PSM · Form RR-1
Readiness Receipt Generator
Select your impact level, intended use cases, and asserted controls. Aiudit will compute a Readiness Index and produce a signed one-page PDF receipt suitable for sharing with authorizing officials and assessors.
Authorized Use Cases
Asserted Controls
Readiness Receipt · FAQ
Frequently asked questions
What is a Readiness Receipt?
A signed, one-page attestation summarizing your organization's AI governance posture — impact level, in-scope use cases, and implemented controls — mapped to NIST AI RMF, ISO/IEC 42001, and the EU AI Act. It is intended for auditors, underwriters, and procurement teams as a fast pre-assessment artifact.
How is a Readiness Receipt signed and verified?
Each PDF embeds a SHA-384 payload hash and Ed25519 signature from Aiudit's issuer key. Verifiers compare the printed hash against the anchored value at /verify or via the ledger export; the corresponding public key is published in JWKS at /.well-known/aegis-jwks.json.
Is a Readiness Receipt an Authorization to Operate (ATO)?
No. It is a self-asserted readiness snapshot. Issuance of an ATO requires an independent 3PAO or agency Authorizing Official review. The receipt is designed to accelerate that review, not replace it.
How long is a Readiness Receipt valid?
Receipts are timestamped at issue and treated as point-in-time evidence. We recommend re-issuing on any material change to scope, controls, or impact level, and at minimum every 90 days for continuous-ATO programs.
Which impact levels are supported?
DoD Cloud SRG Impact Levels IL2, IL4, IL5, and IL6, plus civilian FedRAMP Moderate/High and StateRAMP Moderate/High equivalents. The receipt inherits the residency and cryptographic profile associated with the selected level.
Does generating a receipt store or transmit our data?
No. The receipt is generated client-side in the browser from your selections. No form data leaves the browser unless you separately request a demo or file an assessment through the authenticated workspace.