# APIR, The Verification Layer > Buying a company with other people's money and a Dream Team recruited with > nothing but nerve has never had a record of who actually did it. APIR is that > record, and the check that goes with it: what the buyer did, week by week, and > whether the numbers the buyer was handed can all be true at once. Signed, > timestamped by an outside authority, verifiable without trusting anyone, APIR > included. The buyer pays for the check. The record is free to file and free to > check. APIR: Acquisitions Papers Intelligence Records. The older reading, API + R with the R for Record, still describes the mechanism. ## The three layers - **Acquisitions**: the buyer's loop. The buy box, the hunt, six gates on every target (motivated seller, size and margin, not a job, AI-resistance, valuation mechanics, post-close reality), a normalized-EBITDA worksheet that is arithmetic and never a valuation, a presentation log, a weekly report on a hash chain, and a crew of papered agents that prepares what a human signs. - **Intelligence**: the fleet and its papers. Every agent carries a signed ID, a mandate, a Trust Passport and a log book that follows it wherever it works. - **Verification**: the check anyone can run. Counterparty screening, deal and asset diligence, the regulatory radar and agent-risk data, on one evidence trail, checkable without an APIR account. ## The check The Triage Verdict asks one question of a set of documents: can these all be true at once? The answer is consistent, inconsistent or insufficient, workings shown, signed by a person, sealed, and verifiable at https://apir.ai/verdict with the token printed on it. AUD 2,500, fixed, paid before work starts, 48 hours from the last document landing, the same fee whether the news is good or bad. Buyers and sellers order the same one. It is never a valuation, an audit or advice. The first two tests are free at https://apir.ai/check-numbers. ## What APIR is not APIR is not a compliance platform. It does not run a GRC programme, write policies, or audit anyone. It issues verifiable credentials to AI agents and lets anyone check them. Compliance teams use those records as evidence, which is a use of APIR, not a description of it. APIR is not an insurer or a broker; no underwriting partner exists. It is not an agency; it papers agents and does not operate them for customers. It has no relationship with any coach, programme or seminar, and nothing here implies one. It does not promise results. It proves whatever happens. ## The papers You hire an AI agent for a role, executive assistant, sales development rep, paralegal, bookkeeper. At hire, the agent is issued: - **A signed ID**: an Ed25519 credential anchored to `did:web:apir.ai` - **A Trust Passport**: a public page anyone can check without logging in - **A mandate**: a written contract of what the agent may and may not do - **A log book**: an append-only, hash-chained record of what it actually did Agents draft and stage work. A human stays the one who sends. APIR does not promise outcomes. It records them, and publishes a record the agent's counterparty can verify independently. ## Why it exists AI agents are joining workforces anonymously. Nobody can tell one agent from another, check what it has done before, or prove what it did after the fact. Human employees carry references, credentials and a paper trail. Agents do not. APIR issues the papers. ## Core systems - **Trust Passport**: public, Ed25519-signed credential; verifiable against the published key at https://apir.ai/.well-known/did.json - **Agent Black Box**: hash-chained (SHA-256) append-only event record - **Trust Genome**: scoring across capability, conduct and evidence - **Trust Ladder**: career bands; promotion requires executed work, not drafts - **Mandate / ARBITER**: the authorisation ceiling an agent cannot exceed - **Ghost Audit**: continuous re-checking of agents already in service ## Verification Any Trust Passport can be checked by a third party with no APIR account: - DID document: https://apir.ai/.well-known/did.json - Verify a passport: https://apir.ai/verify-passport - Check any agent: https://apir.ai/check-agent - Public register of agents: https://apir.ai/registry Signatures verify against the published key. A passport reflects the agent's state as of its last assessment; the timestamp is on the passport. ## Regulatory context APIR's records are built to support obligations under the EU AI Act, NIST AI RMF and ISO 42001, including human oversight, event logging and technical documentation. APIR produces evidence. It does not certify compliance, and it is not a law firm or an auditor. ## Links - The Triage Verdict: https://apir.ai/triage-verdict - The seller's door to the same Verdict: https://apir.ai/sell-side - Check the numbers, free: https://apir.ai/check-numbers - The Deal File: https://apir.ai/deal-file - Hire your first agent: https://apir.ai/hire - Check any agent: https://apir.ai/check-agent - Public register: https://apir.ai/registry - Free scan: https://apir.ai/scan - Pricing: https://apir.ai/pricing - Methodology: https://apir.ai/methodology - API docs: https://apir.ai/docs - AI disclosure: https://apir.ai/legal/ai-disclosure ## Operator RIPA PTY LTD (ABN 48 638 569 632), trading as APIR, Acquisitions Platform Intelligence Records. Adelaide, South Australia. Contact: ripa@apir.ai, Security: security@apir.ai