A record is tamper-evident proof of what your AI agent decided, sealed the moment it happened and checkable by anyone — without you, and without us. When a regulator or opposing counsel asks you to prove what happened, it's what you hand them.
Banks, insurers, and healthcare companies are deploying AI agents to approve loans, flag fraud, deny prior authorizations, and triage patients. When a regulator, an auditor, or opposing counsel asks why the agent did what it did, most companies cannot answer.
Your AI agent approved $4.2M in refunds last quarter. The OCC examiner wants three things: which policy governed each decision, whether the model got exactly what was authorized, and proof the record was not touched afterward. You have logs. They are mutable. Not enough.
Opposing counsel subpoenas your AI decision records. Your logs are not write-protected and carry no signature, so anything you hand over can be challenged on authenticity. And if your own cloud signed the evidence about decisions that ran on its infrastructure, they will challenge its independence too.
A challenger asks about one specific decision: the February 18, 2026 loan denial on application LN-2026-0218-3391. Here is what each demand costs you.
| The examiner asks for | Your stack today | With PlainReal™ |
|---|---|---|
| Which policy governed the decision | Reconstruct from deploy history, and hope it matches | Sealed into the artifact as policy_version_hash |
| That the model got exactly what was authorized | You have the input logged, but cannot prove it was not changed | Bound before execution as input_hash |
| That the record was not altered afterward | Rows can be updated. Logs are mutable | WORM-committed, signed, timestamped |
| Independent verification | You vouch for your own logs | The examiner verifies offline, without you |
| Time to produce it | Weeks of cross-system forensics | One record. Under 2 seconds |
Each was built for something other than legal-grade decision evidence, and each stops at the same place: the record stays with a party that has a stake in the outcome.
| Current tool | What it does | What it lacks | With PlainReal |
|---|---|---|---|
| CloudTrail / audit logs | Records API calls | The same provider cannot be both the infrastructure and its auditor | A record the challenger can check without trusting your cloud |
| AI monitoring platforms | Traces execution, monitors drift | Mutable. Not evidence | Sealed the moment the decision happens, by a party with no stake in the decision |
| OPA / policy engines | Evaluates rules at runtime | Enforces, but leaves no provable record | Evidence of what was authorized, that stands up without you |
| LLM observability tools | Logs LLM calls | Logs you could have written yourself | Signed outside your stack, and checkable without us |
| SIEM / log aggregators | Aggregates logs across systems | Collects, but nothing is sealed or independent | One artifact an examiner verifies offline, on their own |
Every other system in your stack can be replayed: same inputs, same code, same result. An AI model is not. Same prompt, same settings, and the answer can come back different, because the provider updated the model behind the same version string or the sampling varied. An agent, chaining several such calls with shifting context, is further still from reproducible.
So you cannot reconstruct what the agent decided six months ago. If it was not sealed as it happened, to the exact input the model saw, it is gone. And the discovery order always arrives long after the decision, which is why capture has to be live.
When an AI makes a consequential decision, the record of it is scattered across the systems that produced it. Your company deployed the AI agent. A vendor supplied it. A provider served the AI model. Some chains are longer. Some are shorter.
PlainReal is that independent witness. Outside the chain, with no stake in the decision itself.
PlainReal is that independent witness. Outside the chain, with no stake in the decision itself.
The in-house case is the worst one, not the best. Build the whole stack yourself and you hold the evidence about everyone's conduct, your own and your vendors'. Every record you produce is a record you could have written.
Better logging, immutable storage, governance tooling, vendor attestation: all worth doing, none of them close this. Each still leaves the record with an interested party.
What is missing is not completeness.
It is independence.
The format is public and the verifier is public. Stop paying us and every record you already hold still verifies, with no cooperation from PlainReal. What you pay for is the sealing itself, decision after decision, because tomorrow's decisions cannot be sealed after the fact. That is how you know the independence claim is real, not marketing.
One self-contained artifact per AI agent action. Signed, sealed, timestamped.
Click any field below to see what it proves. ↓
Each field exists for a forensic reason. Click to see it.
// Excerpt of demo_record.json. Real values, real signature. // The full 33 fields are on the Demo page. { "record_id": "a1b2c3d4-e5f6-4a7b-8c9d-0e1f2a3b4c5d", "record_version": "1.0.0", "evidence_tier": "TIER-A"signed · WORM · timestamped, "decision_kind": "MODEL_DECISION", "capture_layer": "BUSINESS_LAYER"decorator, "consequential": true, "principal_identity": "agent:credit-scoring-v2", "action_type": "credit_decision", "execution_result": "APPROVED", "input_hash": "9c195c99e72720b3.."bound pre-execution, "policy_version_hash": "6b09e1031a4529aa..", "causality_chain_hash": "1f7588b3d1f0c503.."rebound at seal, "provenance": { "upstream": []root record, "workflow_run_id": "c3d4e5f6-a7b8-4c9d.." }, "deployment_mode": "SAAS_MANAGED"who ran the signer, "governance_context": { "accountable_party": "org:acme-lending", "environment": "PROD", "oversight_mode": "SOLELY_AUTOMATED", "retention_class": "STANDARD_7Y"lock derives from this }, "lock_verification_latency_ms": 47, "signing_key_id": "69a0bbac56da5fae.."Ed25519 public key, "signing_attestation": "c56e31877d64f193.."the only unsigned field }
Verify independently: plainreal verify dp_9f3a2c1e
Both produce the same record, verified by the same CLI. Start with auto-instrument for immediate coverage, then promote your regulated paths to the decorator.
Wrap a regulated function. The input is sealed before it runs. For OCC, NYDFS, and litigation evidence.
Zero code changes. Captures every LLM call at the client boundary. For EU AI Act Article 12 and GDPR record-keeping.
One record maps to the controls each framework names, from OCC agentic-AI supervision and FinCEN AML effectiveness to NYDFS Part 500 and EU AI Act Article 12. The same record answers all of them, rather than a separate system per regulator.
All 10 agentic-AI risks map to specific record fields, so a security review checks named controls instead of reading a document. The controls live in code.
The independence above is not a claim, it is an architecture: four properties, each held by a different party so no single one can rewrite the record. PlainReal signs it. Your S3 bucket stores it in write-once mode. A neutral authority timestamps it. And any past artifact still verifies using only the published key, even if PlainReal is gone.
19 years building infrastructure that proves data integrity at the OS level, the storage stack, and federal compliance: HP, VMware, Cloudera, FedRAMP GovCloud, FIPS 140-3. PlainReal asks the same question about AI decisions.
Full background ↗An evidence company that overstates the need is the last one you should trust with evidence. If any of these fit you, you do not need us yet.
Nobody subpoenas a copy drafter. Log it however you like.
That is guardrails and policy enforcement. We record and prove, we do not stop the agent. Different job.
No regulator, auditor, plaintiff, board, or contracted customer. If that is genuinely true, do not buy this.
No law or regulation currently compels cryptographic decision evidence, and we will not pretend otherwise. What we build for is the challenge itself: the discovery request, the adverse-action suit, the examiner asking a question you cannot answer. That exists today, regardless of what any law requires.
deployment_mode field records which arrangement produced a given record, so a reader can see it rather than infer it.The system is live and working today. It seals an AI decision into an independently verifiable record, and if the record is altered, verification fails. It is early, being shaped into production with the first few regulated teams, and you help define what it must prove.
The call is a live walkthrough on your own decision types, not a slide deck. We are taking on two design partners. You define the artifact your auditor needs, we build to it, and the first two shape the format the rest of the market inherits.
90-day pilot, 50% upfront. $15-25K depending on integration depth and auditor requirements. Design-partner pricing applies to the first two.
contact@plainreal.com
The schema is open, the OWASP mapping is public, and the standalone verify CLI will be open source, so your auditor can run it themselves. Inspect the schema and verify a sample artifact before any conversation with us.
SDK integration: 30 minutes in a clean environment · Enterprise production: 1–4 hours
90-day pilot · 50% upfront · $15-25K by scope. One conversation to see if it fits.
Or book directly: 30-min call ↗