Proof Economy Standards Alliance — Founded 2026

The Proof Economy

A Declaration of Independence for Proof and Attestation in any Economy beginning with Cybersecurity.

The Proof Economy is a category coined by Craig Ellrod, 30-year offensive security industry veteran and founder of HACKERverse®, in May 2025. It names the shift from self-declared attestation to cryptographically-earned, independently verifiable proof. PESA is the vendor-neutral governance body that ensures the standards defining this category are written by practitioners and buyers, not the vendors selling into it.

Category Coined
May 2025
by HACKERverse®
Proof Protocol
v1.1
CC BY-ND 4.0
Certified Run #001
PR-2026-12672
Pipelock v3.0.0
Governance
Practitioner-Led
No vendor control

Article I — The Problem with Attestation
A Declaration of Independence for Proof and Attestation in any Economy beginning with Cybersecurity.

The security industry has built its trust architecture on a flawed foundation: self-attestation. Vendors define what counts as valid proof. Vendors run their own tests. Vendors report their own results. The buyer has no independent verification path, and the regulator has no tamper-evident record. When the threat is a sophisticated adversary and the system being evaluated is autonomous, this is not a trust model. It is theater.

The Proof Economy is the correction. It is the transition from claimed performance to earned proof - from marketing-derived detection rates to adversarially-earned, NIST Beacon-anchored, on-chain records that exist independently of the vendor who issued them. A proof run is not a report. It is a cryptographic artifact bound to a pre-committed randomness value, signed by a custodian, and anchored on a public ledger where no single party controls the truth.

PESA exists to govern the standards that define what proof requires. Not because any single organization should own that definition, but because without an independent, vendor-neutral body administering that question, the answer will always be written by whoever benefits most from a lower bar. We are that body. Practitioners and buyers set the bar. Vendors pass it or they do not.


Seven principles that cannot be negotiated.

Principle 01

Vendor Independence

No organization with a commercial stake in conformance outcomes may hold a seat with agenda-setting or voting authority over conformance requirements. Vendors are welcome as contributors and observers. They do not set the bar they must clear.

Principle 02

Open Specification

Core protocol specifications are published under open licenses. No single organization may hold the specification in a manner that prevents independent implementation, independent testing, or independent verification.

Principle 03

Cryptographic Provenance

Valid proof carries tamper-evident cryptographic provenance. Claims without NIST Randomness Beacon pre-commitment, custodian binding, and on-chain anchoring are attestations, not proof. The distinction is non-negotiable.

Principle 04

Independent Verifiability

A proof record must be verifiable without the cooperation or presence of the issuing party. The prover is removed from the trust chain at the moment of issuance. Post-issuance, the record stands or falls on its own.

Principle 05

Separation of Specification and Certification

The body that writes the specification does not issue certifications. The body that issues certifications does not write the specification. Conflicts of interest between these functions are structural, not incidental.

Principle 06

Prior Art Recognition

Standards bodies must honor the public record of who defined what, and when. Attribution is not optional. Retroactive redefinition of category terms to erase prior inventors is a governance failure, not a naming convention. And quite frankly, it's fraudulent.

Principle 07

Public Governance by Default

Governance proceedings, working group outputs, and policy decisions are published publicly by default. Closed deliberations require explicit justification and sunset provisions. Opacity in standards governance is a conflict of interest in waiting.


Four bodies. Clear separation. No vendor capture.

Governance Bodies

Founding Council

Sets strategic direction and approves founding principles. Reserved for independent practitioners and buyers. Any council member who joins a vendor in a governed category must recuse from relevant votes or vacate within 90 days.

Technical Steering Committee

Oversees specification development across all working groups. Composed of practitioners with demonstrated technical expertise. Vendor participation is as contributor only, no voting authority.

Working Groups

WG-1: Atomic Execution Unit definition. WG-2: Valid Proof Event and Proof Stream. WG-3: Proof Verifier conformance requirements. WG-4: Interoperability and cross-chain anchoring. Open membership, public output.

Observer Participation

Vendors, researchers, and regulatory observers may participate as observers. No voting rights. No agenda-setting authority. Full access to proceedings and working group outputs.

Founding Council

CE
Craig Ellrod
Founder, HACKERverse® / Nebulonium, Inc.
Inventor, Proof Economy category (May 2025)
Founding Seat
JW
Josh Waldrep
Independent Security Practitioner
luckyPipewrench / Pipelock - AARM Working Group
Founding Seat
--
Seat 3 - Open
CISO / Practitioner
Independent. Must be practitioner or buyer. No vendor affiliation in governed categories.
Accepting Nominations
--
Seat 4 - Open
Practitioner / Researcher
Independent. Must be practitioner or buyer. No vendor affiliation in governed categories.
Accepting Nominations
--
Seat 5 - Open
Policy / Regulatory
Independent. Must be practitioner or buyer. No vendor affiliation in governed categories.
Accepting Nominations

What PESA will never permit.

These prohibitions are not aspirational. They are structural. Governance that permits the following is governance that has already been captured.

×

Self-Attestation as Conformance

No conformance level may be satisfied by a vendor's own declaration, internal report, or unverified questionnaire. Every conformance claim requires independently verifiable evidence. Self-attestation is not proof. It is a claim.

×

Vendor-Written Conformance Requirements

No organization with a commercial stake in conformance outcomes may draft, vote on, or hold veto authority over conformance requirements in any category where they participate as a vendor. The AARM working group composition, as currently constituted, violates this principle.

×

Badge Issuance Without Benchmark Execution

No certification mark governed by PESA may be issued on the basis of documentation review, vendor presentation, or compliance questionnaire alone. A badge must be earned by passing a live, independently-run benchmark. The ProofStamp mark is the model: no badge without a real benchmark first.

×

Closed Deliberations Without Justification

Working group proceedings, draft specifications, and governance votes are public by default. Closed sessions require explicit written justification, a defined scope, and automatic publication within 90 days. Indefinite closure is not permitted.

×

Retroactive Redefinition of Category Terms

PESA recognizes prior art in category terminology and specification. No working group may redefine established terms in a manner that erases prior inventors or misattributes category origin. The public record is the record.


Proof Protocol is the proof layer PESA governs.

The Defensible Knowledge Proof (DKP) is the basis for the Proof Protocol. The Proof Protocol defines the open standard for proof of control and proof of efficacy in adversarial environments. Invented by HACKERverse®. Published under CC BY-ND 4.0. Governed by PESA. V1.2 and beyond are protected under CC BY-ND 4.0 to prevent forks claiming compatibility.

ProofStamp is the certification mark for implementations that pass a live, independently-run Proof Protocol benchmark. The first certified implementer is Pipelock v3.0.0. Certified Run #001 is on-chain at ProofRegister: PR-2026-12672.

PR-2026-12672
CERTIFIED RUN #001
Protocol
PP-1.1
Custodian
HACKERverse®
Subject
Pipelock v3.0.0
Proof of Control
VERIFIED
Proof of Efficacy
VERIFIED
Threat
AKIRA RANSOMWARE
Containment
71.1%
Detection
100%
Evidence
100%
False Positive
4.5%
Exfil Bytes
0
Encrypt Events
0
NIST Beacon
Pre-committed
Chain Anchor
Bitcoin OP_RETURN
ProofStamp
CERTIFIED

The category was coined. The record is public.

The Proof Economy is not a term that emerged from a standards committee. It was coined by Craig Ellrod, a 30-year offensive security industry veteran, and placed into the public record starting May 2025 - predating all competing frameworks by a minimum of nine months.

May 2025

"Proof Economy" and "Continuous Adversarial Evaluation (CAE)" coined

HACKERverse® publishes the Proof Economy and CAE category definitions publicly. LinkedIn posts tagged #RSAC2025 place the terminology in the public record.

LinkedIn / HACKERverse®
Sep 25, 2025

"The Proof Economy: Proof is the New Currency" - blog.hackerverse.ai

Full category definition post archived by Internet Archive on October 6, 2025. Timestamp-verified prior art, 9+ months before any competing framework.

blog.hackerverse.ai / archive.org
2026

Gartner names "AEV" (Adversarial Exposure Validation)

Gartner's March 2026 naming of the AEV category arrives approximately 10 months after HACKERverse® coinages. The public record predates it. Attribution is available on request.

Gartner / March 2026

Practitioners and buyers set the bar. Join us.

Council seats 3-5 are open to independent practitioners, CISOs, and policy professionals with no vendor affiliation in governed categories. Working group participation is open to all. If you are building on Proof Protocol or seeking ProofStamp certification, contact HACKERverse® directly.