CRUMB a card from devarno-cloud

The One-Page Message for a Regulated Buyer

vest beginner 4 min read

What this means for you

Three sentences carry the entire message. Sentence one names the audit a regulator will run. Sentence two names the artefact VEST produces that satisfies it. Sentence three names a system the buyer already trusts so the comparison is short. Everything else on the page is proof.

The pitch

“Your auditor is going to ask you to prove three things, in writing: that an event happened, who attested to it, and that no one rewrote the record afterwards. VEST gives you a verifiable log that answers all three, built on the same Merkle tree primitive that Google has used for Certificate Transparency since 2013. The first deployments are with law firms running contract workflows, and AI platform teams logging automated decisions for the EU AI Act.”

Who it’s for

The head of compliance, the head of legal, and the platform engineer who has been told to find an audit-trail vendor by the next quarterly review.

Proof points

  • Three sentences map one-to-one to three regulations cited in the source research: SOC2 Type II evidence (sentence one), eIDAS qualified signatures (sentence two), Certificate Transparency precedent (sentence three)
  • “Built on the same primitive Google uses” is verifiable in public: Google’s CT log infrastructure runs on Trillian, and the VEST research roadmap is explicit about the Trillian and Tessera lineage
  • Two named first deployments grounded in the research validation plan: law-firm beta for contract edits, AI platform logging for EU AI Act Article 12 record-keeping, with the latter coming online before the August 2026 enforcement date
  • Cost framing for the buyer is named: an EU AI Act non-compliance fine ceiling of 35 million euros or 7 percent of turnover dwarfs any audit-tooling line item, and the research projects 50 to 60 percent reductions in assessment cost from automating the logging step
journey
title Compliance buyer reads the one-pager
section Sentence one: the audit
Recognises their own audit cycle: 5: Buyer
Reads regulation name: 4: Buyer
section Sentence two: the artefact
Sees the named output: 5: Buyer
Maps it to procurement language: 4: Buyer
section Sentence three: the analogue
Recognises Certificate Transparency: 4: Buyer
Lowers technical risk in their head: 5: Buyer
section Proof points
Reads named deployments: 5: Buyer
Books a demo: 5: Buyer

neighbors on the map