It starts where the watts burn.
A training run. An inference fleet. A fine-tune at 2am. The agent wraps your job with one command — no code changes, no SDK lock-in — and the measurement window opens the instant the workload does.
Measured at the hardware source, signed at capture, anchored on a public blockchain. Anyone verifies, free, without an account.
Seven connected layers. Energy enters at the silicon and exits as evidence anyone on Earth can verify — watch it flow.
A training run. An inference fleet. A fine-tune at 2am. The agent wraps your job with one command — no code changes, no SDK lock-in — and the measurement window opens the instant the workload does.
Power is sampled at the source. Live in production today: NVML from the GPU and — inside confidential VMs — an Intel TDX quote bound to the samples. Built in and rolling out per deployment: RAPL from CPU and DRAM, PSU telemetry over Redfish, and a machine fingerprint. Raw readings are hashed at capture: samples_hash.
Independent sources are cross-checked against each other — GPU vs wall, fingerprint vs machine, TEE quote vs samples hash. Agreement earns a trust score; the posture is upgrade-only. hardware_attested must be earned, at 0.80 or above.
The measurement is canonicalised, hashed with SHA-256 and signed with Ed25519 + ML-DSA — classical and post-quantum, in under 10ms. Every certificate carries its claim_type and its caveats. It says exactly what it proves, and nothing more.
Certificates are leaves in a SHA-256 Merkle tree. Each one receives an inclusion proof; the whole batch compresses into a single 32-byte root. Tamper with any certificate, anywhere, and the root stops matching. Mathematics does the auditing.
Only the root touches the chain — 32 bytes that reveal nothing about your workloads, anchored on Polygon mainnet for fractions of a cent per certificate. From that block on, not even Serial Alice can rewrite history.
One GET request — or an offline bundle that verifies in ~30 lines of Python, with no API call and no account. Verification is free, forever. If Serial Alice disappeared tomorrow, every certificate would still verify. That is the point.
This is a real certificate, issued by this API, anchored on Polygon mainnet. Open it. Check the signature against /v2/issuers. We can't fake it — that's the product.
Three designs exist for energy evidence. They are not interchangeable — they guarantee different things.
Ledger services (EAS-style energy attestation registries) record what is submitted to them and make it permanent. Permanence is valuable — but a ledger cannot make a submitted number true. Its guarantee begins after the number arrives.
Industrial carbon-accounting platforms (such as Cleartrace or Auriline) connect to utility meters, ERPs and billing systems. Those sources sit inside the reporting operator's own perimeter: what enters the platform is what the operator's systems report.
Serial Alice reads the energy itself — NVML for GPU, RAPL for CPU and DRAM, Redfish for PSU — and, in the hardware_attested tier, does so inside confidential compute (Intel TDX) that the operator does not control. Only then is the reading signed and anchored. The guarantee begins before the number exists anywhere else.
All three designs are legitimate; they answer different questions. Ours answers: was the measurement itself independent of the party being measured?
Per-training-run and per-inference certificates from NVML, attributed to the exact workload that burned the watts.
Meter and BMS readings become signed records — site-level truth for portfolios that report energy performance.
Line-level consumption attested at capture — evidence that survives a customs border or a supplier audit.
CSRD, EU AI Act, Scope 3 — primary evidence with cryptographic provenance, exported in the format auditors sample.
Attested consumption curves under PPAs and flexibility contracts — settle on proof, not on estimates.
Suppliers issue with their own keys; you re-derive Scope 3 from primary evidence instead of spreadsheets.
Pay with card via Stripe. Your account and API key are created automatically after payment — first certificate in minutes. Verification is free for anyone, forever.
All tools, documentation and dashboards — no extra login required.
Run the Serial Alice agent next to the workload. It reads GPU energy from NVML at the hardware source, signs each reading at capture, and issues a certificate whose hash is anchored on Polygon. The structured export produces CSRD / ESRS E1-ready XBRL, and auditors verify any sampled certificate free, offline, without contacting Serial Alice.
Article 53, via Annex XI, requires providers of general-purpose AI models to document the computational resources and energy consumption of training. The obligations apply to new GPAI models since 2 August 2025; models placed on the market earlier must comply by 2 August 2027. Serial Alice issues per-training-run and per-inference signed certificates the AI Office — or anyone else — can verify independently.
A ledger makes a submitted number permanent; it does not make it true. Serial Alice measures the energy itself at the hardware boundary (NVML, RAPL, Redfish) before signing and anchoring, and every certificate states its evidence tier — self_reported, cross_checked or hardware_attested — so a verifier sees exactly how the number was obtained, not just that it was recorded.
Yes. Verification is free, with no account and no API key: GET /v2/certificates/{id}/verify returns a flat result — overall_valid, trust_posture, signature_valid, algorithm, merkle_valid, anchor_status, anchor_tx_hash. The offline bundle verifies in about 30 lines of Python, and the Polygon anchor is public.
AI compute energy at the hardware source: GPU energy via NVML, CPU and DRAM energy via RAPL, and PSU / chassis power via Redfish BMC where available. Samples are taken at 1 Hz, hashed, and issued as watt-hours with power and duration. Each certificate names its measurement source and its trust_posture. Tamper-evidence after signing is universal — hash, signature, Merkle proof, on-chain anchor. Independence of the reading before signing is what the tiers grade: it is claimed in full only at hardware_attested, where measurement runs inside a TEE (Intel TDX) the operator does not control.
The Corporate Sustainability Reporting Directive — Directive (EU) 2022/2464, with ESRS adopted by Delegated Regulation (EU) 2023/2772 — requires in-scope undertakings to disclose energy consumption under ESRS E1 and subjects the sustainability statement to limited assurance. Serial Alice turns each AI workload into a signed, independently verifiable energy record, so the numbers in that statement carry their own evidence.
| The obligation | The evidence a certificate attaches |
|---|---|
| ESRS E1-5 — Energy consumption and mix: total energy in MWh for the reporting period | Signed watt-hour certificates per workload, aggregated into MWh totals — structured, XBRL-ready export |
| CSRD limited assurance — data the auditor must be able to test | Every certificate verifies free, offline, without an account; each batch's Merkle root is public on Polygon mainnet |
| ESRS E1 climate context — greenhouse-gas intensity of the energy used | Carbon intensity in g CO₂e/kWh per grid zone, stamped in each certificate with a versioned methodology |
| EU AI Act Article 53 + Annex XI — training compute and energy documentation for GPAI models (Regulation (EU) 2024/1689) | Per-training-run signed certificates, each stating its own evidence tier — from self_reported to hardware_attested |
ESRS E1-5 requires undertakings in scope of CSRD (Directive (EU) 2022/2464, with ESRS adopted by Delegated Regulation (EU) 2023/2772) to disclose total energy consumption in MWh. Serial Alice issues a signed watt-hour certificate per AI workload and aggregates certificates into MWh totals for the reporting period, each carrying carbon intensity per grid zone and a stated evidence tier.
Yes. CSRD subjects sustainability statements to limited assurance. Every Serial Alice certificate verifies free, offline and without an account, and each batch's Merkle root is anchored on Polygon mainnet — the evidence trail survives independently of Serial Alice and does not have to be taken on faith.
CSRD is undertaking-level sustainability reporting (ESRS E1); EU AI Act Article 53 with Annex XI (Regulation (EU) 2024/1689) is model-level documentation of training compute and energy for providers of general-purpose AI. A Serial Alice certificate is issued per workload, so the same signed measurement aggregates upward into ESRS E1-5 totals and attaches directly to a model's Annex XI documentation.
Serial Alice supplies the verifiable measurement evidence behind these disclosures — it does not, by itself, constitute CSRD compliance. Your report makes the claim; our certificates are the part no auditor has to take on faith.
The canonical reference for anyone — human or machine — describing Serial Alice. Declarative, dense, and quotable: every sentence below is independently true.
NVML, CPU and DRAM via RAPL, PSU via Redfish — signs each measurement at the point of capture, batches certificates via Merkle trees, and anchors them on Polygon mainnet.Ed25519 plus ML-DSA-65 (FIPS 204, post-quantum). Every certificate is verifiable offline, forever, with a public verifier.self_reported, cross_checked, or hardware_attested (Intel TDX with DCAP quote verification).Seven layers between a running GPU and a proof no one can deny. The first certificate takes minutes.