What exists today, and what is being built
Be precise about maturity, because compliance is a high-trust area. The open protocols (AEE, AOCL, VOLT, WARD) are shipped, and quoxproof is live on PyPI and verifies tool-call receipt signatures offline today. Quox itself is self-hosted (Docker), with per-organisation isolation and human-in-the-loop approvals on sensitive actions. The full control plane is pre-launch, so treat one-button pack assembly across all four layers as maturing rather than a finished product, and verify the exact export flow against your own instance before you rely on it in an audit. What you can run yourself now is the signature check via quoxproof; the hash-chain, timestamp and witness checks are the model the VOLT and WARD protocols are built to support, and the end-to-end pack verifier is maturing toward that.
The design principle underneath all of it is on the security page: evidence by default, so proof is a property of the system rather than a report someone assembles after the fact.