DDC Assurance Lab is not an accredited laboratory.

Independent systems assurance

Evidence before confidence.

DDC Assurance Lab evaluates AI, agentic, and software systems through explicit scope, adversarial verification, evidence integrity, and reproducible technical assessment.

What we assess

Technical claims that need to survive challenge.

DDCAL is being built for systems where a simple demonstration or implementation claim is not enough.

Authority

Authority boundaries

Whether a system can act beyond the authority, permissions, or delegation it was intended to receive.

Conformance

Implementation conformance

Whether the implemented system conforms to identified requirements, controls, or declared behaviour.

State

Transition assurance

Whether proposed or executed state changes are authorized, valid, bounded, and recoverable.

Evidence

Evidence integrity

Whether evidence actually substantiates the conclusion and preserves provenance, lineage, and context.

Adversarial

Failure behaviour

How the system behaves under malformed, hostile, ambiguous, incomplete, or contradictory conditions.

Verification

Verifier independence

Whether verification is sufficiently independent from the producer’s critical assumptions and failure paths.

Assessment lifecycle

From claim to controlled conclusion.

Every assessment is bounded by defined authority, requirements, evidence, and verification conditions.

DefineAuthority, scope, requirements, and exclusions.
ChallengeTest preconditions, boundaries, and adverse paths.
ObserveCollect traceable evidence of execution and state.
VerifyCheck conclusions against independent evidence and invariants.
ReportIssue a bounded result with evidence and limitations.

Public accountability

Controlled publications

Public methodology, quality documents, and controlled revisions will be registered with status and version information rather than silently replaced.

View publication registry →

Assessment inquiries

Start with scope, not uploads.

Initial inquiries are intentionally low-risk. Do not send confidential evidence, credentials, executables, or sensitive datasets by ordinary email.

How to request an assessment →