ProofForge
A flight recorder for your AI agents.
It records what your agents do and seals each record so any later change is visible. Read-only, so it can never be the incident.
The gap
Logging wasn’t built for agents.
Not because anyone was careless. It was built for systems that ask permission, not for software that acts on its own.
Nobody can say how many agents are running.
Three platforms, three log formats, no single record.
Every one of those logs can be edited.
None of them map to a control you answer for.
The pipeline
From action to evidence
Six steps between an agent doing something and an auditor believing it.
01 · Inventory
Every agent, with a human sponsor.
02 · Capture
Read-only collectors, never in the request path.
03 · Normalize
One canonical record, one fixed taxonomy.
04 · Chain
Append-only. Corrections supersede, they never edit.
05 · Map
Control mappings are content, not code.
06 · Prove
Evidence packs that regenerate byte-identically.
07 · Watch
Three detections. High precision. No intervention.
Nothing is blocked or rewritten in your platform. A rule can notify the people who own it and mark the agent suspended in ProofForge’s own record. A human takes it from there.
The core
Sealed where nobody can quietly rewrite it
The part that has to be true for anything else here to matter.
Tamper-evident core
Each record is canonicalized, then hashed together with the hash of the record before it. Once a day those roots are combined into one value your own key signs, and that value leaves the database for storage you hold.
So an insider with database access, ours or yours, cannot change history quietly. Any alteration fails against copies that were already distributed.
- 01Ingest
- 02Hash
- 03Sign
- 04Seal
- System status
- Operational
- Last block
- #489,210
- Sample data
- Not a live instance
What we guarantee
Four things that stay true wherever it runs.
- Runs inside your organisation
- Self-hosted and single-tenant, on your infrastructure. No vendor control plane, no callbacks, no data crossing your border.
- You hold the keys
- The daily root is signed by your own KMS. We cannot read what you seal, and we cannot sign on your behalf.
- Independently verifiable
- An inclusion proof for the record, checked against anchors you already hold. Your auditor verifies one record without access to everything else.
- Read-only where it counts
- It sits in no request path and cannot block, delay or alter what an agent does, so it can never be the incident. Inside its own record a rule can raise a finding, notify an owner, and suspend an agent pending a human decision.
DeploymentSelf-hosted / single-tenant
AnchoringYour KMS
VerificationMerkle inclusion proofs
ExecutionNone against your systems
The claim we refuse to make
Evidence of capture, not proof of absence.
Every pack states what was captured, source by source, and what wasn’t. When a source goes quiet the gap becomes a finding within a day, and a gap in monitoring is never counted as evidence that monitoring worked.
See a sealed record become evidence.
A 30-minute walkthrough: we record live agent actions, alter a log, and show you exactly where the chain breaks.