Aarloven

Trusted software acceptance environment

Every AI demo works. Your data is where it fails.

And you can't hand your data over to find out.

We test it on your real data in a sealed room in Stockholm. PASS or FAIL, before you pay.

The sealed sample· sealed room, Stockholm
—
    A replay of a real run. Press Run the sealed sample for a live one. Ask your vendor to take the test Security brief →
    Technical details, and how to check it yourself

    The room's answer

    Status
    No run yet.

    Check it yourself

    curl -sO https://aarloven.com/samples/sealed-sample.json
    jq -r .Envelope.ct_b64 sealed-sample.json | base64 -d | shasum -a 256
    curl -s https://aarloven.com/v1/receipt -H 'content-type: application/json' --data-binary @sealed-sample.json

    The second line must print the room's H_ciphertext. With your own package you keep the fingerprint of your data to yourself, so the room can only match it by opening the package.

    Check your own sealed package

    Why AI purchases go wrong after the demo.

    • The demo isn't your data.

      Vendors demo on clean, hand-picked examples. Your records are messy, mixed and incomplete. A good demo shows what it shows; it is not a test of your organisation.

      Source: Zen AI Governance

    • You can't hand it over.

      A vendor that tests on your personal data becomes your processor: a GDPR Article 28 contract first, and transfer rules if they sit outside the EU. So the test runs on fake data, and proves little.

      Source: GDPR, Article 28

    • You find out after you pay.

      About 95% of generative-AI pilots show no measurable return, in an MIT study from 2025. Most buyers learn it from the invoice, not the demo.

      Source: Fortune, on MIT's report

    Your real data, tested where nobody can look.

    You and the vendor agree what the delivery must do. The room checks it on your data, and both of you get the same answer.

    1. 1. You seal it

      Your data is locked on your side, with a key only the room's code can use.

      AWS KMS releases the key to the room alone. Our own admins are refused.

    2. 2. The room tests it

      The delivery runs against what you agreed, on your data, inside the sealed room.

      An AWS Nitro Enclave in Stockholm: no disk, no login, no way to look in.

    3. 3. You both get the receipt

      PASS or FAIL per point, with fingerprints your browser checks. The room keeps nothing.

      Every unlock is logged by AWS CloudTrail.

    Bring one real case.

    An AI tool you are about to pay for, and you are not sure it works on your data? Tell us in a sentence. We will set up the check with you, run it in the sealed room, and you keep the receipt. The first one is on us.

    We keep only these two answers, to reply to you. Stored in the EU (Cloudflare D1, EU jurisdiction) and deleted after 90 days. No cookies, no trackers.

    Selling AI into the EU? The same room lets you prove your delivery on a buyer's data without ever seeing it. Tell us in the box above.

    What is true today, and what comes next.

    Today

    • The room runs in Stockholm (EU)
    • The key is released only to the room (AWS KMS)
    • A changed package is refused
    • Fingerprint check in your browser
    • Every unlock logged by AWS CloudTrail

    How each of these was checked: the security brief →