receipts, governed-run and engagement claims — with what each rests on, when it was last verified, and when that verification expires. Not every sentence on the site; the specific claims a buyer or auditor would need to check before relying on this product. A claim past its expiry shows as stale rather than quietly persisting.
| Claim | Basis | Verified | Expires |
|---|---|---|---|
| ApexClaw Receipts issue / verify / registry endpoints live behind admin auth | FIRST_PARTY (needs re-verification before expiry) | 2026-07-03 | 2026-10-01 |
| Ed25519 public key published at the well-known signatures directory | FIRST_PARTY | 2026-07-03 | 2026-10-01 |
| Signed-agent request observation | COLLECTING — no invented numbers | — | — |
| Omega governed run: refusals on unauthorized sends, receipts emitted, zero real sends | FIRST_PARTY (a past receipt is not proof of present runtime health; re-verified on cadence) | 2026-08-04 | 2026-11-04 |
| Enterprise growth systems engagement (anonymized client) | FIRST_PARTY_NDA (client not named publicly; methodology, period, baseline and limitations on the proof page) | 2026-08-05 | 2027-02-01 |
ApexClaw Receipts signature objects carry alg and kid, enabling algorithm migration (reference samples use Ed25519, which is NOT post-quantum; no quantum resistance is claimed) | FIRST_PARTY | 2026-08-07 | 2027-02-07 |
| SOC 2 | ROADMAP — NOT CLAIMED | — | — |
| ISO 27001 | ROADMAP — NOT CLAIMED | — | — |
Machine-readable: claims-ledger.json. Regenerated 2026-08-26.
Agent identity verification — in progress, honestly labelled
ApexClaw Receipts — issued today
Issue, verify and registry endpoints are live and used to certify reviewed autonomous actions. They require admin authentication and are not a public, self-serve certification service.
RFC 9421 — a finalised standard
HTTP Message Signatures, published 2024. An Ed25519 keypair exists and the public key is published as readiness infrastructure. The private key never leaves the server, and nothing here signs outbound requests with it yet.
Web Bot Auth — an active draft
Applies RFC 9421 to bot identity so a server can verify which agent is calling. It remains an IETF draft. This page will not call it a ratified standard.
Crawler posture: observe, not block
Major AI crawlers are explicitly allowed in robots.txt, grouped by the four jobs they actually do — retrieval, live agent fetch, training, and classic search. Operator surfaces are excluded from every group.
Blocking unverified agents before verification is widely adopted would cost legitimate citations for no real security gain today. When Web Bot Auth matures, that posture gets revisited — and this page will say so on the day it changes, not after.
The rules we hold ourselves to
- No fabricated numbers. Sourced, first-party with methodology, or labelled TARGET / SYNTHETIC / COLLECTING / INTERPRETATION.
- No certifications we do not hold. No ratified certification for agent governance exists — see audit and attestation.
- No internal metric passed off as market proof. Our own system's numbers are labelled as our own system's numbers.
- A past receipt is not proof of present health. Live claims carry an expiry and are re-verified on cadence.
- No client named. Ever. Engagements are described without identifying the client.
What that discipline looks like applied to third-party numbers we cite elsewhere on this site: Gartner's 40% agentic-project-cancellation projection and Forrester's ~88% enterprise-pilot failure figure both carry the study's own definitional caveats rather than being flattened into a bare stat — see the sourced statistics page. Omega, the system ApexClaw governs itself with, is labelled as our own system's number: 0% real external sends across its history, verified at the network layer on the governed-run record — not market proof, just our own evidence. The same discipline applies to regulatory figures: the EU AI Act's three penalty tiers run up to 7%, 3% and 1% of global turnover depending on the obligation breached, never rounded to one headline number.
Security contact: security.txt (RFC 9116). Reports about agent-facing surfaces — MCP endpoints, signing keys, published schemas — are especially welcome. Structured data on this page follows JSON-LD 1.1 and schema.org; signatures reference RFC 9421.
Common questions
What claims does ApexClaw make about itself?
Only claims that are sourced, first-party with stated methodology, or labelled TARGET, SYNTHETIC or COLLECTING. The claims ledger records each claim with a verification date.
Is ApexClaw Receipts a standalone protocol or a ratified standard?
No. It's the receipt format ApexClaw uses inside its own governance audit — not a standalone protocol, and not ratified by any standards body. No certification exists for it and ApexClaw does not issue one.
Which AI crawlers are permitted?
robots.txt declares the posture explicitly for retrieval, search, agent and training crawlers. It is published rather than described so it can be verified directly.
What is published for machines?
llms.txt, llms-full.txt, sitemap.xml, ai-catalog.json, the ApexClaw Receipts schema, and worked sample receipts and passports under /.well-known/.
How are stale claims handled?
Claims carry verification dates and expiry. An expired claim is removed rather than quietly left in place.