Live evidence page

The security questionnaire, answered by the record.

Every number here is read from our own record as this page loads, so it states what is true now, not last quarter. Nothing asks you to take our word: the last section shows how to check it yourself, offline.

◎ Sealed through #14283. 14,284 events across 25 agents; 493 of 496 seals countersigned by an independent timestamp authority, 494 held write-once.read as this page loaded
Events on the chain
14,284
each carries the fingerprint of the one before it
Countersigned
493 of 496
494 also in write-once storage
Sealed through
#14283
head countersigned · nothing waiting
How much of it we are hearing

Configuration completeness, with the to-do.

Integrity is above. This is a different question: how much of what this deployment could record arrives. Published with what closes each gap.

Configuration completeness
79of 100

3 open items to close

What closes each item

  1. 01capture planes not yet live: edgeconnect the plane it names — a gateway, the SDK, a vendor webhook, or read-only access
  2. 021 of 1 traces observed on a single plane only — assertion, not corroborationadd a second capture plane so intent has a corroborating record
  3. 0317 events carry cost the upstream did not priceadd the model to the price table
The questionnaire

The rows a reviewer sends, answered from the chain.

01
Answered from the recordDo you maintain an audit trail of agent actions?
Yes — 14,284 events across 25 agent(s), hash-chained in an append-only store. The chain head is at sequence 14,284.
02
Answered from the recordCan the audit trail be altered after the fact?
Any alteration is computable: each event carries the hash of the one before it; 493 of 496 signed checkpoints are countersigned by an independent RFC 3161 timestamp authority, and 494 are additionally held in write-once storage (S3 Object Lock, compliance mode) that not even our cloud account's root user can delete. Editing a stored event breaks verification at that exact sequence.
03
Answered from the recordIs there a kill switch, and is its use itself recorded?
Yes — a tenant-level halt that wins over every other rule. Current state: armed, not engaged. Every flip is chained under the operator's name.
04
Answered from the recordAre humans in the loop for high-impact actions?
Yes — "Moving more than the threshold requires a named human to approve first." (enforcing). 0 action(s) held for sign-off in this record; every grant or refusal is a chained event naming the reviewer.
05
Answered from the recordAre out-of-bounds actions blocked, not just flagged?
Yes — deny-by-default evaluation runs before enforced actions execute; 0 action(s) blocked in this record, each carrying the rule id, version, and reasons.
06
Answered from the recordAre adverse decisions about people recorded with reasons?
Yes — "A decision against a person must record why, in structured form." (enforcing). A decision against a person without a structured reason is refused.
07
Answered from the recordCan you reconstruct an incident end-to-end?
Yes — events are strictly sequenced, and sessions and trace ids join related actions across capture planes (model, action, effect). Configuration completeness: 79/100, with its open items stated above.
08
Answered from the recordWhat happens to the evidence if the vendor disappears?
Nothing. The format is open, exports are self-contained, and the verifier runs offline with no account — the record stays independently checkable whether or not Auditant exists.
Do not take our word for it

Verify it yourself.

Request the evidence bundle for any window from the operator — a single JSON file carrying the events, the checkpoints, the public keys, and its own verifier. With nothing but Node.js:

The verifier recomputes every hash, re-links the chain, and validates each checkpoint signature and RFC 3161 countersignature. It names the exact sequence number at the first discrepancy.

anyone, anywhere — with nothing but Node
node -e "const b=require('./bundle.json');require('fs').writeFileSync('verify.mjs',b.verifier)"
node verify.mjs ./bundle.json
What this proves, and what it does not

Verification proves the records were not altered after their checkpoint anchored. It cannot prove the log is complete: an action that never reached Auditant is not in it, and no signature can say otherwise. Coverage is answered by deployment configuration — the score above, and its deductions — never by a signature.

That property survives us. The format is open and the verifier needs neither our servers nor our permission.