Prove what every model did

Answer an auditor’s “what did the AI actually do” with proof, not a log line they have to trust.

When an auditor, an investigator, or a customer asks what an AI system actually did, plain logs are a weak answer. They can be edited or deleted, and a single line gives nobody a way to independently verify what a model was asked or what it returned. As AI reaches regulated workflows, that gap turns into a liability.

What you can do

  • Record every interaction on a surface, whether it succeeded, was blocked, or failed, so that you hold a complete transcript of what entered, how it was processed, and what left.
  • Capture per-call cost, latency, tokens, and each guardrail verdict so that you can show who called what, and why it passed or was blocked.
  • Sign every record as a Verifiable Credential and chain it by content hash so that deletion or tampering is detectable, not just individual forged records.
  • Export the signed trail to your SIEM or observability stack so that security and finance work from one source of truth.

How it works

EVERY INTERACTIONPromptStage verdictsCompletionCost · tokens · latencyAUDIT & EXPORTAuditorsSecurityFinanceOTel · SIEM · webhookGovernance RecordsSIGN AS VCW3C Verifiable Credentialappliance DID keyPROTECTEDAES-256-GCM at rest · hashed caller idbody capture optional (digests otherwise)Record 1hash: H1Record 2prev: H1hash: H2Record 3prev: H2hash: H3Verify chain → pass / faildeleting or reordering a recordbreaks the chain

Governance recording is enabled per surface, off by default. Once on, every interaction is written into a Governance Record: an ordered list of the processing stages that ran, each with its verdict, plus the prompt, the completion, and the metrics for the call. Each record is wrapped in a W3C Verifiable Credential and signed with the appliance’s own key, tied to its Decentralised Identifier, and every record embeds the content hash of the previous record on the same surface, forming a per-surface hash chain. Records are encrypted at rest with AES-256-GCM, the caller identity is stored as a salted hash rather than a raw identifier, and each signed record can also be exported to OpenTelemetry or an integration such as a webhook, a SIEM, or a streaming bus.

A surface’s chain can be verified on demand: verification recomputes every record’s content hash and walks the links, returning a pass or fail with the number of records checked, so a deleted or reordered record is detectable rather than silent. With body capture turned off, the appliance keeps cryptographic digests only, still proving what content flowed without storing the raw text.