Proof

Every agent decision, on a receipt anyone can verify.

Praesidia writes each policy decision on an agent’s tool calls into a signed, chained record, and builds signed bills of materials, trust passports and incident files from the same evidence. Your auditor checks the record on their own machine, offline, without trusting us.

Signed bills of materials, trust passports and the signed audit trail are in every plan, including the free Developer plan. No credit card required.

Decision record · No. 000412 Illustrative
When
14 Sep 2026, 10:42:07 UTC
Agent
Invoice agent
Wanted to
Refund €8,250 to customer C-1182 through the payments MCP server
Rule
Refunds above €5,000 need a finance approver
Decision
Held for approval · 10:42 Approved by finance lead · 10:44

signed 7f3a 91c0 … c21e
follows no. 000411 a90d … 4b07

Illustrative record, real record shape. A hold applies once a policy is set to enforce; human approval is an Enterprise capability.

The question this page answers

Can your auditor check what an agent did last Tuesday, without logging in to anyone’s console, including ours?

A dashboard can tell you an agent was governed. Praesidia hands you the record: what the agent asked to do, which rule decided it, who approved it, and a signature and chain that stop checking out if anyone changes a single line afterwards.

Exhibits

Evidence you can hand over, not screenshots of a dashboard

Each exhibit is something Praesidia produces for you, signed, so the person receiving it can tell nothing was changed after it left your hands.

Exhibit A · every plan

A signed bill of materials for every AI system

Models, tools, data sources and policies, versioned on every change. Export it as CycloneDX, compare two releases line by line, and verify it offline. A new model or data source reopens the system’s review on its own.

The AI bill of materials

Claims triage assistant · version 14 → 15 Illustrative
Model · openai / gpt-4.1No longer used
Removed
Model · anthropic / claude-sonnet-4.5Replaces it
Added
Tools · tickets.read · kb.searchUnchanged
Same
Tool · crm.export_contactsNew tool the assistant can call
Added
Data · EU customer ticketsPersonal data
Added
Policy · Support, read-onlyUnchanged
Same

Review reopened: substantial change · CycloneDX · Signed snapshot

Exhibit B · every plan

A trust passport your customers can check

Publish a page, a badge and a PDF for each AI system, rooted in its evidence. When a vendor sends you theirs, import it and verify it against the key you pinned, before their agent touches your data.

How trust passports work

Trust passport · Claims triage assistant Illustrative
Published by
Acme Finance
Bill of materials
Version 15, signed
Last evaluation
Passed, 12 Sep 2026
Evidence root
3c9e 0b12 … 77fa

Verified passport

Exhibit C · every plan

An incident file, opened for you

Related signals become one incident with a response timeline and a signed evidence bundle, with the report a regulator asks for after a serious incident drafted from it. Each incident proposes the control that stops a repeat: one click to accept, one to undo.

Incident response

Incident 0192 · support agent, data exfiltration attempt Illustrative
Guardrail blocked a prompt injection in an inbound ticket10:02
Call to an undeclared outside domain refused at the gateway10:04
Incident opened: 3 signals grouped10:05
Opened
Agent’s email tool permission removed; owner notified10:21
Evidence bundle signed; regulator report drafted11:40
Signed
Proposed control: an evaluation that replays this attack before every release11:42
From the product

The record itself, before anyone checks it

Every action, who took it, when, and the payload it carried: the rows a signed export is built from.

Audit log table: ten rows, each naming the action, the actor, the timestamp and a details payload. The top four are hourly audit root computations, then Protected Action Closed, Gateway Budget Reservation Committed and Billing Usage Logged; every visible row was recorded by the system itself.
The Praesidia audit log, demo workspace.
By the numbers

Counted, not claimed

Numbers you can check against the product, not against a customer we can’t name.

62ISO/IEC 42001 controls in the catalogue
72NIST AI RMF subcategories
142crosswalk mappings between them
24guardrail templates, plus your own
11red-team attack families
6model providers behind one gateway URL
13relationship kinds in the AI System Graph
4rollout stages from simulate to enforce

Counted in the product, September 2026.

Verify

Don’t take our word for it. Check the record.

The audit trail is signed and hash-chained by default. Its value is that you never have to trust Praesidia to believe it.

  1. 1

    Export a signed bundle. Organization owners and compliance officers export any range up to 90 days. The export is itself recorded.

  2. 2

    Hand it to whoever needs to check. Your team, your auditor, a regulator, together with our Apache-2.0 offline verifier, which we give you directly.

  3. 3

    They check it on their own machine. Offline, without calling us. Valid, invalid or incomplete, with an exit code a script can act on, never a silent pass.

Verifier output Illustrative — real output shape
$ praesidia-verify finance-2026-q3.zip

manifest          valid  1 checked
row signatures    valid  412 checked
chain integrity   valid  412 checked
root signatures   valid  3 checked
rekor receipts    valid  3 checked
platform attest.  valid  1 checked

RESULT: OK   exit 0

Receipts from the public Rekor log appear when external anchoring is on.

Limits

What the proof shows, and what it does not

A seal is only worth what you know about its limits. These are the short versions; the full list is on verify your audit trail.

It shows
  • Nothing was changed. No record in a bundle was added, altered or removed after it was signed.
  • Nothing is missing from the chain. The records form one unbroken hash chain: no fork, no orphan, no gap.
  • Who signed it. Every record is signed by a key in the bundle’s signed key set, and that key was not revoked.
  • An outside witness, when you want one. With external anchoring on, each hash root has a receipt in a public log we cannot rewrite.
It does not show
  • That every action was captured. A signing outage leaves an unsigned record and no marker in the chain.
  • That the newest records are all there. The not-yet-anchored tail of your history is not bound to a count.
  • That anchoring was on. Read the anchoring line; an overall pass does not imply it.
  • Certification. Framework mappings are not certifications, and a passport reports posture rather than guaranteeing it.

New policies start in observe mode: decisions are recorded, nothing is blocked. Denials and holds apply once a policy is set to enforce. Human approvals are an Enterprise capability. Framework mappings are not certifications. Records and figures marked Illustrative show the real shape with invented data.

Read next: evidence and audit · incident response · Trust Center · compliance mappings · the whole platform

Start with one agent. Keep every receipt.

Pricing is public. No credit card required.