Verifiable AI MLOps Governance
01 / 08

Accountable models.
From experiment to production, backed by evidence.

Your data team trains models and saves them in MLflow. MLflow knows which version is the winner, what data it was trained on, and what metrics it achieved. What it lacks, however, is what an audit requires: controls backed by evidence, approval before going into production, and proof of exactly which files were in production on a given date. V-PROOF Read your MLflow—without ever writing to it—and add those three things.

6Deterministic controls by version, without any language model
0Writing in MLflow: V-PROOF read-only
1Signed approval before a version goes into production
1 GBper version, with the footprint calculated by the portal; plus, with the pipeline script
Demo · 1:48
02 / 08

A model, its versions, and a review of each one.

Recorded on the Portal V-PROOF Connected to a demo MLflow: two models, one that is well-governed and another that fails all six evaluated checks.

Video · MLOps Governance V-PROOF
00:45

Connect MLflow in read-only mode and register the model in your project.

00:55

Each version has its own run, training data, metrics, and files.

01:00

Six deterministic checks and approval for transition to production.

01:15

Model V-Seal, entry in the AI registry and public verification without an account.

What's Changing
03 / 08

MLflow knows which version is the winning one.
V-PROOF Add what the auditor requests.

Nothing is duplicated or migrated. The data team continues to work in MLflow; governance monitors, controls, and approves from V-PROOF.

What MLflow Already Has

Experiments, versions, and aliases

Which version is the winner, which run produced it, which datasets were used to train and evaluate it, and what metrics it achieved.

What it adds V-PROOF

Evidence-Based Controls

Six policies were evaluated based on what MLflow stores; each verdict serves as evidence and as a self-assessment of the control at the model's input.

What MLflow Already Has

A production alias that anyone can use

Anyone with write access can mark a version as " champion," without any record of who made the decision or why.

What it adds V-PROOF

Pre-production approval

A designated person approves the deployment by signing off on it. If a version is in production without approval, an alert is triggered in Monitoring. The next run of checks verifies the approval and updates the alert status.

What MLflow Already Has

Files That Change Over Time

The artifacts for a given version are stored in MLflow; there is no proof that today's artifacts are the same ones that were in production on the day of the audit.

What it adds V-PROOF

The Model V-Seal

The cryptographic fingerprint of each file, dataset, and version result— sealed —is cryptographically verified and can be verified by anyone, without an account.

The Journey of a Version

The company's MLflow

Tracking URL, basic authentication, or token. Read-only.

AI Registry

The model is entered with the reference MLF-…, supplier MLflow, contact person, and project.

Versions

Execution, training data and evaluation, final metrics, and files.

Six checks

Schema, serialization, requirements, lineage, documentation, and promotion.

Approval

Deployment approved by a responsible person, with certification.

Model V-Seal

File, data, and result records, sealed with a cryptographic proof.

Public Verification

Anyone can verify the seal using the reference number, without logging in or viewing internal data.

Client SystemV-PROOFCryptographic Test
Six controls, no AI
04 / 08

Each version was evaluated the same way.
Same inputs, rules, and fonts: same result.

No language model is involved: each control is a rule stored by MLflow. The result is recorded in Governance as evidence and as a self-assessment of the control, in the model’s own entry.

01 · Home

Input Diagram

The model should specify what data it expects to receive.

No one reports anything: no one can verify the information they receive.

02 · Format

Serialization

The format in which the model was saved.

pickle, cloudpickle, or joblib: formats that can execute code when loaded.

03 · Facilities

Requirements

Libraries pinned to a specific version and with no known security advisories, according to the public OSV database.

The list is missing, or a bookstore has notices. Just not pinned: partial.

04 · Data

Data lineage

The execution should log which datasets were used for training.

It does not record any.

05 · Documentation

Description and License

The model's description and license.

Everything is missing. With just one of the two, it's incomplete.

06 · Production

Promotion

That a production version has an approval of V-PROOF.

It is in production without approval. Out of production; does not apply.

Two MLflow demo models · verdict by control

credit-risk-classifier v2 · in production · approved
6 / 6
churn-model v1 · in production · unapproved
0 / 6 · alert active
ImplementedPartiallyNot implemented

The six policies appear under "Policies and Controls" after the first run and are managed by the administrator from that point on: changing the prohibited formats or production aliases affects the next evaluation.

Approval and Seal
05 / 08

Before production, someone says yes.

MLflow allows anyone with permission to move the production alias. V-PROOF It records whether a responsible person has approved it. Requesting approval creates a pending deployment approval; the approver decides on it in Reviews and Approvals, with their acknowledgment. The next run of checks verifies the approval and updates the alert’s status.

V-Seal s of the model: files, data, and results.

seal It records proof of exactly what that version was. If nothing has changed, seal is rejected again; a new metric, file, or dataset results in a new seal. Each seal is downloaded as a PNG and PDF along with its manifest and inventory, and anyone can verify it on the public page.

What comes into the plant and what leaves the company

SealedThe cryptographic fingerprint of each file in the template, calculated by the portal (up to 1 GB per version) or by the pipeline's auxiliary script.
It is sealedThe training and evaluation datasets, along with the fingerprint assigned to them by MLflow.
It is sealedThe results: parameters, final metrics, and evaluation files.
Data leaves the companyOnly an encrypted manifest of traces and counts. Neither the model, nor the data, nor the value of any metric leaves its infrastructure.
VerifiedUsing the manifest reference on the public verification page: card Model Version sealed, with no internal data.
Regulatory Framework
06 / 08

High-risk bonds are accounted for at the model level.

The requirements set forth in the European AI Regulation for a high-risk system stem from the model's lifecycle. This is where the evidence either exists or does not exist.

ObligationWhat is being requested?What it offers V-PROOF
European AI Regulation · Art.10: Data and Data GovernanceTraining, validation, and test datasets identified and managed.Data lineage tracking; datasets for each version are displayed on the "Data" screen and at sealed in the Model V-Seal.
European AI Regulation · Art. 11Technical DocumentationDescription of the system, its development, and its performance.Documentation control; versions with execution, parameters, and metrics; downloadable manifest and inventory.
European AI Regulation · Art. 12Activity LogTraceability of performance throughout the life cycle.Every synchronization, check, approval, and stamp is recorded in the audit trail; a deleted version in MLflow is retained as marked.
European AI Regulation · Art. 14Human OversightPeople who can make decisions and take action.Approval of deployment by a responsible person prior to production, with verification and an alert if missing.
European AI Regulation · Art.15: Accuracy and RobustnessDeclared and sustained performance levels.Final metrics for each version are stamped; a change in metrics requires a new stamp.
ISO/IEC42001: AI System LifecycleDocumented controls for development, deployment, and operation.Six MLOps policies, such as controls with automatic self-assessment and evidence in the AI log.
Honestly
07 / 08

What it does and what it doesn't do.

We'd prefer that you know this before the first demonstration.

  • V-PROOF It never writes to MLflow or saves the model files: the versions preserve the MLflow metadata, and the timestamps record timestamps, sizes, and paths.
  • Synchronization and checks are triggered manually. A change to an alias in MLflow is detected during the next synchronization or check run, not immediately.
  • The fingerprint that MLflow assigns to a dataset is its own, not a fingerprint of the original file.
  • With MLflow on Databricks, token-based authentication works; reading and calculating file hashes has not been tested. In the meantime, the helper script handles the hashing.
  • A file whose fingerprint has not been calculated by anyone is stamped based solely on its name and size, and the stamp indicates this.
Verifiable AI MLOps Governance
08 / 08

Which versionof "
" is in production,and who approved it?

Technical demonstration using your own MLflow, with your organization's policies.