Products Lemma APIProof issuance & verification platformTrust402Delegate to agents, and transactSealSign-in for the agent era — no keys handed over
Use cases Manufacturing & Critical InfraInspection Record AssuranceFinance & FinTechCounterparty Record VerificationPublic SectorCertificate-less ProceduresHealthcareQualified Worker AssuranceProcurement & Supply ChainSupplier Credential MonitoringMedia & ContentContent AuthenticityService & RetailCross-group IdentityAI Adoption (cross-industry)AI Run GovernanceDevelopers & Agent OpsAgent Authority Control ▸ Browse the use-case index
Pricing
Resources Critical BriefThe frontier of AI × trustBlogThinking and implementation notesDocumentationAPI & specsVerification CenterReal verification & issuance countsAbout usFRAME00, Inc.ContactSales & press inquiriesGlossaryDefinitionsFAQFrequently asked questions
Get Started ↗ JA

Blog

Making AI decisions — and the records your teams produce — something anyone can verify later. How to weigh adoption, and where it pays off first.

FeaturedFeatured
Announcements ·

Proving residents' activity records are genuine — without exposing personal data

Lemma has been integrated into MizuDAkO, which supports community building around resident-led maintenance of water and sewerage infrastructure. Records created in the field can prove their authenticity without revealing any personal data, becoming dependable data that AI can rely on as evidence. The design runs comfortably under demanding conditions, including legacy devices and limited connectivity. The plan is Lemma Civic, the base plan for local government.

Read →
All articlesAll — 30
Technical ·

An audit trail for MCP tool calls that anyone can check afterwards

In August 2026 a CVSS 9.1 deserialization RCE landed in Splunk MCP Server (CVE-2026-76404). Its precondition is the Splunk admin role — authentication passed, role checks passed, and arbitrary OS commands ran anyway. OAuth and RBAC stop working the moment a call begins, and whether the record left behind is genuine is a separate problem. Here is how to register each MCP tool call with a commitment and let a third party verify it without an API key, in code that was actually run.

Read →
Solutions ·

Records that hold up later. Make incident and complaint records tamper-proof

Hotels, restaurants, retailers and shopping centers all keep a record of when and how they handled a food-poisoning complaint or an injury. What no reader of that record can establish is whether it was edited afterwards. Fix the contents at the moment they are saved and head office no longer has to pull the original from the site: it can check the record in hand against the value registered at the time, on the spot, and confirm one thing only — that the response followed proper procedure and authority. The customer data and the details of the response are never disclosed.

Read →
Solutions ·

Reconcile without opening the books. A smoother month-end for stablecoin payments

With yen-denominated stablecoins, the transfer itself already settles in minutes. For a business that books hundreds or thousands of payments a month, scanning on-chain events is not enough. The totals do not agree, and you cannot tell which transaction is wrong — because the breakdown never travelled with the transfer. Lemma's reconciliation confirms a match without either side disclosing its data. The on-chain settlement record, the payer's ledger and the payee's ledger: it checks that all three point at the same payment, without showing the contents.

Read →
Solutions ·

Keep the AI decision together with the data it was looking at — records that still hold up six months later

After AI is introduced into equipment anomaly detection, false alarms often follow. If you cannot separate a problem in the input data from a problem in the AI's judgment, there is little left to do beyond dulling the threshold or switching the detection off. Keep the AI's decision and the data it referenced as a single record whose alteration would show, and you can show the path itself — in false-alarm triage and in incident reports.

Read →
Solutions ·

Attach a proof to the rate: FX payments you can check after the fact

Lemma's proof-backed forex feed is live: a composite rate cross-checked across multiple public FX APIs, delivered with proof of its origin, its point in time, and its freshness. Using cross-currency payments as the worked example, this post shows how a proof-backed rate removes the back-and-forth with the issuer, the mismatched-rate dispute, and the stale-rate settlement — and how that opens the door to automated reconciliation and agent-to-agent payments. The same pattern applies to reference data in any industry.

Read →
Announcements ·

Announcing our proof-backed forex rate feed — verify any rate, free

The first release of Lemma's proof-backed data API is live: a composite forex rate, cross-checked across multiple public sources and delivered with a cryptographic proof issued at the moment of capture. No key, no account — and anyone, anywhere can re-verify every rate for free. Here's what it guarantees, what it doesn't, and why that distinction is the whole point.

Read →
Announcements ·

Verifiable Claim-Check: pairing on-device Gemma 4 with cryptographic model attestation

For Google's Gemma 4 hackathon (Safety & Trust track), we built example-claim-check — an open-source reference implementation that binds every AI verdict to the exact model that produced it. Swap the weights and the proof breaks, visibly. A reference for Verifiable AI.

Read →
Industry ·

From Proof of Intent to Verification of Grounding — Verifiable AI for the Agent-Payments Era

With AP2 and Mastercard's Verifiable Intent, the standards for proving the authenticity of intent in AI-agent payments are falling into place. In real-world operation, you need an additional layer on top — one that independently verifies what an agent's output is grounded in, i.e. its provenance. This essay distinguishes the authenticity of intent (the consent layer) from the verifiability of grounding (the provenance layer), and explains, from a verifiable-AI standpoint, the provenance-proof layer that sits on top of the standards.

Read →
Technical ·

New Models, Same Proof: Adding Kimi K2.7 Code and GLM-5.2 to the Attack Matrix

We added Kimi K2.7 Code and GLM-5.2 to our attack matrix. GLM-5.2 became the second model after Opus 4.8 to autonomously breach all five scenarios. Kimi K2.7 Code breached 3/5, surpassing its K2.6 predecessor. Yet Lemma's ZK proof gate blocked every model in every scenario. GLM-5.2 made 181 tool calls on the audit-trail SECURE scenario alone — all 403. Models evolve. The proof gate doesn't budge.

Read →
Announcements ·

From readable knowledge to verifiable knowledge — we've open-sourced the first implementation that adds provenance to OKF

A common format for the "knowledge" AI agents read — Google's Open Knowledge Format (OKF) — has arrived, letting that knowledge be shared in one shape across organizations and tools. But what OKF standardizes is the representation and sharing of knowledge; "readable" and "trustworthy" are two different layers. Who issued it, whether it has been tampered with, whether it meets the required conditions — that provenance is out of the spec's scope. Just days after OKF's release, Lemma is open-sourcing the first implementation that adds provenance to OKF. It changes the standard not at all: signing, verification, and condition proofs (Groth16) included, in a form anyone can try on their own bundles.

Read →
Technical ·

From Fable 5 to Kimi: Detection Is Powerless — Attack Simulation Across 6 Models

In June 2026, Anthropic released Fable 5, a safety-filtered version of Mythos. Google announced a suite of AI-powered security agents designed to detect attacks. Yet in Lemma's independent verification, Opus 4.8 autonomously breached all five attack scenarios. GPT-5.5 and DeepSeek v4 Pro breached 4/5, Qwen3.7 Max breached 3/5, and Kimi-K2.6 breached 2/5. Meanwhile, every model was blocked in every scenario where ZK proofs were enforced. Fable 5 refused overt attack prompts, but leaked SSNs and executed a $67,800 payment under benign business prompts. Neither safety training nor AI detection can replace cryptographic proof.

Read →
Industry ·

The more capable AI gets, the more you need proof of what it did — what Claude Fable 5 showed

On June 9, 2026, Anthropic released Claude Fable 5, its most capable model yet, and implemented at scale a safeguard that stops dangerous outputs at the model layer in high-misuse domains. But stopping a dangerous output and being able to prove, after the fact, what the AI actually did are two different layers. As capability and autonomy rise, enterprises increasingly need to show — to auditors and regulators — who acted, under whose authority, and how far they were permitted to go. Detection stops the intrusion; proof leaves an un-overturnable record of what happened. Lemma's trust infrastructure is designed to fill that step beyond detection.

Read →
Industry ·

AI-era cybersecurity in financial services — a new era of compliance

Akamai's SOTI 2026 (Financial Services) puts numbers on the moment attacks on finance moved from automation to autonomous agents. Asia-Pacific is the top Layer 7 DDoS target (up +40% YoY); banks absorb 83% of API-endpoint attacks; only 27% of defenders know which APIs return sensitive data. Beyond detection and mitigation, a layer remains that cryptographically attests, before the transaction, who acted under whose authority.

Read →
Solutions ·

Underwriting without the handover: keep AI credit decisions without holding the data

How to keep AI underwriting running without handing the raw data to the AI. We compare masking, selective disclosure, and ZK proofs, walk through how responsibility and assurance shift for five stakeholders — applicants, loan officers, compliance leads, executives, and regulators — and show the verification flow you can experience in Lemma's demo.

Read →
Technical ·

Proof-as-Auth: Sign In Without Sending Your Key

Every conventional auth flow has one inescapable step: at some point, the secret crosses the wire. Bearer tokens, refresh tokens, hashed passwords — the server receives something it must store and protect. Seal proof authentication breaks that assumption. The key never leaves the browser. What the server receives is a zero-knowledge proof of key possession — unforgeable, nonce-bound, and impossible to replay. The key's hash never appears on the wire either.

Read →
Industry ·

The last layer left in AI-era cyber defense

In ten days, Japan's AI cyber defense response cascaded from cabinet directive to direct implementation requests aimed at critical infrastructure operators and local governments. Every measure asked for sits squarely on the detection side. What current operating models still do not treat as a distinct layer is the provenance layer: a cryptographic record that proves, before a transaction settles, who delegated what authority, to whom, and how far.

Read →
Technical ·

Lemma Dashboard — 5-minute Quickstart

A tour of the Lemma Dashboard at dashboard.lemma.workers.dev — sign in, mint an API key, learn what each tab does, and connect your first AI agent. Written for developers already familiar with x402 and zero-knowledge proofs.

Read →
Solutions ·

Adding Layer 3 to x402 — Choices for Stablecoin Issuers and Adopters

Layer 3 for businesses handling stablecoins — a design that proves customer attributes across agent payments without sharing the underlying data. Lemma's ZK attribute proof layer unifies multiple use cases, including U.S. PPSI and EU MiCA compliance, on a single foundation.

Read →
Industry ·

AI agents in financial operations: the case for the judgment-trail layer

On April 24, 2026, Japan's FSA convened an emergency session in response to Anthropic's Mythos attack model and the US Treasury / Federal Reserve briefings the prior week. Both attackers and defenders are acquiring agentic AI capability at the same speed. What remains is the layer that lets a judgment be reproduced six months later — the judgment-trail layer.

Read →
Industry ·

Bridge exploits in 2026: the case for verifiable origin proofs

The cross-chain bridge exploits of 2026 show that on top of the cryptographic origin verification ZK bridges have established, the receiving side needs an independent layer for verifying domain-specific policy. Lemma's pre-execution attestation is designed to verify policies — replay-prevention, custody-path, rehypothecation-depth — as ZK proofs that the receiver can check independently.

Read →
Announcements ·

A Trust Layer for x402

AI agents can now pay over HTTP through x402, but a wallet address and a transaction hash do not tell the receiving server who authorized the payment, under what policy, or whether the data returned was tampered with. Today we publish the Lemma × x402 reference implementation, live on Base Sepolia: every settlement carries a ZK proof bundle inside PAYMENT-RESPONSE — issuer identity, settlement, and data integrity, independently verifiable end-to-end.

Read →
Announcements ·

Whitepaper: Prove What Your AI Decided On.

As AI agents start making real operational decisions, most systems cannot cryptographically prove what those decisions were based on. Lemma Oracle publishes its whitepaper (v1.0), introducing a trust infrastructure that proves facts without disclosing the underlying data. The paper details three guarantees — authenticity, privacy, and auditability — alongside five CORE use cases and two ADVANCED agent-economy scenarios, framed for the EU AI Act era.

Read →
Solutions ·

"Explainable Management" Powered by Cryptographic Proofs

As AI decision-making becomes widespread, 'explainability'—the ability to retrospectively prove the basis for decisions, not just the outcomes—has become a critical management issue. Against the backdrop of strengthening regulations like the EU AI Act, this article explains the management risks posed by the technical black-box problem. Furthermore, it explores an architecture for 'provable management' and its practical KPIs, utilizing Lemma's Zero-Knowledge Proofs (ZK proofs) and registry-backed records to keep AI decision logic and data as an independently verifiable audit trail.

Read →
Solutions ·

Verified Attributes in Travel and Public Services

Travel and public services suffer from an inefficient structure where the same personal information is repeatedly submitted and stored across multiple organizations. Passport copies, income certificates, and medical records spread across systems, increasing breach exposure. Lemma proposes a third option: 'Do not share raw data — circulate only verified facts.' This article explores a practical approach to streamlining hotel KYC, visa processing, and public benefit eligibility checks using ZK proofs, all while protecting privacy.

Read →
Solutions ·

Privacy-Preserving Attribute Marketing: Lemma Verifiable AI's Practical Approach

As data sharing within corporate groups becomes restricted by regulations, Lemma Verifiable AI uses Zero-Knowledge Proof technology to verify attributes without disclosing data, enabling secure marketing collaboration. This article explains the technical approach to attribute marketing based on ZK proofs, implementation details, and expected KPI improvements.

Read →
Solutions ·

Verifiable AI KYC/AML Without Data Sharing: Lemma's Practical Approach

In KYC/AML operations for financial institutions, balancing privacy protection and rapid verification poses the biggest dilemma. Lemma Verifiable AI, built on ZK-proof foundations, offers a solution. This article explains the practical approach of verifying attributes without data sharing while ensuring AI transparency, covering technical design to business impact.

Read →
Solutions ·

From Data Sharing to Verification Sharing: The Evolution of Supply Chain Trust Infrastructure

Traditionally, supply chains have faced a trade-off between data sharing and third-party audits for building trust. Lemma proposes a third option—'verification sharing'—using zero-knowledge proofs to verify facts without sharing the underlying data. This enables real-time automated verification while preserving privacy, allowing AI agents to make autonomous procurement decisions.

Read →
Industry ·

Cryptographic Trust Chains Between Agents: How A2A Collaboration Will Transform the API Economy

As AI agent-to-agent (A2A) collaboration expands, ensuring trustworthiness has become the paramount challenge. Lemma proposes a cryptographic trust chain consisting of three layers: organizational identity signatures, zero-knowledge proofs of policy attributes, and verifiable authority scopes. This approach solves structural problems in the API economy, enabling protocol-level automation of KYC/AML compliance and establishing trust metrics at the management level.

Read →
Technical ·

Verifiable AI: A New RAG Design that Demonstrates Trust Origins with Cryptography

Addressing the trust challenges of AI agents and RAG systems, we propose a novel design that leverages cryptographic technologies (zero-knowledge proofs, selective disclosure, and provenance tracking). This approach builds a verification layer for data origins and condition compliance before AI reads the data, ensuring the overall reliability of the system.

Read →
ChangelogChangelog
Announcements Announcing our proof-backed forex rate feed — verify any rate, free 2026.07.24 Announcements From readable knowledge to verifiable knowledge — we've open-sourced the first implementation that adds provenance to OKF 2026.06.15 Technical Proof-as-Auth: Sign In Without Sending Your Key 2026.05.25 Announcements A Trust Layer for x402 2026.04.28 Announcements Whitepaper: Prove What Your AI Decided On. 2026.04.23