Govern the estate
Evidence a third party can check.
A run started. Citations verified. Policies evaluated. A named lawyer signed off. A report exported. Each of those is hashed, linked to the event before it, and immutable at the database level. What comes out is shaped for the person asking, not a dump of raw logs.
run_started
hash 9f41…c2
citations_verified
prev 9f41…c2
policies_evaluated
12 linked verdicts
human_review
named reviewer
certificate_issued
insurer pack
report_exported
sha256 anchored
Illustrative. Change any earlier link and every hash after it stops matching.
The unusual artifact is not that software refused. It is that a named human accepting a flagged risk becomes something a regulator can inspect.
Most AI governance tooling can tell you a policy fired. Very little of it can tell you who read the flag, what they were shown at the time, what they decided, and prove afterwards that the answer has not been edited since. That last part is what an SRA enquiry, a PI renewal and a client questionnaire all separately need.
Ships today
Exports shaped for the person asking.
A regulator, an insurer and a client want different documents. None of them wants a log file.
For the regulator
SRA-aligned audit report
An editable document covering a period you choose. Every figure is queried from the evidence store and maps to the Code provisions it answers.
For a single matter
Per-run evidence pack
One run, end to end: the report, the execution trace, the verbatim audit rows with their hashes and signatures, and a manifest.
For your broker
PI insurer evidence pack
The AI questions on a proposal form, answered from records rather than adjectives, in time for renewal.
For the client
Client AI-use disclosure
What AI touched this client's work, under what supervision. The answer to an outside-counsel questionnaire before it is asked.
For the framework
EU AI Act oversight attestation
Human-oversight evidence in the shape Article 14 expects, for firms whose output reaches the EU.
For a visit
Inspection bundle
A frozen snapshot of the dashboard plus a chain attestation, so what an inspector sees is what you saw.
On the roadmap
Not shipped yet, and we will not imply otherwise.
These three make the chain verifiable by someone who does not trust us at all. They are in build, not in production, and this page will say so until they are.
Asymmetric signing
Signing keys held in a hardware-backed vault, so the chain proves non-repudiation rather than only tamper-evidence.
Published transparency log
Periodic roots published openly, so we cannot quietly rewrite history either.
Standalone verifier
A command-line tool that re-checks every hash and signature in a bundle on a machine with no access to us.
The evidence chain, answered.
What the record holds, who can check it, and what we have not built yet.
Still have questions? Talk to the founderFrom the blog
What the evidence has to prove
The records a regulator can ask for, what an audit report has to contain, and the questions arriving with your renewal.
See what your firm could produce today.
The readiness check tells you which of these records your firm could hand over now, and which would take a fortnight of reconstruction.