Problem Deploy Demo Security Pricing GitHub FAQ
●  For the moment someone asks you to prove what your AI decided: an examiner, a plaintiff, your own board  and more →

Your AI is already making decisions. Prove every one of them.

A record is one AI decision, sealed the moment it was made and tamper-evident ever since: the policy that governed it, what the model was given, what it decided. Whoever is asking can check it without you and without us.

A working system, live today. Not a mockup.
The gap

Someone challenges the decision.
You have only your word.

AI agents now approve loans, flag fraud and deny prior authorizations. Regulators, auditors and opposing counsel are all entitled to ask why.

OCC examination scenario

Your AI agent approved 9,300 loan applications last quarter. Now prove how each one was decided. You have logs and audit trails. They sit inside your own systems, vouched for by you. Not enough. What you cannot prove, you concede.

Five demands. Here is what each one costs you.

01

Which version of the policy was in force?

✗
Your stack todayReconstructed afterwards, and hope it matches
✓
With PlainRealThe policy version itself, sealed at the decisionpolicy_version_hash
02

Prove the model got exactly that, and nothing else

✗
Your stack todayLogged, but not provably unchanged
✓
With PlainRealExactly what the model was given, locked before it raninput_hash
03

Prove nobody edited this afterwards

✗
Your stack todayControls you administer, and can change
✓
With PlainRealWritten once, signed, timestamped
04

Prove it without asking me to trust you

✗
Your stack todayYou vouch for your own logs
✓
With PlainRealThe examiner verifies offline, without you
05

And have it by Friday

✗
Your stack todayWeekslegal, engineering, whoever owns the logs, and outside counsel. Each reconstructing separately, each billing
✓
With PlainRealNonenothing to reconstruct; it was sealed at the decision
And the tools you already run

None of that is fixed by them. Cloud audit logs, AI monitoring, policy engines and your SIEM govern the runtime. They record what ran. None of them commits what the model was given, before it ran.

A communications archive is the strongest version of this objection. It holds the record outside your systems, which genuinely answers custody. It still records what passed through it, and checking it means asking whoever holds it.

Which is the question worth asking of anything that calls itself sealed: what does someone need in order to check it? Here, the file and a published key. Nothing else, and nobody to ask.

Why CloudTrail and OpenTelemetry fall short →
The artifact

This is what you hand over.

One record for each decision that matters. The one below is real and this summary is generated from it, so it cannot say anything the record does not. Change the outcome and watch the proof fail.

Decision record · a1b2c3d4-e5f6-4a7b RENDERED FROM SIGNED BYTES
Credit decision: application
20 June 2026, 14:30:00 UTC · case CRM-88213
Who is accountable
AnyCompany Lendingfrom the artifact · who is accountable
What decided it
agent:credit-scoring-v2, running gpt-4-turbo. No human in the loop. what if a human approves? →from the artifact · what decided it · human oversight: none
Which policy governed it
Version 6b09e103…, pinned at the decision, not reconstructed afterfrom the artifact · which policy applied
What the model saw
Input 9c195c99…, committed before the agent ran. The seal is refused if it differs.from the artifact · what the model was given, committed before the agent ran
8 of 33 fields shown above, four of them in plain words.
What this does not establish
Correctness

A verified record of a bad decision is still a verified record of a bad decision.

Completeness

A signature covers what is present, not what was never written.

Custody

Only the declared retention class is signed; confirming the lock needs the storage account.

Human approval

This one was solely automated, and the signature is ours, not a human’s.

Do not take our word for any of it.

Everything above rests on one thing: the bytes have not changed since they were signed. The verifier checks that in your browser, on a site whose framing we do not control. No account, no upload, nothing leaves the page.

This is the page you hand over with the record. Whoever you hand it to opens a link and gets an answer, without installing anything and without a call to you.

01
Load the sample.One button. It ships inside the page.
02
Change one character.Edit it right there. Any character will do.
03
Run the checks.This is the part worth doing. It fails.
Try to break a record ↗

Open source at github.com/plainreal/verify. Every release is signed, and the signature names the exact page you were served, so the checker itself can be checked. How that works →

Non-determinism

You cannot re-run an LLM
to find out what it did.

The rest of your stack is reproducible by design: same inputs, same code, same result. An AI model is not. One exception is worth naming: where an agent writes code once and that code is then frozen, running it again gives the same answer. What cannot be re-run is the decision that produced the code. Same prompt, same settings, and the answer can come back different, because the provider updated the model behind the same version string or the sampling varied.

So you cannot re-derive what the agent decided six months ago. Whatever you did not capture as it happened, to the exact input the model saw, is gone. And what you did capture is only as good as your ability to show it has not changed. The discovery order arrives long after the decision, which is why capture has to be live.

The actual problem

Nobody in the chain
is neutral.

The record of a consequential AI decision is scattered across the systems that produced it. Your company deployed the agent. A vendor supplied it. A provider served the model. Some chains are longer, some shorter.

Inside one decision: twelve components, and not one of them neutral

One decision is pinned in every party it reached: d-4f21, the one an examiner asked about. Where a component has changed since, its row shows what it was running then. Six parties hold a copy. None of them is a witness.

solid outline: inside your company dashed: a party you do not control

  • Your companykeeps the logs, the prompts and the outputs.It is the party being examined.
  • The agent vendorskeep the agents’ own traces.Their product is what the dispute is about.
  • Public model providerskeep the inference records.None can be both the infrastructure and its auditor.
  • A model in your VPCkeeps nothing you do not already hold.It is your own infrastructure, so it adds no witness.

Eighteen months on, that combination no longer exists. The two public models are the sharp case: v2026-05 and v2026-03 never move while the model behind the string can be replaced.

Outside it
PlainReal™ is the independent witness.

It holds the sealed record and gains nothing from the decision going one way or the other. The check runs without us and without you, open source and in your own browser.

The in-house case is the worst one, not the best. Build the whole stack yourself and you hold the evidence about your own conduct. Every record you produce is a record you could have written.

Better logging, immutable storage and governance tooling are all worth doing. None of them closes this.

The gap is not what you think

What is missing is not completeness.
It is independence.

Why leaving costs you nothing

The format is public and the verifier is public. Stop paying us and every record you already hold still verifies, with no cooperation from us. What you pay for is the sealing itself, because tomorrow's decisions cannot be sealed after the fact. That is how you know the independence claim is real rather than marketing.

What a sealed record is made of

Evidence accretes in layers.

Five things happen when a record is sealed, and the finished record carries all five. Turn a layer to see what it holds. Every value shown is read out of the sample record, not typed in.

Hover or click a layer to turn it towards you
Signed, and by whom
c56e31877d64f19378c0f3f8973d91b2
cf09ecb1246887cd71ec25cf73a4b26a
key 69a0bbac56da5fae1b82f570…
covers 32 of 33 fields
Written once, cannot be edited
records/a1b2c3d4-e5f6-4a7b.json
Object Lock COMPLIANCE
retention_class STANDARD_7Y
period derived, not declared
Checked that it really is locked
GetObjectRetention
Mode COMPLIANCE
RetainUntilDate 2033-06-20
scope this key + version
Timestamped by someone else
records/a1b2c3d4-e5f6-4a7b.tsr
created_at 2026-06-20T14:30:00Z
authority external TSA
requested only after the lock
Findable later
a1b2c3d4-e5f6-4a7b-8c9d-0e1f2a3b4c5d
evidence_tier TIER-A
availability_policy BLOCK_ON_…
role convenience, not the record

The order is the guarantee: the time anchor is only requested once the lock has been read back. And no two of these layers are held by the same party. PlainReal signs, your storage keeps it under a lock its own operator cannot lift, and an outside authority timestamps. That is what makes it an architecture rather than a promise.

How each layer is built, and the OWASP agentic mapping →
Integration

Two ways to deploy.

Both produce the same record, verified by the same CLI. Start with auto-instrument for immediate coverage, then promote your regulated paths to the decorator.

Compliance coverage

One record, whoever is asking.

Whoever asks, the question is much the same: what did the agent decide, on what, and can you show it has not changed since. One record answers that once.

Tap one to see what it actually says.

All frameworks, in detail →
About the founder
Swapan Shridhar

Swapan Shridhar.

19 years building infrastructure that proves data integrity at the OS level, the storage stack, and federal compliance: HP, VMware, Cloudera, FedRAMP GovCloud, FIPS 140-3. PlainReal asks the same question about AI decisions.

Full background ↗
Honest scoping

Who this is not for.

An evidence company that overstates the need is the last one you should trust with evidence. If any of these fit you, you do not need us yet.

Why now, if no law forces it

No law or regulation currently compels cryptographic decision evidence, and we will not pretend otherwise. What we build for is the challenge itself: the discovery request, the adverse-action suit, the examiner asking a question you cannot answer. That exists today, regardless of what any law requires.

Common questions

Before you ask.

No. A PlainReal record is written to your S3 bucket in your AWS account. The signing operation receives the hash of your data, not the data itself. PlainReal has no write access to your bucket after provisioning. The deployment_mode field records which arrangement produced a given record, so a reader can see it rather than infer it.
See the full FAQ →
Get started

Become a design partner.

For Compliance, Legal & Risk Teams
What would you hand over if someone asked you to prove it?

Live today and early. We are taking on two design partners: you define what your auditor would accept, and we build to it.

Book a 30-minute call Not ready for a call? Send your details See what a full response contains a template, with a real record worked through it. No email, no form. →

Engineers, look before we talk. a real record, deployment modes, or verify one yourself. SDK integration takes about 30 minutes. contact@plainreal.com

Request access.

90-day pilot · 50% upfront · scope set together. One conversation to see if it fits.

Or book directly: 30-min call ↗

Received. We will be in touch within one business day.