Questions

Checked against the code, not against the brochure. Where something is built and not yet proven, it says so.

What runs on my own hardware, and what does it need?

That depends on which of the two deployments you are on, and the honest answer names both. On the invitation-bound beta, nothing but a web browser: the crawler, the analysis, the database and the sealing run on infrastructure we operate in New Zealand or the EU, there is no client to keep patched, and the minimum specification is whatever runs your browser.

There is also an install kit for running AVA on your infrastructure, and that is a design requirement rather than something bolted on later. It carries its own schema and migrations and does not need a service of ours to crawl a site or analyse what it finds. The crawl then reaches your site from your network rather than ours.

Two parts stay with us, for different reasons. The sealing does, because a seal you generate yourself proves nothing to a third party — the whole value of the record is that an independent party made it. And the models you sample are your choice: either you point the install at our inference service, or you supply your own commercial API keys and it calls those providers under your account. The first needs nothing of you but the install; the second assumes you already hold keys and know what they cost.

How you get it: the kit is issued, not published. There is no trial and no free tier — that is an access ruling rather than a technical limit, and the two should not be confused. Running AVA yourself is a commercial arrangement, and for partners reselling it to their own clients it is the intended shape rather than an exception.

How long does an audit take?

Measured on 21 September 2026 against a real site: eight pages fetched in 42 seconds, about one second per page including the pause between requests. A 25-page crawl is roughly half a minute; the 500-page maximum is a few minutes.

It is bounded by the page limit you set and by our politeness delay, not by processing power. You start it and come back — nothing depends on your machine staying awake. That figure is one measurement of one small site and is offered as an order of magnitude, not a service level.

Does a run produce a timestamped record I can rely on later, and how would I test it?

Tamper-evident, never immutable, and the distinction is the product. Nothing we build prevents a record being altered. The seal makes alteration detectable by someone who does not trust us: the record is hashed, signed, and stamped by an independent authority, so a later change breaks the chain and anybody can see that it did.

A sampling batch is sealed as a whole — one hash covering every observation in it — and the result is written to every record in the batch. To test it, recompute an observation’s hash from the stored answer, find it among the batch’s leaves, recompute the root, and check that against the stamp. Change one character of the recorded answer and the root will not match.

Stated plainly: the seal has been built and has not yet run on a live audit. The machinery is complete and the paths are wired. Until it has run, any description of how you would receive and keep a sealed record describes an intention rather than an experience. The independent verification bundle — the thing that would let you check a record entirely offline, without us — is specified and not built.

What is SSST, and where does it run?

Sovereign Sealed, Signed and Timestamped. The name is the mechanism, in order. A record is sealed so its contents are fixed to a hash; signed so the seal is attributable and cannot be forged; timestamped by an independent authority so the moment it existed is attested by someone other than us; and sovereign because all of that happens on infrastructure in a jurisdiction you chose, with no US-owned cloud in the chain.

Take any one away and the record stops proving what it claims. Unsealed it can be edited; unsigned it can be fabricated; unstamped it has no date anybody else will accept; and without sovereignty it sits under a legal regime you did not pick.

It runs on our infrastructure, not yours, and that is what makes it worth anything: a seal you could generate yourself would prove nothing to a third party. It is the substrate underneath AVA and the other record products, and it stays with My Digital Sovereignty Ltd.

Whose key signs my records?

Ours. Every customer’s records are sealed under a single estate key, and the verification page resolves against the estate’s published identity. We are acting as an independent custodian — that is the role, and it is the reason the record means something to a third party who has no reason to trust either of us.

So the record is held and attested on your behalf; it is not signed with a key you hold. Anyone telling you otherwise about a hosted verification service is describing something different.

Is the whole thing sovereign?

The record is: held in New Zealand or the EU, no US-owned cloud in the chain, sealed by a custodian in that jurisdiction.

The measurement cannot be. Finding out what OpenAI or Perplexity say about you means asking OpenAI and Perplexity, and they are US companies; your questions and their answers travel to them. A tool claiming a fully sovereign chain while sampling US models would be claiming something impossible.

What does this give me that a tool built on a proprietary stack does not?

Your data sits in a jurisdiction you chose. Not a preference setting — there is no US cloud to opt out of.

The finding can be checked by someone who does not trust us. A tool reporting a score inside its own dashboard asks you to take its word; a sealed, independently timestamped record does not.

The limits are in the artefact. Where a timestamp is not legally qualified, the record says so. Where a verdict is non-authoritative, it is labelled that in the data rather than in a footnote.

You are told what was measured, not only what was concluded — every page fetched, its status, its hash, its robots verdict, and which model answered which question.

What is AVA, in two paragraphs?

People increasingly ask an AI assistant rather than a search engine. When somebody asks what your organisation does, whether you serve their region, or who they should use for the thing you sell, a model answers — from whatever it has absorbed, which may be outdated, partial, or about a competitor. AVA measures that. It puts the questions your buyers actually ask to AI systems, records what comes back, and compares those answers against what your site actually publishes. Where a model says something your own pages contradict, that gap is the finding.

The reason to point it at your site is that this is currently invisible to you. Analytics show who arrived; they cannot show the conversations where you were described wrongly, described as someone else, or not mentioned at all. AVA makes that measurable, records each measurement as evidence you can put in front of a board or a regulator, and runs it on infrastructure inside a jurisdiction you chose. It is not a ranking tool and does not promise to change what a model says — it tells you what is being said and what on your own site supports or contradicts it.

What is not finished?

The seal has not yet run on a live audit. The offline verification bundle is specified and not built. Authoritative policy verdicts need infrastructure that is not yet stood up, so sandbox verdicts are labelled non-authoritative in the data. A queued crawl needs a worker process running, and if it is not, the crawl waits rather than failing — tell us and we will start it.

All of that is on this page for the same reason the rest of it is: you are buying a record you can show to somebody else, and a vendor who hides its own gaps is not selling that.

The longer explanation is under how it works.