# Rootz for Data Centers — Measured AI™ (AI-readable edition)

> Speak AI rendering of the Rootz **Data Centers** vertical (datacenters.rootz.global). Same page,
> expanded and structured for an agent. One source, two audiences. Everything here is verifiable at the
> live surfaces under "Proof, live today."

## One line
Rootz adds a **quality program to the data center**: the facility's own controls, signed and
**bound to the AI output**, verifiable in public. Provable AI hosting, priced at a premium. This is the
data-center vertical of **Measured AI** — proof, ownership, and portability for everything an AI reads,
decides on, and remembers.

## The problem (data-center framing)
A tenant runs an AI workload in a facility. The operator cannot prove — to the tenant, an auditor, or a
regulator — which hardware ran it, that the environment wasn't changed mid-job, or that the output is the
real one. Three gaps:
- **No record of the plant** — a data center can be re-pointed/reconfigured overnight and no one would know;
  planned changes look like unplanned ones.
- **Not bound to the output** — classic provenance stops at the rack; nothing ties the controls to the AI
  result the customer receives.
- **Trust me, not verify** — compliance is a PDF from last year, not proof of this job.

## What Rootz adds (sits on top of existing infrastructure — does not replace racks/power/security)
- **Good records, a bright light** — who touched what and when; planned vs. random changes, signed and auditable.
- **Bound to the output** — the facility's internal controls are cryptographically tied to the AI job that ran.
- **HSM-rooted, verifiable in public** — a hardware-anchored identity mints each record; anyone verifies it
  against blockchain/public sources without trusting Rootz or the operator.
- **Publish evidence, relying party decides** — part of the manifest public, rest private; no central
  chokepoint, so it is not a foundation for a denial-of-service attack.
- **Measured compute, not trusted computing** — even a spoofable measurement raises the cost of lying and
  creates a record; honest depth stated per claim (L1–L4); weak-but-real beats strong-but-asserted.

## How it works — the Binder
A local server inside the facility:
1. **Aggregate** — collects the facility's attestations: who/what/when, environment, hardware identity
   (e.g. OCI instance-principal cert + AMD SEV-SNP report).
2. **Measure & sign** — mints a signed manifest of what actually ran, rooted in an operator-controlled HSM.
3. **Bind to output** — cryptographically ties the record to the AI output the workload produced.
4. **Verify in public** — the tenant, an auditor, or the tenant's AI checks the proof against public
   sources; the operator chooses what is public.
Analogy: a broker checking a carrier's safety status before dispatch — a quick hash + a verification link,
backed by public records. Zero-trust architecture applied to the data center itself.

## The stack (turn on in layers)
1. **Signed MCP** *(live)* — sign every agent call/response in and out of the facility (PQ-hybrid). Cheapest start.
2. **Proof of Origin** *(live L1 → pilot L2/L3)* — a receipt per AI job: prompt → model → hardware → output.
3. **Measured Data Center — the Binder** *(pilot, THIS vertical)* — the whole facility made provable and
   bound to output; the revenue premium; "Zero Trust, finished."
4. **Government-grade identity** *(pilot, adjacent vertical)* — self-created, registered identity for
   sovereign/government data-center operators and tenants; every act signed and citizen-verifiable.

## Assurance depth
L0 nothing signed · **L1 attested transport — LIVE** · L2 GPU/TEE attests loaded weights (pilot) ·
L3 measured weights bound to declared identity, anchored on-chain (pilot) · L4 fleet of signed receipts,
traceability + recall + SPC (roadmap). Depth is a level, never a boolean.

## The business case
- **~10–15% revenue-per-kW premium** for provable / measured hosting.
- **Zero Trust finished** — up to the AI output, not stopping at the rack.
- **Differentiation** — a defensible answer to "prove what ran" vs. commodity capacity.
- **Rides the existing stack** — a software layer on the racks, power, and security already deployed.

## Proof, live today (open and verify)
- https://proof.rootz.global/origin — Proof of Origin — L1 live
- https://proof.rootz.global/signed-mcp — Signed MCP (PQ-hybrid) — live
- https://proof.rootz.global/manifest — Signed Manifest / evidence atom — live
- https://discover.rootz.global — Speak AI / AI-visibility — live
- https://freight.rootz.global — same engine, freight vertical (eBOL proof) — live
- https://politics.rootz.global — origin-proofed public data — live
- https://title.rootz.global — chain-of-title — live
- https://vsp.rootz.global — proof of a measured capture — live
- https://food.rootz.global — Speak AI in the wild — live

## How to engage
1. **Wedge (free)** — Signed MCP + live demos.
2. **Pilot (NRE, ~$75–350k, 60–90 days)** — the Binder on one real facility/workload at L1→L3.
3. **Scale (subscription)** — measured hosting across the fleet; provable, Measured AI™-badged capacity per tenant.
Partners co-present with Rootz: partner's infrastructure, Rootz's measured-compute layer.

## About / credibility
The measured-compute layer for AI; data centers are one vertical of a platform live today (13 public
surfaces). Granted patent on attested inference; active in the Digital LTL Council eBOL signing-layer
standards work; "Measured AI" is the umbrella brand and certification mark. Rights-and-infrastructure play
riding a regulatory tailwind (GDPR → DMA → eIDAS). Led by Steven Sprague.

## Positioning guardrails
- Lead with **provable hosting, revenue, and Zero-Trust-finished** — not privacy, not the word "sovereignty."
- Rootz makes the **verb provable** and keeps **custody local**; not winner-take-all, not surveillance.
- Do not overclaim assurance depth; state the honest L-level.

## Contact
Steven Sprague — steven@sprague.com — https://rootz.global
