Histor Labs

Open-source infrastructure for EU AI Act Article 57 regulatory sandboxes

Histor

A regulator can supervise a high-risk AI system, and a notified body can verify the outcome, without anyone seeing personal data and without trusting the provider or the platform operator.

In Homer, the histor is the witness who knows the facts and settles a dispute.

How it works

One test run, in order

The provider brings a model, the regulator brings a signed test plan, and the host runs the test.

  1. The model runs isolated, with no network, at the host.

    On Kubernetes with default-deny networking, or on Slurm at an HPC centre. Whatever the model tries to reach is dropped and logged.

  2. The test data stays sealed.

    It is decrypted only inside the test harness, never handed to the provider, the regulator or the operator.

  3. Results are signed where they are measured.

    The harness signs each result as it produces it, so a number cannot be changed on its way to the report.

  4. Every action goes into a hash-chained ledger.

    Each entry is linked to the one before it and timestamped externally, so the record cannot be rewritten after the fact.

  5. At exit, the keys are destroyed.

    Once the run ends, the data can no longer be decrypted on the platform.

  6. Anyone can re-check the evidence bundle offline.

    The free verifier runs on your own machine, without network access and without an account.

The film

One supervised test run on a cluster

Three minutes, silent and captioned. An age-estimation model is tested, a hostile model is contained, and the evidence is verified offline.

3 min · silent · captioned Kubernetes · default-deny networking Download MP4

Who it is for

Each party keeps what is theirs

National competent authorities and data-protection authorities
Supervise a test remotely against your own signed plan, and sign the exit report.
AI Factories, TEFs and HPC centres
Accept confidential participations on your own infrastructure.
Notified bodies
Verify the outcome offline with the free verifier.
Providers
Have a model tested without handing over its weights, and without receiving the test data.

Open by design

Licensed EUPL-1.2

Histor is open-source software, licensed under the EUPL-1.2.

An open verifier means a notified body does not have to take our word, or anyone's, for what a run showed.

What Histor Labs offers

  • Deployment at the host
  • A supported release line
  • Testing work