Trusted software acceptance environment
Every AI demo works. Your data is where it fails.
And you can't hand your data over to find out.
We test it on your real data in a sealed room in Stockholm. PASS or FAIL, before you pay.
Technical details, and how to check it yourself
The room's answer
- Status
- No run yet.
Check it yourself
curl -sO https://aarloven.com/samples/sealed-sample.json jq -r .Envelope.ct_b64 sealed-sample.json | base64 -d | shasum -a 256 curl -s https://aarloven.com/v1/receipt -H 'content-type: application/json' --data-binary @sealed-sample.json
The second line must print the room's H_ciphertext. With your own package you keep the fingerprint of your data to yourself, so the room can only match it by opening the package.
Why AI purchases go wrong after the demo.
-
The demo isn't your data.
Vendors demo on clean, hand-picked examples. Your records are messy, mixed and incomplete. A good demo shows what it shows; it is not a test of your organisation.
Source: Zen AI Governance
-
You can't hand it over.
A vendor that tests on your personal data becomes your processor: a GDPR Article 28 contract first, and transfer rules if they sit outside the EU. So the test runs on fake data, and proves little.
Source: GDPR, Article 28
-
You find out after you pay.
About 95% of generative-AI pilots show no measurable return, in an MIT study from 2025. Most buyers learn it from the invoice, not the demo.
Source: Fortune, on MIT's report
Your real data, tested where nobody can look.
You and the vendor agree what the delivery must do. The room checks it on your data, and both of you get the same answer.
-
1. You seal it
Your data is locked on your side, with a key only the room's code can use.
AWS KMS releases the key to the room alone. Our own admins are refused.
-
2. The room tests it
The delivery runs against what you agreed, on your data, inside the sealed room.
An AWS Nitro Enclave in Stockholm: no disk, no login, no way to look in.
-
3. You both get the receipt
PASS or FAIL per point, with fingerprints your browser checks. The room keeps nothing.
Every unlock is logged by AWS CloudTrail.
Bring one real case.
An AI tool you are about to pay for, and you are not sure it works on your data? Tell us in a sentence. We will set up the check with you, run it in the sealed room, and you keep the receipt. The first one is on us.
Selling AI into the EU? The same room lets you prove your delivery on a buyer's data without ever seeing it. Tell us in the box above.
What is true today, and what comes next.
Today
- The room runs in Stockholm (EU)
- The key is released only to the room (AWS KMS)
- A changed package is refused
- Fingerprint check in your browser
- Every unlock logged by AWS CloudTrail
Next
- AWS hardware signature on each receipt
- Signed, chained receipts
- The room streams each step live
- Published room code
- Your own key
How each of these was checked: the security brief →