Audit-grade evidence,
not a promise.
When you answer to an auditor or an Authorizing Official, "trust us" isn't an answer. Every action an agent takes is Ed25519-signed, hash-chained, and mapped to NIST 800-171 and CMMC controls — exported as OSCAL / eMASS and re-verifiable offline, with no connection to us.
An export, not a promise.
The evidence is generated at the layer below the agent — server-side and signed — so it's the same record whether you read it or your auditor does.
Signed, re-verifiable chain
Every prompt, tool call, and output is Ed25519-signed and hash-chained. Export any run and re-check every signature and hash offline on your own machine. Tamper one byte and verification fails — the proof is yours to hold.
Ed25519 · VERIFY OFFLINEMapped to your controls
Runtime events are mapped to NIST 800-171 and CMMC controls — so the evidence lines up with the framework your assessor already uses, instead of a pile of logs nobody can trace to a requirement.
NIST 800-171 · CMMCOSCAL / eMASS export
Generate machine-readable OSCAL and eMASS-shaped output you can hand directly to a compliance pipeline or an Authorizing Official — the same evidence, in the format the process expects.
OSCAL · eMASSSeparation of duties
Owner / reviewer / viewer roles are enforced server-side, and destructive actions are gated by role. Who approved, who launched, who could not — it's stamped into the same signed chain you export.
ROLE-GATED · ACTOR-STAMPEDHow an agent run becomes cATO evidence.
Continuous monitoring needs a continuous source of truth. Here's the path a single agent action takes — from the moment it happens to the artifact your assessor opens.
The action is captured below the agent SERVER-SIDE
A prompt, a tool call, an output, a routing decision, a kill — each is recorded at the runtime layer, not by the agent describing itself. The workload can't choose what gets logged, omit a step, or edit the record after the fact.
It's signed and chained Ed25519 · HASH-CHAINED
Each event is Ed25519-signed and linked to the one before it. Reorder, drop, or alter a single event and the chain breaks — so the sequence itself is part of the evidence, not just the contents of any one entry.
It's mapped to a control 800-171 · CMMC
The event is tied to the NIST 800-171 and CMMC control it evidences — access enforcement, audit generation, boundary protection — so your continuous-monitoring story is anchored to the framework your assessor already reports against.
It exports as OSCAL / eMASS MACHINE-READABLE
The mapped, signed evidence renders as machine-readable OSCAL and eMASS-shaped output — the form an Authorizing Official's process expects — and the same run re-verifies offline, byte for byte, on a machine we never touch.
Runtime events, mapped to the families.
The mapping isn't decoration — each runtime event is the kind of evidence a 800-171 control family asks for. A few representative examples.
Access enforcement
Owner / reviewer / viewer roles, who could launch a run, and who was denied a destructive action are recorded as access-control evidence — the actor is stamped into the signed chain, not asserted in a policy doc.
ACCESS CONTROL · 3.1Audit & accountability
Every prompt, tool call, and output is generated as a signed, time-ordered audit event that can't be repudiated — covering the audit-generation and tamper-protection expectations directly, with offline re-verification as the proof.
AUDIT & ACCOUNTABILITY · 3.3System & comms protection
The no-route sandbox and sole-egress broker are boundary protection in practice: a blocked egress attempt or a constrained model call is captured as evidence the boundary held, not just configured.
SYSTEM & COMMS · 3.13System & information integrity
A host-authoritative kill — outside the sandbox, on budget breach or kill-switch — is recorded as a contained, signed event, evidencing that the monitoring and response controls actually fired when they had to.
SYSTEM INTEGRITY · 3.14Verifiable beats credible.
The point isn't that we say the controls ran. It's that you don't have to take our word for it.
The agent can't reach the chain NO-ROUTE SANDBOX
Each agent runs in its own container with no route to the internet, and a sole-egress broker is the only door out. The thing being audited has no path to the evidence about it — so the record can't be quietly rewritten by the workload.
The key never enters the workload BROKER-HELD
Your model keys live in a libsodium-encrypted vault. The broker holds them and injects them at call time, policy-checked against the allowed model, the budget, and the kill switch — the key is never present inside an agent container to leak.
Re-verify it yourself, offline OPEN VERIFIER
Export a run and re-compute every hash and re-check every Ed25519 signature with no network connection to us. A governance product that can't be checked independently isn't governance — it's a claim. This one is the opposite.
What an AO actually wants to hear.
Straight answers to the questions a security lead or Authorizing Official raises first — no hedging.
“Can the agent tamper with its own audit trail?”
No. The evidence is generated at the runtime layer, below the agent, and written to a hash-chained log the agent has no route to reach. To alter the record, you'd have to break an Ed25519 signature and re-link the chain — and the offline verifier would catch it. The workload being audited is structurally separated from the evidence about it.
“Do we have to trust your infrastructure to trust the evidence?”
No. That's the point of offline re-verification. You export a run and re-compute every hash and re-check every signature on your own machine, with no connection back to us. If our infrastructure had quietly changed a byte, the verification fails on your hardware. The trust anchor is the math, not our word.
“How does this fit a continuous-ATO posture?”
cATO needs a continuous, trustworthy evidence stream tied to controls — not a point-in-time screenshot. Every governed run emits signed events mapped to 800-171 and CMMC controls and exported as OSCAL / eMASS, so monitoring is fed by the runtime itself. We're the evidence source that feeds your eMASS and GRC process, not a competing system of record.
“What’s self-assessed versus attested?”
Plainly: CMMC L1 / L2 is self-assessed today, and the SOC 2 Type II audit is targeted for Q3 2026 — not yet attested. SSO / SAML and a per-tenant policy editor are not shipping today. We tell you the state because a trust product that overstates its own posture is the one thing an auditor will never forgive.
Don’t trust us — verify the export. Re-compute every hash and re-check every Ed25519 signature offline, on a machine we never touch. If one byte changed, it fails. That’s the difference between “we logged it” and evidence you hold.
Where we stand. No asterisks.
The signed audit chain is the evidence backbone, mapped to NIST 800-171 and CMMC, with OSCAL / eMASS export. CMMC L1/L2 is self-assessed; the SOC 2 Type II audit is targeted for Q3 2026, not yet attested. We don't ship SSO or a policy editor today, and we won't pretend otherwise — a trust product that overstates isn't one.
NIST 800-171
Runtime events are mapped to the controls your assessor reports on.
CONTROLS MAPPEDCMMC L1 / L2
Self-assessed today. We say so plainly rather than imply a certification we don't hold.
SELF-ASSESSEDSOC 2 Type II
Targeted for Q3 2026. Not yet attested — that's the honest state today.
TARGETED Q3 2026Hand the export
to your auditor.
Run a governed agent, export the signed evidence mapped to your controls, and let your security team — or an Authorizing Official — re-verify it themselves. Business is $1,779 / mo; BYOK, so you only ever pay your provider for tokens. For a tailored rollout, talk to us.