The trust layer for AI

SF2X is the trust app for AI: an open, auditable attestation format and API. Every answer attested is decomposed into atomic claims, independently source-grounded, scored against domain-specific calibration, and signed. Businesses attest, suppress, and re-validate trust over time — so AI output carries a verifiable warrant, not a promise.

Get an API key
Warrant Format v1.1
Look up any trust scorecard (no key needed)

Warrant fields

FieldTypeDescription
warrant_idstringGlobally unique warrant identifier.
answer_version_idstringThe attested answer this warrant backs (lineage id).
premisesstring[]Explicit premises the conclusion depends on. Empty premises invalidate a warrant.
conclusionstringThe warranted conclusion being attested.
confidence_scorenumber (0–1)Independent verifier confidence given the premises.
validity_statusenumvalid = well-supported; weak = mixed; invalid = unsupported/fabricated; expired = premises stale.
sourcesstring[]Cited sources — independently checked during attestation.
expiry_dateISO-8601 datetimeWhen premises must be revalidated.
signed_hashstringHMAC-SHA256 attestation over (answer|premises|sources). Verifiable by anyone holding the SF2X attestation key.

Example warrant

{
  "warrant_id": "w_8f3...",
  "answer_version_id": "av_2c1...",
  "premises": [
    "Aspirin inhibits platelet aggregation.",
    "Primary-prevention benefit in low-risk adults is small and outweighed by bleeding risk."
  ],
  "conclusion": "A 52-year-old with no cardiovascular history should not routinely take daily low-dose aspirin for primary prevention.",
  "confidence_score": 0.82,
  "validity_status": "valid",
  "sources": ["USPSTF 2022 recommendation", "NEJM meta-analysis 2019"],
  "expiry_date": "2026-09-01T00:00:00.000Z",
  "signed_hash": "sf2x_sig_dG9iZUV4YW1wbGU..."
}

API endpoints

Find each function's URL under Dashboard → Code → Functions. Replace $FUNCTION_URL with your provisioned endpoint.

warrantApikey

Inbound attestation. Submit an answer + optional premises/sources; returns verdict, trust, claims, signed warrant.

warrantApix-api-key
curl -X POST $FUNCTION_URL/warrantApi \
  -H "Content-Type: application/json" \
  -H "x-api-key: $SF2X_API_KEY \
  -d '{ "answer_text": "...", "premises": [], "sources": [], "domain": "medicine", "stakes": "high", "model_label": "gpt-5" }'
batchWarrantkey

Attest up to 25 answers at once. Per-item results returned in order.

batchWarrantx-api-key
curl -X POST $FUNCTION_URL/batchWarrant \
  -H "Content-Type: application/json" \
  -H "x-api-key: $SF2X_API_KEY \
  -d '{ "answers": [{ "answer_text": "...", "domain": "finance" }, ...] }'
revalidateWarrantkey

Re-check a previously attested answer against the live web. Detects drift, logs corrections, downgrades stale warrants.

revalidateWarrantx-api-key
curl -X POST $FUNCTION_URL/revalidateWarrant \
  -H "Content-Type: application/json" \
  -H "x-api-key: $SF2X_API_KEY \
  -d '{ "answer_version_id": "av_2c1..." }'
trustScorecardfree

Free, keyless lookup. Returns the trust scorecard for any lineage id — publish it anywhere.

trustScorecard
curl -X POST $FUNCTION_URL/trustScorecard \
  -H "Content-Type: application/json" \
  -d '{ "answer_version_id": "av_2c1..." }'
gateApikey

Callable suppression gate. Returns allow / escalate / suppress for a lineage id so low-trust answers never reach users.

gateApix-api-key
curl -X POST $FUNCTION_URL/gateApi \
  -H "Content-Type: application/json" \
  -H "x-api-key: $SF2X_API_KEY \
  -d '{ "answer_version_id": "av_2c1..." }'

How it fits together

  1. Your model answers → you call warrantApi (or batchWarrant) to attest it.
  2. Before showing the answer to users, call gateApi — suppress if it returns suppress.
  3. Publish the scorecard anywhere via trustScorecard or the /scorecard/:id page.
  4. Schedule revalidateWarrant to catch drift as sources rot and facts change.