The world's first cryptographic audit standard for AI-driven trading
formally submitted to global regulators.
VeritasChain Standards Organization (VSO) is an independent standards organization
dedicated to making transparency in algorithmic and AI-driven trading cryptographically verifiable.
For the mission, scope, and neutrality of VeritasChain Standards Organization (VSO), see About VSO →
Designed to support MiFID II, EU AI Act, GDPR, and emerging international regulations.
"Encoding Trust in the Algorithmic Age"
See our global regulatory submissions
For an explanation of VSO's role, scope, and organizational structure, see the Overview: What is VSO and VeritasChain Protocol.
VCP v1.0 has been formally submitted to regulatory authorities across 50 jurisdictions
Continuously expanding — additional jurisdictions in progress
Submission does not imply endorsement or approval.


















































An audit protocol formally submitted to regulators worldwide
Spanning Americas, Europe, Asia-Pacific, Middle East, and Africa
A reference implementation demonstrating how AI-driven trading systems can produce cryptographically verifiable audit trails
"Verify, Don't Trust."
Any modification to logged events is cryptographically detectable by third parties
Third parties can detect omission of events after anchoring, at batch granularity
Auditors can verify independently without trusting the operator
Documents decision factors and model outputs for explainability
Reference implementation • VCP v1.1 Silver Tier • CC BY 4.0 License
A local-only, audit-safe reference implementation
for running the AI Decision Auditability Benchmark
and exporting an Audit Evidence Pack.
VAP Scorecard Explorer is a reference implementation of the AI Decision Auditability Benchmark (10 criteria / 20 points).
It allows audit and assurance teams to:
All processing runs locally.
No network communication. No external APIs. No analytics.
Benchmark specification and scoring criteria are published openly as the canonical reference.
A demonstration dashboard, running on simulated sample data, that shows how independent, cryptographic verification of VCP records works.
No live trading system is connected, and the Explorer API is not yet deployed (Planned — no date set).
One-click verification of any trade lifecycle
Merkle proofs, hash-chain validation, and timestamp verification are performed entirely client-side — no server trust required.
Essential technical documentation and standards for developers, regulators, and integrators
RESTful API documentation for VCP event queries and verification
View API DocsComplete protocol specification with data models and integrity layers
Read SpecificationTechnical conformance certification scheme for VCP implementations, assessed by accredited Conformity Assessment Bodies
Learn About CertificationOpen-source repositories including specifications, the SDK specification and reference implementations
Explore RepositoriesStart building with VCP — Explore the API documentation, the SDK specification, and reference implementations
VeritasChain Protocol (VCP) is an open standard specification for recording the "decision-making" and "execution results" of algorithmic and AI-driven trading — including AI model versions, decision factors, time-synchronized event lifecycles, and cryptographically hashed audit trails — in a tamper-evident, append-only and verifiable format. VCP provides a cryptographically secured chain of evidence, designed to support compliance efforts with international regulations including MiFID II, EU AI Act, and CAT (Consolidated Audit Trail), making it a valuable tool for RegTech, Audit, and Compliance. VCP verifies the integrity and attribution of recorded events — it does not certify the correctness or safety of the underlying AI or trading decisions.
In addition to the order and execution data that FIX messages carry, VCP defines records for:
FIX standardises the messages exchanged between counterparties; it does not define a record of a system's internal decision factors or risk state.
This makes VCP relevant to evidence requirements under MiFID II RTS 25, EU AI Act Article 12, and next-generation RegTech.
VSO's position is that oversight of algorithmic and AI-driven trading should rest on records that can be verified independently. The rules below require record-keeping, event logging or clock synchronisation; none of them mandates cryptographic audit trails or refers to VCP.
Requires business clocks traceable to UTC, with specified accuracy, for trading venues and their members and participants in the EU (Delegated Regulation (EU) 2025/1155, Arts. 11–16; replaced RTS 25 on 2 March 2026)
Requires automatic event logging (Art. 12) and human oversight (Art. 14) for high-risk AI systems; Annex III obligations apply from 2 December 2027
U.S. SEC's Consolidated Audit Trail requires granular trade lifecycle tracking
VCP provides a single open standard that produces evidence relevant to all these requirements, reducing fragmentation across jurisdictions — by design.
Tamper-evident audit trails using Merkle trees (RFC 6962 domain-separated hashing) and external anchoring; hash chains are optional
Ed25519 by default, upgradeable to post-quantum algorithms including ML-DSA (FIPS 204)
Each signature carries its algorithm identifier, so algorithms can be changed. Post-quantum signatures are EXPERIMENTAL in v1.2 RC1 and are not a certification requirement.
Designed to produce evidence relevant to MiFID II RTS 25, EU AI Act, GDPR, CAT Rule 613, and international reporting
Compliance tiers for HFT (Platinum), Institutional (Gold), and Retail (Silver).
Note: Silver Tier relies on system time (Best-effort) and delegated signatures. It provides transparency, not regulatory-grade evidence.
Side-car integration with existing FIX engines — no change to trading gateways required
Fully open specification with public reference implementations. Designed for long-term interoperability across brokers, exchanges, and regulators.
Split-View Attack and Omission Attack resistance (v1.1). Designed so that removing events from an anchored batch, or showing different records to different parties, is detectable.
Records algorithm identity and version, a model hash, decision factors and approval records (VCP-GOV). Where a system is classified as high-risk under the EU AI Act, such records are evidence relevant to Article 12 record-keeping; algorithmic trading is not listed in Annex III.
Audit-trail verification, algorithmic decision reconstruction, and cross-border regulatory coordination
Best-execution evidence, trade lifecycle verification, and verifiable records as input to regulatory reporting
Transparent order matching, CEX audit trails, and cross-venue surveillance
Tamper-evident audit trails for high-frequency and algorithmic trading systems
Verifiable trading records for payout and performance disputes
Merkle root anchoring to public blockchains
Integrate VCP into your trading infrastructure using the open specification, the SDK specification and the reference implementations
View Specification (Available Now) →Deploy VCP as a sidecar to existing FIX engines to support regulatory compliance efforts
Contact Us →Industry-specific profiles for cryptographically verifiable AI audit evidence
VAP (Verifiable AI Provenance Framework) — which VSO describes as "the flight recorder for AI" — is the cross-domain upper-level metaframework (current: v1.2.0 Draft 3) that defines the structural requirements for cryptographically verifiable AI decision provenance. Its scope is deliberately strict: domains where system failure could cause serious, irreversible harm to human life, societal infrastructure, or democratic institutions. Finance, healthcare, transportation, energy, and public policy are VAP's mandatory application domains; content/creative AI and capture provenance are served by released profiles. VAP itself is not an implementation — domain profiles apply its requirements to a sector. Status in the VAP registry (§4.5.2): CAP v1.0 Released; MAP Working Draft; PAP Partial Draft; IAP Announced; DVP and EIP Planned (no specification document exists for IAP, DVP or EIP). Read the VAP Framework overview →
VeritasChain Co., Ltd. is a technology company developing open cryptographic audit and provenance standards for algorithmic and AI-driven trading, enabling regulators, institutions, and markets to verify—not merely trust—system behavior.
For media inquiries, partnership opportunities, technical collaboration, or standardization initiative participation, please contact us:
VSO does not provide financial services or regulatory approvals.