It starts where the watts burn.
A training run. An inference fleet. A fine-tune at 2am. The agent wraps your job with one command — no code changes, no SDK lock-in — and the measurement window opens the instant the workload does.
Connect AI measurements and actions to their origin, execution context and signatures. Start with energy. Inspect the evidence.
Seven connected layers. Energy enters at the silicon and exits as evidence anyone on Earth can verify — watch it flow.
A training run. An inference fleet. A fine-tune at 2am. The agent wraps your job with one command — no code changes, no SDK lock-in — and the measurement window opens the instant the workload does.
Power is sampled at the source. Live in production today: NVML from the GPU and — inside confidential VMs — an Intel TDX quote bound to the samples. Built in and rolling out per deployment: RAPL from CPU and DRAM, PSU telemetry over Redfish, and a machine fingerprint. Raw readings are hashed at capture: samples_hash.
Independent sources are cross-checked against each other — GPU vs wall, fingerprint vs machine, TEE quote vs samples hash. Agreement earns a trust score; the posture is upgrade-only. hardware_attested must be earned, at 0.80 or above.
The measurement is canonicalised, hashed with SHA-256 and signed with Ed25519 + ML-DSA — classical and post-quantum on supported hybrid certificates. Every certificate carries its claim_type and its caveats. It says exactly what it proves, and nothing more.
Certificates are leaves in a SHA-256 Merkle tree. Each one receives an inclusion proof; the whole batch compresses into a single 32-byte root. Tamper with any certificate, anywhere, and the root stops matching. Mathematics does the auditing.
Only the root touches the chain — 32 bytes that reveal nothing about your workloads, anchored on Polygon mainnet with transaction costs that vary. From that block on, not even Serial Alice can rewrite history.
One GET request — or an offline bundle that verifies in ~30 lines of Python, with no API call and no account. Retain the bundle, public keys and required trust material for independent verification. That is the point.
POST-QUANTUM EVIDENCE
Hybrid certificates combine Ed25519 and ML-DSA-65. Inspect the algorithms, public keys and individual verification results in a record you can retain and share.
On 23 September 2026, we checked the ML-DSA-65 signature of this public certificate with a separate implementation. This validates that signature, not every deployment or every layer of the infrastructure.
Inspect the certificate →IDENTITY. ENVIRONMENT. DECLARED MANDATE.
Action records can bind agent identity, runtime context and a declared mandate reference to signed content. These are distinct from energy certificates; the available checks depend on the record type.
The declared agent and the signing key. A signature identifies the signer under the applicable trust model; it is not automatically a verified human identity.
Runtime and hardware evidence, where available. A valid TEE quote can support execution-environment claims; it does not by itself establish geographic location or data residency.
The declared mandate reference and decision class. Current action records do not validate the mandate chain, delegation or revocation. Recording approval is different from independently verifying authority.
EXISTING ARCHIVES · PROJECT SCOPING
Have older signed records to preserve? We can scope a preservation project: inventory formats and keys, assess existing signatures, and define a new evidence envelope without modifying the originals.
This is a project to assess, not an automated migration service currently available. A new signature protects a new commitment to the archive; it does not retroactively prove the original content or signing date.
Assess my archive →This is a real certificate, issued by this API, anchored on Polygon mainnet. Open it. Inspect the signature, public key and available proofs. A valid signature establishes integrity under the stated trust model, not the physical accuracy of the measurement.
Three designs exist for energy evidence. They are not interchangeable — they guarantee different things.
Ledger services (EAS-style energy attestation registries) record what is submitted to them and make it permanent. Permanence is valuable — but a ledger cannot make a submitted number true. Its guarantee begins after the number arrives.
Industrial carbon-accounting platforms (such as Cleartrace or Auriline) connect to utility meters, ERPs and billing systems. Those sources sit inside the reporting operator's own perimeter: what enters the platform is what the operator's systems report.
Serial Alice reads the energy itself — NVML for GPU, RAPL for CPU and DRAM, Redfish for PSU — and, in the hardware_attested tier, does so inside confidential compute (Intel TDX) that the operator does not control. Only then is the reading signed and anchored. The guarantee begins before the number exists anywhere else.
All three designs are legitimate; they answer different questions. Ours answers: was the measurement itself independent of the party being measured?
Deliver workload energy evidence to customers, with the measurement source and scope attached.
Keep measurements traceable to their execution and inspect the available hardware evidence.
Inspect record integrity, signing keys and declared execution context during technical reviews.
Examine the evidence supporting a claim and identify the checks that remain unavailable.
Scope a preservation project for older records. Automated post-quantum migration is not yet a released service.
Evaluate additional telemetry sources against an agreed scope and evidence requirements.
Pay by card via Stripe. API units measure API usage separately from certificate allowances. Evidence levels depend on the available sources, not the plan price. Contact us to scope your integration.
Explore research, operations, audit and integration tools. Access requirements depend on the service.
Run the Serial Alice agent next to the workload. It reads GPU energy from NVML at the hardware source, signs each reading at capture, and issues a certificate whose hash is anchored on Polygon. The structured export produces CSRD / ESRS E1-ready XBRL, and auditors verify any sampled certificate free, offline, without contacting Serial Alice.
Article 53, via Annex XI, requires providers of general-purpose AI models to document the computational resources and energy consumption of training. The obligations apply to new GPAI models since 2 August 2025; models placed on the market earlier must comply by 2 August 2027. Serial Alice issues per-training-run and per-inference signed certificates the AI Office — or anyone else — can verify independently.
A ledger makes a submitted number permanent; it does not make it true. Serial Alice measures the energy itself at the hardware boundary (NVML, RAPL, Redfish) before signing and anchoring, and every certificate states its evidence tier — self_reported, cross_checked or hardware_attested — so a verifier sees exactly how the number was obtained, not just that it was recorded.
Yes. Verification is free, with no account and no API key: GET /v2/certificates/{id}/verify returns a flat result — overall_valid, trust_posture, signature_valid, algorithm, merkle_valid, anchor_status, anchor_tx_hash. The offline bundle verifies in about 30 lines of Python, and the Polygon anchor is public.
AI compute energy at the hardware source: GPU energy via NVML, CPU and DRAM energy via RAPL, and PSU / chassis power via Redfish BMC where available. Samples are taken at 1 Hz, hashed, and issued as watt-hours with power and duration. Each certificate names its measurement source and its trust_posture. Tamper-evidence after signing is universal — hash, signature, Merkle proof, on-chain anchor. Independence of the reading before signing is what the tiers grade: it is claimed in full only at hardware_attested, where measurement runs inside a TEE (Intel TDX) the operator does not control.
The Corporate Sustainability Reporting Directive — Directive (EU) 2022/2464, with ESRS adopted by Delegated Regulation (EU) 2023/2772 — requires in-scope undertakings to disclose energy consumption under ESRS E1 and subjects the sustainability statement to limited assurance. Serial Alice turns each AI workload into a signed, independently verifiable energy record, so the numbers in that statement carry their own evidence.
| The obligation | The evidence a certificate attaches |
|---|---|
| ESRS E1-5 — Energy consumption and mix: total energy in MWh for the reporting period | Signed watt-hour certificates per workload, aggregated into MWh totals — structured, XBRL-ready export |
| CSRD limited assurance — data the auditor must be able to test | Every certificate verifies free, offline, without an account; each batch's Merkle root is public on Polygon mainnet |
| ESRS E1 climate context — greenhouse-gas intensity of the energy used | Carbon intensity in g CO₂e/kWh per grid zone, stamped in each certificate with a versioned methodology |
| EU AI Act Article 53 + Annex XI — training compute and energy documentation for GPAI models (Regulation (EU) 2024/1689) | Per-training-run signed certificates, each stating its own evidence tier — from self_reported to hardware_attested |
ESRS E1-5 requires undertakings in scope of CSRD (Directive (EU) 2022/2464, with ESRS adopted by Delegated Regulation (EU) 2023/2772) to disclose total energy consumption in MWh. Serial Alice issues a signed watt-hour certificate per AI workload and aggregates certificates into MWh totals for the reporting period, each carrying carbon intensity per grid zone and a stated evidence tier.
Yes. CSRD subjects sustainability statements to limited assurance. Every Serial Alice certificate verifies free, offline and without an account, and each batch's Merkle root is anchored on Polygon mainnet — the evidence trail survives independently of Serial Alice and does not have to be taken on faith.
CSRD is undertaking-level sustainability reporting (ESRS E1); EU AI Act Article 53 with Annex XI (Regulation (EU) 2024/1689) is model-level documentation of training compute and energy for providers of general-purpose AI. A Serial Alice certificate is issued per workload, so the same signed measurement aggregates upward into ESRS E1-5 totals and attaches directly to a model's Annex XI documentation.
Serial Alice supplies the verifiable measurement evidence behind these disclosures — it does not, by itself, constitute CSRD compliance. Your report makes the claim; our certificates are the part no auditor has to take on faith.
The canonical reference for anyone — human or machine — describing Serial Alice. Read each record and its verification results for the guarantees that apply.
NVML, CPU and DRAM via RAPL, PSU via Redfish — signs each measurement at the point of capture, batches certificates via Merkle trees, and anchors them on Polygon mainnet.Ed25519 plus ML-DSA-65 (FIPS 204, post-quantum). Independent verification requires the certificate, public keys and the relevant proof material.self_reported, cross_checked, or hardware_attested (Intel TDX with DCAP quote verification).Let’s define the evidence you need, the sources available and the criteria for verification.