AGENT RECORD AUDIT · FORENSIC RECORD & PROVENANCE VERIFICATION FOR AUTONOMOUS SYSTEMS
If one of your AI agents harmed a third party tomorrow, could you prove what it did — and that the record wasn't altered afterward?
Under whose authority it acted, what information it had, which model produced the action, what actually executed. Most organizations find out the answer during the incident. That is the wrong time to find out.
What a reconstructable record looks like
The findings memo you receive follows the same discipline — read a full sample report built from this synthetic incident, or download it as a PDF.
Start here — check your own records
Before any engagement, run the self-check. It is the same eight questions every audit answers, and it will show you where your evidentiary chain likely breaks — for free, and without sending us anything.
Answer these about your own agent deployment. This runs entirely in your browser — nothing is uploaded, and this is a self-assessment, not the audit. The audit reconciles your answers against independent evidence.
What it is — and is not
The method is reconciliation: we take what your system claims happened and reconcile it against what independently verifiable sources say happened — provider billing, upstream and downstream logs, execution records, cryptographic recomputation. The goal is to find where the chain of events cannot be independently reconstructed.
It is not a penetration test, not a model evaluation, and not a certificate that your system is “safe.” It does not manufacture a defense. It tells you what your system can actually prove — and where it cannot.
What we will not claim
This is not a legal opinion — your counsel determines the legal significance of any finding. No architecture creates a safe harbor; a tamper-evident record does not make unauthorized conduct lawful. We do not certify claims we cannot substantiate, and our bias-screening research measures toxicity and framing signals — it is not a protected-class discrimination test and will not be represented as one.
Beyond the first session
Scope and pricing for these are established after the initial session. No engagement begins before scope is agreed in writing. Every finding ships with the method used to reach it, so your own team can reproduce the test after remediation — the method transfers; you don't stay dependent on us.
To start
Bring one agent deployment and whoever owns its logs. We examine the Eight Questions. If your system already has good answers, we'll tell you. If it doesn't, we'll show you where the evidentiary chain breaks and what it would take to close the gap.
BOOK THE 90-MINUTE REVIEW →