Skip to content
Open Governance Standard

The T.R.U.S.T. Framework

T.R.U.S.T. is an open governance standard for responsible AI deployment — not SpanForge IP. Any organisation can adopt it. SpanForge is the reference implementation, built to make adoption production-ready with no additional overhead.

The five dimensions
T

Transparency

Customers, regulators, and employees understand how AI affects them. AI behaviour is made intelligible to all affected parties — not just technical teams.

R

Responsibility

A named human is accountable for every AI system. AI cannot be deployed without a designated owner who carries accountability for its behaviour in production. Responsibility extends to cost: the Cost Intelligence Layer makes infrastructure spend visible at Design time and measures actual token costs in production via the SpanForge llm.cost.* namespace — ensuring accountable owners understand the financial implications before committing to them.

U

User Rights

Consent, transparency, and recourse for every individual AI affects. Users have the right to understand how AI decisions affect them and to seek redress where required.

S

Safety Guardrails

Technical constraints embedded in architecture, not just policy. Safety mechanisms are built into the system — not left as aspirational guidance or documents.

T

Traceability

Every AI decision must be traceable to its source data, model version, and configuration state. Full audit trail. No black boxes. Every decision is logged with an immutable, timestamped, cryptographically signed record — ready for regulators, auditors, and post-incident review.

Operationalisation

Embedded across three platform phases

The T.R.U.S.T. Framework is not applied at the end of delivery — it is embedded as technical controls across the Design, Govern, and Scale phases.

Design phase (Cost Intelligence Layer) — cost accountability is embedded via the Cost Readiness dimension of the Gate Readiness Score™. Responsible owners must understand and document the financial implications of architecture decisions before any resource is committed — evidenced via a documented cost estimate with scenario comparison.

Govern phase — compliance mapping (including EU AI Act risk categorisation), live risk registers, governance maturity assessment, and board-level reporting packs, all structured around the five T.R.U.S.T. dimensions.

Scale phase (SpanForge) — technical enforcement of Traceability (immutable HMAC-signed audit trail via RFC-0001 SpanForge), User Rights (consent boundary monitoring via the consent namespace), and Safety Guardrails (automated playbooks on guard and hitl events) in production. Cost attribution is recorded on every SpanForge event as part of the same tamper-evident chain — neither Traceability nor cost accountability is left to human process alone.

SpanForge certification

What SpanForge-certified means

A SpanForge-certified AI system has completed the full five-phase lifecycle, passed all six Build gates, satisfied every T.R.U.S.T. dimension in the Govern phase, and has SpanForge active in production. Certification is self-attested by the named Gate Authority sponsor, supported by the complete audit trail of gate records, risk registers, and incident playbooks.

See it operationalised.

The T.R.U.S.T. Framework is embedded in the Govern phase — with EU AI Act compliance mapping, risk registers, and board-ready reporting.

Explore the Govern Phase →