Company overviewOne page, start to finishUpdated September 2026
Evidence infrastructure for regulated AI.
Organisations are deploying AI agents faster than they can govern them. Flow Forge records what those agents do and seals each record so any later change is visible. It runs inside your environment, under your keys.
- What it is
- Evidence infrastructure for regulated AI
- Product
- ProofForge
- Runs
- Self-hosted, under your keys
- Posture
- Read-only
01
The gap we close
Three questions most organisations cannot currently answer about their own AI agents:
- 01
How many AI agents are running inside the organisation right now, and who sponsors each one?
- 02
What did they do last Tuesday — and can that record be shown not to have been altered since?
- 03
Which of the control obligations you are audited against does that evidence actually satisfy?
Not because anyone was careless — because the tooling doesn’t exist. Each platform logs to its own store in its own format, with no integrity guarantee and no mapping to the controls the organisation is audited against. Audit logs, SIEM archives and database history can all be edited by someone with enough access, and none of them can demonstrate that they weren’t. The obligations arrived before the infrastructure did.
02
What ProofForge does
Every agent is registered with an owner, a business purpose, a risk tier and a lifecycle state. An agent that is active but never approved surfaces as a standing finding — the shadow agent nobody declared.
Activity is pulled, never intercepted, and normalized into one canonical action record. Capture is metadata-first, with full payloads opt-in per source and encrypted field by field.
Append-only and hash-chained in sequence, with a daily root signed by your own key management service and exported to storage you already hold. Corrections supersede; they never edit.
Coverage against the controls you are audited against, evidence samples, findings and a chain-of-custody statement — regenerating byte-identically, attested by a named reviewer.
03
How a record becomes a proof
01
Ingest
Agent activity arrives from the systems you already run — read-only, inside your own network. Nothing is moved out to us.
02
Hash
Each record is canonicalized to one byte-exact form and hashed together with the hash of the record before it.
03
Sign
The day's root is signed by your own key management service. We cannot sign on your behalf, and payload keys never leave your control.
04
Seal
The signed anchor is exported to write-once storage or an audit mailbox. Alter any record afterwards and verification fails against copies you already hold.
04
How it deploys
- Runs inside your organisation
- Self-hosted and single-tenant, with no vendor control plane and no cross-border transfer. Updates arrive as signed images through your own registry; an offline bundle path exists.
- You hold the keys
- Anchoring is signed by your key management service and payload encryption keys stay yours. We cannot read what you seal.
- Independently verifiable
- Verification returns an inclusion proof for the record plus a check of the chain around it — so an auditor can check one record without access to everything else.
- Read-only by design
- It sits in no request path, blocks nothing and scores nothing. It cannot cause an incident, and it is worth little to an attacker as a way in.
05
What we refuse to claim
Evidence of capture, not proof of absence. Every pack states what was captured, source by source, and what wasn’t. When a source goes quiet the gap becomes a finding rather than a silent hole in the record — and a gap in monitoring is never counted as evidence that monitoring worked.
Model-generated summaries, where they appear at all, are labelled non-evidentiary and never enter the integrity chain. Every claim in a report traces back to a record you can open. Auditors distrust magic, so there isn’t any.
06
Who it’s for
Any organisation that lets AI agents act on its behalf — government and regulators, financial services, telcos, healthcare, enterprise IT and managed security providers. These are the roles that carry the question.
- The security lead
- A defensible answer to whether AI agents are acting inside the environment at all.
- Risk and AI governance
- An inventory with owners and risk tiers, and proof the governance on paper is the governance in practice.
- The auditor or regulator
- Evidence per period with a chain-of-custody proof, instead of timelines reconstructed after the fact.
- The platform engineer
- An integration that cannot break the agents they already run.
07
See it for yourself
A 30-minute walkthrough, run on real behaviour rather than slides: we record live agent actions, alter a log, and show you exactly where the chain breaks. Requests are read personally and answered within 48 hours — no drip campaign.