# PlainReal · Evidence for every AI decision that matters

Source: https://plainreal.com/

● For the moment someone asks you to prove what your AI decided: an examiner, a plaintiff, your own board and more →

## Your AI is already making decisions. Prove every one of them.

A record is one AI decision, sealed the moment it was made and tamper-evident ever since: the policy that governed it, what the model was given, what it decided. Whoever is asking can check it without you and without us.

Book a 30-minute call
Check a record in your browser ↗

A working system, live today. Not a mockup.

The gap

### Someone challenges the decision. You have only your word.

AI agents now approve loans, flag fraud and deny prior authorizations. Regulators, auditors and opposing counsel are all entitled to ask why.

OCC examination OCC
AML alert triage AML
Prior-authorisation denial Prior-auth
Litigation discovery Litigation

OCC examination scenario

Your AI agent approved 9,300 loan applications last quarter. Now prove how each one was decided. You have logs and audit trails. They sit inside your own systems, vouched for by you. Not enough. What you cannot prove, you concede.

Five demands. Here is what each one costs you.

01

#### Which version of the policy was in force?

✗ Your stack today Reconstructed afterwards, and hope it matches

✓ With PlainReal The policy version itself, sealed at the decision policy_version_hash

02

#### Prove the model got exactly that, and nothing else

✗ Your stack today Logged, but not provably unchanged

✓ With PlainReal Exactly what the model was given, locked before it ran input_hash

03

#### Prove nobody edited this afterwards

✗ Your stack today Controls you administer, and can change

✓ With PlainReal Written once, signed, timestamped

04

#### Prove it without asking me to trust you

✗ Your stack today You vouch for your own logs

✓ With PlainReal The examiner verifies offline, without you

05

#### And have it by Friday

✗ Your stack today Weeks legal, engineering, whoever owns the logs, and outside counsel. Each reconstructing separately, each billing

✓ With PlainReal None nothing to reconstruct; it was sealed at the decision

And the tools you already run

None of that is fixed by them. Cloud audit logs, AI monitoring, policy engines and your SIEM govern the runtime. They record what ran. None of them commits what the model was given, before it ran.

A communications archive is the strongest version of this objection. It holds the record outside your systems, which genuinely answers custody. It still records what passed through it, and checking it means asking whoever holds it.

Which is the question worth asking of anything that calls itself sealed: what does someone need in order to check it? Here, the file and a published key. Nothing else, and nobody to ask.

Why CloudTrail and OpenTelemetry fall short →

The artifact

### This is what you hand over.

One record for each decision that matters. The one below is real and this summary is generated from it, so it cannot say anything the record does not. Change the outcome and watch the proof fail.

Decision record · a1b2c3d4-e5f6-4a7b
RENDERED FROM SIGNED BYTES

Credit decision: application approved make it denied

20 June 2026, 14:30:00 UTC · case CRM-88213

Who is accountable
AnyCompany Lending from the artifact · who is accountable

What decided it
agent:credit-scoring-v2 , running gpt-4-turbo. No human in the loop. what if a human approves? → from the artifact · what decided it · human oversight : none

Which policy governed it
Version 6b09e103… , pinned at the decision, not reconstructed after from the artifact · which policy applied

What the model saw
Input 9c195c99… , committed before the agent ran. The seal is refused if it differs. from the artifact · what the model was given , committed before the agent ran

Give this to your examiner
This decision as a document, in plain language, with the steps to check it and what it does not establish. Two pages, no account needed.
Download the record, PDF →

What it is generated from
All 33 fields as signed JSON. The document above is rendered from this file, so it cannot say anything the record does not.
Open the record →

8 of 33 fields shown above, four of them in plain words.

The proof beside it.

What was sealed
a4cbb405487c41856cbf56a04b0f6fcb49ef1c05e404937030076838a45f103b

What it comes to now
a4cbb405487c41856cbf56a04b0f6fcb49ef1c05e404937030076838a45f103b

All 64 characters match, so these are the bytes that were signed.
61 of 64 characters differ. 132 of 256 bits. These are not those bytes.

The seal covers everything except the signature, which cannot sign itself. See the exact bytes →

✓ read exactly as delivered ·
✓ seal recomputed ·
✓ signature valid ·
– who held it since is not checkable from this file alone

What this does not establish

Correctness A verified record of a bad decision is still a verified record of a bad decision.

Completeness A signature covers what is present, not what was never written.

Custody Only the declared retention class is signed; confirming the lock needs the storage account.

Human approval This one was solely automated, and the signature is ours, not a human’s.

#### Do not take our word for any of it.

Everything above rests on one thing: the bytes have not changed since they were signed. The verifier checks that in your browser, on a site whose framing we do not control. No account, no upload, nothing leaves the page.

This is the page you hand over with the record. Whoever you hand it to opens a link and gets an answer, without installing anything and without a call to you.

01
Load the sample. One button. It ships inside the page.

02
Change one character. Edit it right there. Any character will do.

03
Run the checks. This is the part worth doing. It fails.

Try to break a record ↗
Open source at github.com/plainreal/verify . Every release is signed, and the signature names the exact page you were served, so the checker itself can be checked. How that works →

Non-determinism

### You cannot re-run an LLM to find out what it did.

The rest of your stack is reproducible by design: same inputs, same code, same result. An AI model is not . One exception is worth naming: where an agent writes code once and that code is then frozen, running it again gives the same answer. What cannot be re-run is the decision that produced the code. Same prompt, same settings, and the answer can come back different, because the provider updated the model behind the same version string or the sampling varied.

So you cannot re-derive what the agent decided six months ago. Whatever you did not capture as it happened, to the exact input the model saw, is gone. And what you did capture is only as good as your ability to show it has not changed. The discovery order arrives long after the decision, which is why capture has to be live.

The actual problem

### Nobody in the chain is neutral.

The record of a consequential AI decision is scattered across the systems that produced it. Your company deployed the agent. A vendor supplied it. A provider served the model. Some chains are longer, some shorter.

Inside one decision: twelve components, and not one of them neutral

One decision is pinned in every party it reached: d-4f21 , the one an
examiner asked about. Where a component has changed since, its row shows what it was
running then. Six parties hold a copy. None of them is a witness.

solid outline: inside your company
dashed: a party you do not control

- Your company keeps the logs, the prompts and the outputs. It is the party being examined.

- The agent vendors keep the agents’ own traces. Their product is what the dispute is about.

- Public model providers keep the inference records. None can be both the infrastructure and its auditor.

- A model in your VPC keeps nothing you do not already hold. It is your own infrastructure, so it adds no witness.

Eighteen months on, that combination no longer exists. The two public models
are the sharp case: v2026-05 and v2026-03 never move while the model
behind the string can be replaced.

Outside it

PlainReal™ is the independent witness.

It holds the sealed record and gains nothing from the decision going one way or the other . The check runs without us and without you, open source and in your own browser.

The in-house case is the worst one, not the best. Build the whole stack yourself and you hold the evidence about your own conduct. Every record you produce is a record you could have written.

Better logging, immutable storage and governance tooling are all worth doing. None of them closes this.

The gap is not what you think

What is missing is not completeness. It is independence.

Why leaving costs you nothing

The format is public and the verifier is public. Stop paying us and every record you already hold still verifies, with no cooperation from us. What you pay for is the sealing itself, because tomorrow's decisions cannot be sealed after the fact. That is how you know the independence claim is real rather than marketing.

What a sealed record is made of

### Evidence accretes in layers.

Five things happen when a record is sealed, and the finished record carries all five. Turn a layer to see what it holds. Every value shown is read out of the sample record, not typed in.

Hover or click a layer to turn it towards you

Signed, and by whom

c56e31877d64f19378c0f3f8973d91b2 cf09ecb1246887cd71ec25cf73a4b26a key 69a0bbac56da5fae1b82f570… covers 32 of 33 fields

Written once, cannot be edited

records/a1b2c3d4-e5f6-4a7b.json Object Lock COMPLIANCE retention_class STANDARD_7Y period derived, not declared

Checked that it really is locked

GetObjectRetention Mode COMPLIANCE RetainUntilDate 2033-06-20 scope this key + version

Timestamped by someone else

records/a1b2c3d4-e5f6-4a7b.tsr created_at 2026-06-20T14:30:00Z authority external TSA requested only after the lock

Findable later

a1b2c3d4-e5f6-4a7b-8c9d-0e1f2a3b4c5d evidence_tier TIER-A availability_policy BLOCK_ON_… role convenience, not the record

01 Sign Signed before it is stored, so nothing signs a value that changed afterwards.
02 Commit How long it is kept comes from the record itself, so a mislabelled one cannot exist.
03 Confirm This record's own lock is read back, not the storage account's general setting.
04 Timestamp Proves when. Taken before the lock was confirmed, it would attest to nothing.
05 Index An index, not the record. If it fails the record is still evidence.

The order is the guarantee: the time anchor is only requested once the lock has been read back. And no two of these layers are held by the same party . PlainReal signs, your storage keeps it under a lock its own operator cannot lift, and an outside authority timestamps. That is what makes it an architecture rather than a promise.

How each layer is built, and the OWASP agentic mapping →

Integration

### Two ways to deploy.

Both produce the same record, verified by the same CLI. Start with auto-instrument for immediate coverage, then promote your regulated paths to the decorator.

@plainreal.consequential
Decorator
Wrap a regulated function. The input is sealed before it runs .
For OCC, NYDFS, and litigation evidence.

how the decorator captures →

plainreal run
Auto-instrument
Zero code changes. Captures every LLM call at the client
boundary. For EU AI Act Article 12 and GDPR record-keeping.

how auto-instrument captures →

Compliance coverage

### One record, whoever is asking.

Whoever asks, the question is much the same: what did the agent decide, on what, and can you show it has not changed since. One record answers that once.

EU AI Act
FinCEN
GDPR
OCC

Tap one to see what it actually says.

All frameworks, in detail →

About the founder

### Swapan Shridhar.

19 years building infrastructure that proves data integrity at the OS level, the storage stack, and federal compliance: HP, VMware, Cloudera, FedRAMP GovCloud, FIPS 140-3. PlainReal asks the same question about AI decisions.

Full background ↗

Honest scoping

### Who this is not for.

An evidence company that overstates the need is the last one you should trust with evidence. If any of these fit you, you do not need us yet.

Your AI does not make consequential decisions about people or money.
Nobody subpoenas a copy drafter. Log it however you like.
This is me
Then you do not need us yet. Nothing further to read.

You want to prevent bad decisions, not prove what happened.
That is guardrails and policy enforcement. We record what happened; we do not stop the agent.
This is me
Then you do not need us yet. Nothing further to read.

Nobody with authority will ever ask you to prove it.
No regulator, auditor, plaintiff, board or contracted customer. If that is genuinely true, do not buy this.
This is me
Then you do not need us yet. Nothing further to read.

Why now, if no law forces it

No law or regulation currently compels cryptographic decision evidence, and we will not pretend otherwise. What we build for is the challenge itself: the discovery request, the adverse-action suit, the examiner asking a question you cannot answer. That exists today, regardless of what any law requires.

Common questions

### Before you ask.

Is our data leaving our environment? +
No. A PlainReal record is written to your S3 bucket in your AWS account. The signing operation receives the hash of your data, not the data itself. PlainReal has no write access to your bucket after provisioning. The deployment_mode field records which arrangement produced a given record, so a reader can see it rather than infer it.

See the full FAQ →

Get started

### Become a design partner.

For Compliance, Legal & Risk Teams
What would you hand over if someone asked you to prove it?

Live today and early. We are taking on two design partners: you define what your auditor would accept, and we build to it.

Book a 30-minute call

Not ready for a call? Send your details
See what a full response contains a template, with a real record worked through it. No email, no form. →

Engineers, look before we talk. a real record , deployment modes , or verify one yourself . SDK integration takes about 30 minutes. contact@plainreal.com

✕

Request access.

90-day pilot · 50% upfront · scope set together. One conversation to see if it fits.

Request a Conversation
Or book directly: 30-min call ↗

That did not send. Send it by email instead , with your details already filled in. Or book a call ↗ .

Received. We will be in touch within one business day.
