Plain layer · ten-second read

You deploy a product built on someone else's AI model. An auditor, a regulator, or a large customer asks you to prove you are monitoring that model for behavioral change, and that your own logs are not the only evidence. Modelometer gives you a dated, independent record and a monthly statement you can drop straight into that file: either what changed and when, or a proven quiet period. The evidence is written by an outside party, so it settles the question your own logs cannot.

The situation

Post-market monitoring, vendor-risk review, and AI-assurance audits increasingly ask the same thing: show that the behavior of the model you deploy is watched over time, by evidence that is not just your word. Your internal logs are written by the interested party and see only your own traffic. When an auditor asks for proof of monitoring, self-authored logs are the weakest form of it.

What Modelometer gives you here

Worked example

Illustrative.

Your assurance lead is preparing an audit file for a model you depend on. Illustratively, over a year of coverage the file accumulates twelve monthly attestations: ten report a proven quiet period, each with its resolvable-movement bound, and two report a confirmed behavioral change, each with the date, the plain-language description, and the record entry an auditor can verify. The file then shows continuous, independent monitoring, with two caught events and ten evidenced quiet months, none of it authored by you.

What to do with it

Keep the monthly attestation in your post-market monitoring or vendor-risk file as the independent monitoring record. When an auditor asks how you monitor the model, hand them the attestations and the record reference rather than your own logs. When a change is disputed, the dated entry predates the conversation.

Technical layer · rigor intact

The attestation states, per watched endpoint, the readings taken in the period, the state of each (no material change, or a confirmed published change), and the smallest movement the readings could have resolved, so a quiet month is a bounded claim rather than an assurance. Each reading references its entry in the append-only record; entries are hash-chained, so their order is independently verifiable from the public JSON, and external timestamping (OpenTimestamps anchoring) is being added so the dates verify without trusting the bureau either. A behavioral change is named only when confirmed and reproduced; serving-integrity signals sit on their own channel and are never reported as behavioral findings. The file carries states and dated evidence, never adjectives about the model.

?

Common questions

Does the auditor have to trust Modelometer?

As little as possible. The record is append-only and hash-chained, so entries cannot be silently rewritten and the auditor checks them directly from the public JSON; external timestamping is being added so the dates verify without trusting us either. Our role is to run one frozen protocol and record it, not to be believed.

Is a quiet month worth filing?

Yes. A proven quiet period, with the bound on what it could have resolved, is evidence of monitoring; the file's value is continuity, not only incidents.

Does this replace our internal monitoring?

No. It is the independent layer beside your own logs, and the value is precisely that it is not authored by you.