Verifiable AI MLOps Governance
01 / 08

Accountable models.
From experiment to production, backed by evidence.

Your data team trains models and saves them in MLflow. MLflow knows which version is the winner, what data it was trained on, and what metrics it achieved. What it lacks, however, is what an audit requires: controls backed by evidence, approval before going into production, and proof of exactly which files were in production on a given date. V-PROOF reads your MLflow, without ever writing to it, and adds those three things.

6Deterministic controls by version, without any language model
0Writes to MLflow: V-PROOF is read-only
1Signed approval before a version goes into production
1 GBper version, fingerprinted by the portal; more with the pipeline script
Demo · 1:48
02 / 08

A model, its versions, and a review of each one.

Recorded on the V-PROOF portal, connected to a demo MLflow: two models, one well governed and another that fails all six evaluated controls.

Video · MLOps Governance V-PROOF
00:45

Connect MLflow in read-only mode and register the model in your project.

00:55

Each version has its own run, training data, metrics, and files.

01:00

Six deterministic checks and approval for transition to production.

01:15

Model V-Seal, entry in the AI registry and public verification without an account.

What's Changing
03 / 08

MLflow knows which version is the winning one.
V-PROOF adds what the auditor requests.

Nothing is duplicated or migrated. The data team continues to work in MLflow; governance monitors, controls, and approves from V-PROOF.

What MLflow Already Has

Experiments, versions, and aliases

Which version is the winner, which run produced it, which datasets were used to train and evaluate it, and what metrics it achieved.

What V-PROOF adds

Evidence-backed controls

Six policies evaluated on what MLflow stores; each verdict is recorded as evidence and as a control self-assessment in the model's entry.

What MLflow Already Has

A production alias that anyone can use

Anyone with write access can mark a version as "champion" without any record of who made the decision or why.

What V-PROOF adds

Pre-production approval

A designated owner approves the deployment. If a version is in production without approval, an alert is triggered in Monitoring. The next run of checks verifies the approval and updates the alert status.

What MLflow Already Has

Files that change over time

The artifacts for a given version are stored in MLflow; there is no proof that today's artifacts are the same ones that were in production on the day of the audit.

What V-PROOF adds

The model V-Seal

The cryptographic fingerprint of each file, dataset and result of the version is sealed and can be verified by anyone, without an account.

The Journey of a Version

The company's MLflow

Tracking URL, basic authentication, or token. Read-only.

AI Registry

The model is entered with the reference MLF-…, provider MLflow, owner and project.

Versions

Execution, training data and evaluation, final metrics, and files.

Six checks

Schema, serialization, requirements, lineage, documentation, and promotion.

Approval

Deployment approved by an owner, with a trusted timestamp.

Model V-Seal

File, data, and result records, sealed with a cryptographic proof.

Public Verification

Anyone can verify the seal using the reference number, without logging in or viewing internal data.

Client SystemV-PROOFCryptographic proof
Six controls, no AI
04 / 08

Each version was evaluated the same way.
Same inputs, rules and sources: same result.

No language model is involved: each control is a rule applied to what MLflow stores. The result is recorded in Governance as evidence and as a self-assessment of the control, in the model’s own entry.

01 · Input

Input schema

The model should specify what data it expects to receive.

None declared: there is no way to check what it receives.

02 · Format

Serialization

The format in which the model was saved.

pickle, cloudpickle, or joblib: formats that can execute code when loaded.

03 · Dependencies

Requirements

Libraries pinned to a specific version and with no known security advisories, according to the public OSV database.

The list is missing, or a library has advisories. Only unpinned: partial.

04 · Data

Data lineage

The execution should log which datasets were used for training.

It does not record any.

05 · Documentation

Description and License

The model's description and license.

Everything is missing. With just one of the two, it's incomplete.

06 · Production

Promotion

A production version must have a V-PROOF approval.

It is in production without approval. Out of production; does not apply.

Two MLflow demo models · verdict by control

credit-risk-classifier v2 · in production · approved
6 / 6
churn-model v1 · in production · unapproved
0 / 6 · alert active
ImplementedPartiallyNot implemented

The six policies appear under "Policies and Controls" after the first run and are managed by the administrator from that point on: changing the prohibited formats or production aliases affects the next evaluation.

Approval and Seal
05 / 08

Before production, someone says yes.

MLflow lets anyone with permission move the production alias. V-PROOF records whether an owner has approved it. Requesting approval creates a pending deployment approval; the approver decides on it in Reviews and Approvals, with a trusted timestamp. The next run of checks verifies the approval and updates the alert’s status.

Model V-Seals: files, data and results.

The seal records proof of exactly what that version was. If nothing has changed, resealing is rejected; a new metric, file, or dataset results in a new seal. Each seal is downloaded as a PNG and PDF along with its manifest and inventory, and anyone can verify it on the public page.

What gets sealed and what leaves the company

SealedThe cryptographic fingerprint of each file in the model, calculated by the portal (up to 1 GB per version) or by the pipeline's auxiliary script.
It is sealedThe training and evaluation datasets, along with the fingerprint assigned to them by MLflow.
It is sealedThe results: parameters, final metrics, and evaluation files.
Data leaves the companyOnly an encrypted manifest of fingerprints and counts. Neither the model, nor the data, nor the value of any metric leaves its infrastructure.
VerifiedUsing the manifest reference on the public verification page: card Model version sealed, with no internal data.
Regulatory Framework
06 / 08

High-risk obligations are met at model level.

The requirements set forth in the European AI Regulation for a high-risk system stem from the model's lifecycle. This is where the evidence either exists or does not exist.

ObligationWhat it requiresWhat it offers V-PROOF
EU AI Act · Art. 10Data and data governanceTraining, validation, and test datasets identified and managed.Data lineage tracking; datasets for each version are displayed on the "Data" screen and and sealed in the model V-Seal.
EU AI Act · Art. 10 11Technical DocumentationDescription of the system, its development, and its performance.Documentation control; versions with execution, parameters, and metrics; downloadable manifest and inventory.
EU AI Act · Art. 10 12Activity LogTraceability of performance throughout the life cycle.Every synchronization, check, approval, and stamp is recorded in the audit trail; a deleted version in MLflow is retained as marked.
EU AI Act · Art. 10 14Human OversightPeople who can make decisions and take action.Approval of deployment by a responsible person prior to production, with verification and an alert if missing.
EU AI Act · Art. 1015: Accuracy and RobustnessDeclared and sustained performance levels.Final metrics for each version are sealed; a change in metrics requires a new seal.
ISO/IEC42001: AI System LifecycleDocumented controls for development, deployment, and operation.Six MLOps policies as controls, with automatic self-assessment and evidence in the AI registry.
In plain terms
07 / 08

What it does and what it doesn't do.

We'd prefer that you know this before the first demonstration.

  • V-PROOF never writes to MLflow or stores the model files: the versions keep the MLflow metadata, and the seals record fingerprints, sizes and paths.
  • Synchronization and checks are triggered manually. A change to an alias in MLflow is detected during the next synchronization or check run, not immediately.
  • The fingerprint that MLflow assigns to a dataset is its own, not a fingerprint of the original file.
  • With MLflow on Databricks, token-based authentication works; reading and calculating file hashes has not been tested. In the meantime, the helper script handles the hashing.
  • A file whose fingerprint has not been calculated by anyone is sealed by name and size only, and the seal says so.
Verifiable AI MLOps Governance
08 / 08

Which versionof "
" is in production,and who approved it?

A technical demo on your own MLflow, with your organization's policies.