The Standard & the Engine
One record. Two lenses. The standard proves it; the Aperture engine runs it.
Confidential · June 2026. The engine and the standard exist today; the seam between them is designed. Live customer measurement and enterprise hardening are the next build — staged through a first design-partner account. We sell the architecture and the wedge, not a finished platform.
The product is two halves built for each other
govrn.ai is a governance standard (the judgment a board, auditor, and regulator accept) and the Aperture engine (a deterministic system of record). The standard reads a typed, read-only view of the engine's record to render posture and attest — the standard calls the engine, never the reverse.
| govrn — the standard | Aperture — the engine | |
|---|---|---|
| Verb | See · Prove | Run |
| Buyer | CISO · board · risk | CTO · CFO · platform |
| Owns | the judgment | the record of fact |
govrn — the standard (built, live)
- Three-lens assessment — technology, security, and AI, productized and repeatable across clients.
- Standards crosswalks — NIST AI RMF · ISO/IEC 42001 · EU AI Act · OWASP · ATLAS · CSF 2.0, mapped to a single control library.
- Independent attestation — accredited, never self-certified. The body that builds is never the body that attests.
- Product-AI review — the AI a company ships (model disclosure, regulated-domain review, disparate-impact) — the part a regulator and a PE owner care about most, and the part no usage-monitoring tool addresses.
Aperture — the engine (built & tested; pre-MVP on live data)
- Deterministic measurement — pure attribution, no model in the measurement path; the same inputs produce byte-identical outputs, which is exactly what makes a measurement attestable.
- Pointers, not payloads — metadata only, enforced in the architecture (no content ever crosses the boundary); survives an enterprise security review.
- Shadow-AI bucket — the AI spend no one owns, surfaced with a dollar figure. The wedge that opens the account.
- Attributed cost & usage — every dollar resolved to a team through inspectable rules; the accounting engine is built and has a passing test suite.
Honest status. Connectors are built and ready for first live integration; the readout runs today on a representative org and goes to measured the moment it connects. We say modeled until then, and never present a synthetic figure as a customer result.
The seam — the load-bearing joint
The shared object is exactly one thing: a typed, read-only, versioned view over the engine's record (attributed events, rollups, the shadow bucket, freshness signals). Aperture computes the truth; govrn renders the posture. The interface carries evidence, not a verdict — the firewall that keeps the attestation independent and therefore worth paying for.
Independence — a feature, not a constraint
Even as one company, the arm that attests stays structurally independent of the arm that builds and runs — the same separation that lets an auditor sign books they didn't keep. It is the reason the verdict is credible to a board, an auditor, or a regulator, and it raises what the engine is worth.
The annuity — why this is a relationship, not a sale
Operate → emits evidence → re-assess → re-baseline, and the loop closes. An attestation is valid only against a fresh record, so continuous measurement is required, not optional. The accumulated, attributed baseline history is the moat — it compounds the longer an estate is measured, and a competitor cannot buy it overnight.