Atom Works, Inc.Attestation for autonomous systems

Your AI can't be
its own witness.

Agents, gateways and platforms now act and spend at machine speed, and each keeps its own record of what it did. When that record is requested, the answer should not come from the system being asked. Atom Works builds the second signature: an independent seal on the record, auditable by anyone, without the platform's help.

Live: two seals on one record sha-256
agent procurement-07
action approve_invoice
tokens remaining of 250,000 ← edit
at 2026-09-07T16:04:11Z
The record is hashed and signed in your browser with real ECDSA P-256 keys generated on load. Nothing leaves the page.
Operator's own seal
Verified
Second signature · independent
Verified
Both seals verify. Edit the tokens remaining above and watch what each seal does.
The record question

Oversight of an autonomous system becomes concrete after something has happened. The request is narrow: produce the record.

Today that record is held, formatted and produced by the operator of the system in question. That is not an allegation about anyone. It is a structural fact, and it holds even when the operator is diligent and acting in good faith, because the party being asked is also the party attesting to the answer.

01

The record will be requested.

By a customer, an auditor, an insurer, a regulator or a court. Not if. When. The design question is what shape it is in when that happens.

02

A self-signed record proves the signer had the key.

It does not prove the record is the one that was written at the time. The operator's own seal will always verify, because the operator can re-sign anything it changes.

03

The second signature is what catches it.

A countersignature from a party that does not control the system, produced when the record was made, and auditable by anyone, anywhere, without asking either of them.

Property one

Record independence

Can the system's record of its own consequential behavior be generated and cryptographically sealed by a component the system cannot read, modify, or invoke at will — with that separation verifiable before deployment? A system that seals its own record offers testimony, not evidence. In the publicly documented agent-to-agent privilege escalation of August 2026, injected commands executed in the same environment that wrote the logs of record; reconstruction rested on a witness the attacker controlled.

Property two

Offline, migration-durable verifiability

Does a sealed record still verify years later, on an air-gapped machine, with no vendor participation — after the signature algorithms beneath it have been replaced? This requires binding, at sealing time, an identifier of the algorithm suite then in force (federal policy requires post-quantum key establishment by the end of 2030 and signatures by the end of 2031), and verification cost that grows logarithmically with record volume.

Both are yes-or-no architectural properties, implementable today with standardized primitives (FIPS 203, 204, 205), vendor-neutral by construction, and checkable in an afternoon. We state them in these words in every submission we make, so that what documentation should disclose and what evaluation should verify are the same two questions.

Separation of privilege domains by cryptographic construction, not by policy.

Three flagships

One idea, applied where the records already matter.

Each product puts a second signature on a class of record that is currently produced only by the system that generated it. Each one is built to the two properties above.

Amem
The independent seal for AI records.
Attestation layer · Patent pending

Amem™ countersigns a record produced by a system it does not control, at the moment the record is produced, and issues a verifier that works with no connection to Amem™, to the operator, or to the platform the record came from.

It is the layer the other products are built on, and the layer a first-party platform cannot supply for its own records however well it is built. A platform can sign. It cannot countersign itself.

Implemented
Record independence and offline verification, tested against tamper-and-fail cases.
Verifier
Offline, with an exit-code contract, so a machine can check a record as easily as a person.
Status
Patent pending. Public writing describes what it does, not how it does it.
TokenMark
Attested AI spend assurance.
Sealed savings · Proven, not promised · Patent pending

Enterprises are routing AI traffic through gateways that pick the cheapest model and report the savings. The gateway is grading its own homework. TokenMark™ sits in the request path as a separate privilege domain, records what was actually spent and never the content, and issues a sealed statement that a finance team, an auditor or a provider can verify without trusting the gateway or TokenMark™.

Routers change the rate. TokenMark™ changes the quantity and proves it, at pinned rates, so a provider price cut cannot create or destroy a dollar of claimed savings. Commercially: own the proof on subscription, share the savings on results. Never a per-record fee, never compensation from your AI providers.

Built and tested
TokenMark™ Core: observe-mode gateway that needs one base-URL change and fails open; hash-chained append-only ledger; an independent attester that checks the record before it countersigns and halts, signed, on any fault; offline verifier; admin panel; 67 automated tests across four suites, plus fifteen hostile QA passes.
Filed
Non-provisional application filed August 2026. Patent pending.
Next
Observe mode goes first, with one base-URL change. The optimization layer that produces a signed savings figure ships when a customer's success criteria call for one.
HoldMark Forge
Attested provenance for coding agents.
Software supply chain · Federal-ready · Patent pending

When an agent writes code, the question a reviewer, a customer or an agency will ask later is what context it was given, what it did with it, and whether anyone other than the agent's operator can confirm either. HoldMark Forge™ seals the context an agent worked from, ledgers what it produced, and gates the merge on a verifier that runs in CI and answers with an exit code.

Built for the environments that will ask first: a control map to NIST SP 800-53 Rev. 5, cryptographic bill of materials emission, and archival export in NARA BagIt 1.0, so the record outlives the tool that made it.

Built and tested
Sealed context container; Merkle-checkpointed ledger; generator and attester in separate privilege domains, with self-attestation rejected by construction; CI merge gate; department profiles for the US edition.
Verified
Unit, integration and adversarial suites, all passing at the current kit.
Status
Patent pending.
The -Mark™ house

The same signature, wherever an autonomous system earns, buys, or is born.

Every property in the portfolio is the second signature applied to a different record. They share one runtime format, one seal, and one rule.

THE SECOND SIGNATURE SynthWorkerLABOR VoxMarkCOMMERCE ForgeMarkBIRTH MPSWAFORMAT Quantum OrbitPLATFORM
SynthWorker Autonomous labor
An autonomous system cannot sign its own timesheet. SynthWorker™ and the Robot Ownership Token put attested records under robot and agent labor, so ownership, earnings and insurance can attach to work that a machine did.
VoxMark Voice commerce
Attested voice-to-buy for streaming and connected TV. When a voice command becomes a purchase, the record of what was said, matched and charged is countersigned, with neutrality between platform and merchant enforced by construction rather than promise.
ForgeMark Coming
Attested learning agents, struck like currency: each one born with a genesis record and a birth certificate that is transferable title. Create, lease, and be paid on every lease. Marketplace and arena in build.
MPSWA Runtime format
The encapsulated-agent container the fleet runs in. Provenance is inside the container, not bolted on, with capability negotiation and a post-quantum hybrid seal from Amem™.
Quantum Orbit Platform
The platform the agent fleet runs on: persistent sealed memory, calibration ledgers, and more than a hundred agent dossiers, with copyright and patent-pending marking across the modules.
What is built

We tell you which is which.

A company selling proof should not ask you to take its word. This is the current line between what is implemented and tested, and what is specified and filed but not yet a working demonstration.

Implemented and tested2026-09
  • Record independence implemented and tested
  • Offline, migration-durable verifiability implemented and tested
  • TokenMark™ Core v0.6 gateway, ledger, attester, verifier, admin panel, cost accounting, release signing; 67 automated tests
  • Independent attester checks the record, countersigns, halts signed on any fault
  • HoldMark Forge™ kit sealed context, Merkle ledger, CI merge gate; unit, integration and adversarial suites passing
  • Tamper-and-fail demonstration the same kind you just ran at the top of this page, against real ledgers
Specified and filed, not yet demonstratedhonest gap
  • Scoped suspension who may suspend an autonomous system and who may lift it, as a privilege-separated act rather than a switch the operator holds
  • Optimization layer dual-rate savings statements that produce a signed savings figure; built when a customer's success criteria require one
  • Streaming passthrough the current build is non-streaming; streaming inference is the next production step
  • ForgeMark™ marketplace in build; terms and policies pending review

Why say this out loud. Because the whole company rests on the claim that a party's own account of itself is not evidence. It would be strange to ask you to accept ours.

Get involved

The second signature is a category, and it is early.

We are a small company with filed mechanisms, working code, and a thesis that gets more obviously true every quarter. Here is where help is useful.

Investors

Back the record layer.

Attestation for autonomous systems is infrastructure, not a feature. We are building the layer the platforms cannot build for themselves, with patents pending on the mechanisms and code that has already been through hostile QA.

Start an investor conversation
Strategic partners

Countersign what you already count.

Gateways, payment networks, identity and security platforms: you produce first-party records at scale. We supply the independent second signature you cannot supply for yourselves, without touching your rate or your customer relationship.

Talk about a partnership
Standards and policy

Put the properties in the templates.

We file public comments, brief staff, and participate in standards work on agent accountability and AI documentation. If you are writing the rules for records of autonomous systems, we would like to be useful.

Request a briefing
Contact

Tell us what you are working on.

A short note is enough. Say who you are, what you are building or deciding, and what would be useful from us. You will hear back from a person, usually within two business days.

We do not add you to a list, and nothing you write here is shared outside Atom Works.

John M. Ossenmacher, President & CEO
Prefer email? john.ossenmacher@amem.law
Atom Works, Inc. · Corona Del Mar, California

By sending, you agree we may reply to you at this address. Details in our privacy policy.