ProofForge

A flight recorder for your AI agents.

It records what your agents do and seals each record so any later change is visible. Read-only, so it can never be the incident.

The gap

Logging wasn’t built for agents.

Not because anyone was careless. It was built for systems that ask permission, not for software that acts on its own.

  1. Nobody can say how many agents are running.

  2. Three platforms, three log formats, no single record.

  3. Every one of those logs can be edited.

  4. None of them map to a control you answer for.

The pipeline

From action to evidence

Six steps between an agent doing something and an auditor believing it.

  1. 01 · Inventory

    Every agent, with a human sponsor.

  2. 02 · Capture

    Read-only collectors, never in the request path.

  3. 03 · Normalize

    One canonical record, one fixed taxonomy.

  4. 04 · Chain

    Append-only. Corrections supersede, they never edit.

  5. 05 · Map

    Control mappings are content, not code.

  6. 06 · Prove

    Evidence packs that regenerate byte-identically.

  7. 07 · Watch

    Three detections. High precision. No intervention.

    Nothing is blocked or rewritten in your platform. A rule can notify the people who own it and mark the agent suspended in ProofForge’s own record. A human takes it from there.

The core

Sealed where nobody can quietly rewrite it

The part that has to be true for anything else here to matter.

Tamper-evident core

Each record is canonicalized, then hashed together with the hash of the record before it. Once a day those roots are combined into one value your own key signs, and that value leaves the database for storage you hold.

So an insider with database access, ours or yours, cannot change history quietly. Any alteration fails against copies that were already distributed.

  1. 01Ingest
  2. 02Hash
  3. 03Sign
  4. 04Seal
System status
Operational
Last block
#489,210
Sample data
Not a live instance

What we guarantee

Four things that stay true wherever it runs.

Runs inside your organisation

DeploymentSelf-hosted / single-tenant

Self-hosted and single-tenant, on your infrastructure. No vendor control plane, no callbacks, no data crossing your border.
You hold the keys

AnchoringYour KMS

The daily root is signed by your own KMS. We cannot read what you seal, and we cannot sign on your behalf.
Independently verifiable

VerificationMerkle inclusion proofs

An inclusion proof for the record, checked against anchors you already hold. Your auditor verifies one record without access to everything else.
Read-only where it counts

ExecutionNone against your systems

It sits in no request path and cannot block, delay or alter what an agent does, so it can never be the incident. Inside its own record a rule can raise a finding, notify an owner, and suspend an agent pending a human decision.

The claim we refuse to make

Evidence of capture, not proof of absence.

Every pack states what was captured, source by source, and what wasn’t. When a source goes quiet the gap becomes a finding within a day, and a gap in monitoring is never counted as evidence that monitoring worked.

See a sealed record become evidence.

A 30-minute walkthrough: we record live agent actions, alter a log, and show you exactly where the chain breaks.