Evidence an auditor will actually accept.
A hash-linked, Ed25519-signed audit chain — not a folder of screenshots.

From record to verified evidence in four stages.
- 01
RECORD
Every decision, policy change and guardrail verdict is written as a hash-linked entry.
- 02
SIGN
Exports are signed with Ed25519 so recipients can verify origin and integrity.
- 03
VERIFY
Anyone with the public key can recompute the chain and confirm nothing was altered.
- 04
SHARE
Auditors get a scoped, read-only portal. Internal teams use the evidence locker.
What it does.
Tamper-evident audit chain
Hash-linked entries make it computationally obvious if a single record is changed or deleted.
Ed25519-signed exports
Every export bundle carries a signature and includes the public key needed to verify it.
Auditor portal
A scoped, read-only external role that lets auditors browse evidence without seeing production data.
Evidence locker
Collected artifacts, campaign results and policy snapshots stored in one governed location.
Access trail and audit log
Who viewed, exported or modified what — with timestamps and identity attribution.
Exportable PDF reports
Board, auditor and regulator-ready reports generated from live evidence in seconds.
AI readiness assessment
A structured evaluation of governance, risk and control maturity against leading frameworks.
SEC incident materiality decision tree
Walk through the SEC cybersecurity disclosure logic with documented rationale at each node.
Privacy operations
DSR intake and handling workflows plus ROPA records for privacy teams.
One entry, one hash.
policy > "Export the last 90 days of runtime verdicts for auditor 'external-firm-2026'"
export_id: "exp-2026-0830-ce"
entries: 2,847,192
signed_with: "ed25519:pk-7d1a…e03b"
merkle_root: "sha256:9f4c…b21a"
chain_valid: true
recipient: "auditor/external-firm-2026"
access_expires: "2026-11-30T23:59:59Z"
verdict: "EXPORT_SIGNED_AND_DELIVERED"
Controls and evidence are mapped to the frameworks that govern your AI risk.
Mapped to the standards that matter.
OWASP LLM Top 10 (2025)
Runtime guardrails map directly to LLM01 Prompt Injection, LLM02 Sensitive Information Disclosure and LLM06 Excessive Agency.
NIST AI RMF
GOVERN, MAP, MEASURE and MANAGE are covered by governance workflows, data posture, continuous measurement and inline controls.
MITRE ATLAS
Red-teaming probes and runtime detections align with adversarial tactics, techniques and procedures in the ATLAS matrix.
ISO/IEC 42001
AI management-system requirements are supported by policy lifecycle, risk assessment and evidence management.
EU AI Act
Risk classification, governance documentation, transparency and post-market monitoring evidence are produced automatically.
GDPR
Data-flow mapping, DSR handling, ROPA records and PII detection in prompts support privacy-by-design obligations.
SEC cybersecurity disclosure
Incident materiality decision tree and timeline evidence help disclose material AI security incidents with defensible rationale.
AIUC-1
AI usage and control evidence is collected continuously for internal AI use-case governance and review.
SOC 2 Type II is in progress. We will publish the report here when it is issued — we will not claim it before then.