Accountable models.
From experiment to production, backed by evidence.
Your data team trains models and saves them in MLflow. MLflow knows which version is the winner, what data it was trained on, and what metrics it achieved. What it lacks, however, is what an audit requires: controls backed by evidence, approval before going into production, and proof of exactly which files were in production on a given date. V-PROOF reads your MLflow, without ever writing to it, and adds those three things.
A model, its versions, and a review of each one.
Recorded on the V-PROOF portal, connected to a demo MLflow: two models, one well governed and another that fails all six evaluated controls.
Connect MLflow in read-only mode and register the model in your project.
Each version has its own run, training data, metrics, and files.
Six deterministic checks and approval for transition to production.
Model V-Seal, entry in the AI registry and public verification without an account.
MLflow knows which version is the winning one.
V-PROOF adds what the auditor requests.
Nothing is duplicated or migrated. The data team continues to work in MLflow; governance monitors, controls, and approves from V-PROOF.
Experiments, versions, and aliases
Which version is the winner, which run produced it, which datasets were used to train and evaluate it, and what metrics it achieved.
Evidence-backed controls
Six policies evaluated on what MLflow stores; each verdict is recorded as evidence and as a control self-assessment in the model's entry.
A production alias that anyone can use
Anyone with write access can mark a version as "champion" without any record of who made the decision or why.
Pre-production approval
A designated owner approves the deployment. If a version is in production without approval, an alert is triggered in Monitoring. The next run of checks verifies the approval and updates the alert status.
Files that change over time
The artifacts for a given version are stored in MLflow; there is no proof that today's artifacts are the same ones that were in production on the day of the audit.
The model V-Seal
The cryptographic fingerprint of each file, dataset and result of the version is sealed and can be verified by anyone, without an account.
The Journey of a Version
The company's MLflow
Tracking URL, basic authentication, or token. Read-only.
AI Registry
The model is entered with the reference MLF-…, provider MLflow, owner and project.
Versions
Execution, training data and evaluation, final metrics, and files.
Six checks
Schema, serialization, requirements, lineage, documentation, and promotion.
Approval
Deployment approved by an owner, with a trusted timestamp.
Model V-Seal
File, data, and result records, sealed with a cryptographic proof.
Public Verification
Anyone can verify the seal using the reference number, without logging in or viewing internal data.
Each version was evaluated the same way.
Same inputs, rules and sources: same result.
No language model is involved: each control is a rule applied to what MLflow stores. The result is recorded in Governance as evidence and as a self-assessment of the control, in the model’s own entry.
Input schema
The model should specify what data it expects to receive.
None declared: there is no way to check what it receives.
Serialization
The format in which the model was saved.
pickle, cloudpickle, or joblib: formats that can execute code when loaded.
Requirements
Libraries pinned to a specific version and with no known security advisories, according to the public OSV database.
The list is missing, or a library has advisories. Only unpinned: partial.
Data lineage
The execution should log which datasets were used for training.
It does not record any.
Description and License
The model's description and license.
Everything is missing. With just one of the two, it's incomplete.
Promotion
A production version must have a V-PROOF approval.
It is in production without approval. Out of production; does not apply.
Two MLflow demo models · verdict by control
The six policies appear under "Policies and Controls" after the first run and are managed by the administrator from that point on: changing the prohibited formats or production aliases affects the next evaluation.
Before production, someone says yes.
MLflow lets anyone with permission move the production alias. V-PROOF records whether an owner has approved it. Requesting approval creates a pending deployment approval; the approver decides on it in Reviews and Approvals, with a trusted timestamp. The next run of checks verifies the approval and updates the alert’s status.
Model V-Seals: files, data and results.
The seal records proof of exactly what that version was. If nothing has changed, resealing is rejected; a new metric, file, or dataset results in a new seal. Each seal is downloaded as a PNG and PDF along with its manifest and inventory, and anyone can verify it on the public page.
What gets sealed and what leaves the company
Model version sealed, with no internal data.High-risk obligations are met at model level.
The requirements set forth in the European AI Regulation for a high-risk system stem from the model's lifecycle. This is where the evidence either exists or does not exist.
| Obligation | What it requires | What it offers V-PROOF |
|---|---|---|
| EU AI Act · Art. 10Data and data governance | Training, validation, and test datasets identified and managed. | Data lineage tracking; datasets for each version are displayed on the "Data" screen and and sealed in the model V-Seal. |
| EU AI Act · Art. 10 11Technical Documentation | Description of the system, its development, and its performance. | Documentation control; versions with execution, parameters, and metrics; downloadable manifest and inventory. |
| EU AI Act · Art. 10 12Activity Log | Traceability of performance throughout the life cycle. | Every synchronization, check, approval, and stamp is recorded in the audit trail; a deleted version in MLflow is retained as marked. |
| EU AI Act · Art. 10 14Human Oversight | People who can make decisions and take action. | Approval of deployment by a responsible person prior to production, with verification and an alert if missing. |
| EU AI Act · Art. 1015: Accuracy and Robustness | Declared and sustained performance levels. | Final metrics for each version are sealed; a change in metrics requires a new seal. |
| ISO/IEC42001: AI System Lifecycle | Documented controls for development, deployment, and operation. | Six MLOps policies as controls, with automatic self-assessment and evidence in the AI registry. |
What it does and what it doesn't do.
We'd prefer that you know this before the first demonstration.
- V-PROOF never writes to MLflow or stores the model files: the versions keep the MLflow metadata, and the seals record fingerprints, sizes and paths.
- Synchronization and checks are triggered manually. A change to an alias in MLflow is detected during the next synchronization or check run, not immediately.
- The fingerprint that MLflow assigns to a dataset is its own, not a fingerprint of the original file.
- With MLflow on Databricks, token-based authentication works; reading and calculating file hashes has not been tested. In the meantime, the helper script handles the hashing.
- A file whose fingerprint has not been calculated by anyone is sealed by name and size only, and the seal says so.
Which versionof "
" is in production,and who approved it?
A technical demo on your own MLflow, with your organization's policies.
