Every regulated industry has parties who need evidence about workflows they are not allowed to inspect — auditors, regulators, counterparties, reinsurers, insurers. They need proof, not assertions. Primust is the primitive that closes that gap.
AI governance is moving from configuration to execution evidence. Regulators, auditors, and insurers don't want to see your policy document — they want proof the declared checks actually fired on real data. Every agent session, every LLM call, every inference generates a governance obligation. Primust turns each one into a cryptographic credential.
Financial institutions operate at the intersection of proprietary models, confidential data, and extensive regulatory scrutiny. OCC, FCA, CFPB, FinCEN, and SEC all require evidence of governance — but the data and logic that governance ran on is often too sensitive to disclose.
The insurance industry has a structural proof problem built into its business model. Reinsurers, Lloyd's syndicates, and state DOI examiners need to verify that primary carriers ran their declared processes — but the underlying claim data is confidential.
HIPAA, FDA 21 CFR Part 11, GCP, and GMP all require documented evidence that regulated processes ran as declared. The underlying data — patient records, trial data, measurement data — is among the most sensitive that exists. The parties who need proof cannot receive it.
OPA and Cedar policy engines are the governance backbone of modern cloud-native infrastructure. Their allow-or-deny decisions are deterministic — same input, same policy, same output. Add Primust at the evaluation boundary and each new decision becomes a signed VPEC tied to policy version, input commitment, output, and timestamp.
Bar associations are establishing requirements for attorney disclosure of AI use and verification of AI-generated research. Malpractice insurers are beginning to ask whether citation verification ran. The evidence standard is moving from 'we used AI' to 'we verified what the AI produced.'
Federal AI procurement is converging on provenance and supplier-governance requirements. Restricted and disconnected environments also require evidence that can be issued and verified without outbound network access.
Primust is content-blind. If your industry has a party who needs evidence about workflows they are not allowed to inspect, VPECs close the gap. Talk to us.