Witnessed audit trails for AI agents

Prove what your agent did.

Your own logs prove nothing — you wrote them. Tallwright witnesses every action your AI agents take and seals it into a record you cannot quietly change and an auditor can verify without trusting you.

payments-agent/eu-desk-04·sealing record 4,419·

Record 4,419, the latest sealed record on the stack
Record4,419
Digest

SHA-256 chained · co-signed out of your reach · verifiable offline

A log you control is not evidence.

An agent moves a payment, settles a claim, tells a customer something binding. The only account of what happened sits in a database your own engineers can write to. That is fine until someone asks you to prove it.

Then the question is not what your logs say. It is why anyone should believe them. Eleven months on, with a regulator or a customer’s lawyer across the table, an internal record is a statement, not evidence.

Introducing

Tallwright

The witness layer for agentic software. One line of middleware in; evidence out.

  1. Prompt
    customer asked to move 12,400 to a saved payee
    verbatim, redacted per your policy
  2. Retrieved
    account balance · payee history · fraud score
    every lookup the agent made
  3. Model
    gpt-5.2-financial · temperature 0.1
    exact model and version that decided
  4. Decision
    transfer approved, under daily limit
    with the rule that allowed it
  5. Action
    transfer.execute → core banking API
    the call, its parameters, the response
The record

Written as it happens. All of it.

Not a transcript stitched together after the fact. The prompt, the retrievals, the model and version that decided, the rule that allowed it, and the exact call that went out — captured in the moment the agent acted, sealed before anyone had a reason to want it different.

When a dispute arrives, this is the difference between reconstructing a story from six systems and handing over the page.

The proof

Change one character.

Two consecutive records. The second one carries the first one’s digest — that is what binds them. Edit the amount below and watch a real SHA-256, computed in your browser, refuse to line up.

12,400.00 → 12,490.00·digest recomputed·link cut

  1. Record 4,417
    Altered
  2. Agent
    payments-agent/eu-desk-04
  3. Payee
    DE89 3704 0044 0532 0130 00
  4. Amount
    EUR 12,400.00
  5. Digest
Link cut
  1. Record 4,418
    Chain broken
  2. Expects
  3. Found

The record still reads plausibly. The next record no longer accepts it — and the break is visible to anyone who checks.

How it works

Three steps, in this order.

A record is struck, a witness countersigns it, and anyone can check the arithmetic. Watch it happen on the right — it never stops.

01

Record

SDK call

Your agent calls Tallwright as it acts. What it was asked, what it retrieved, which model decided, what it did. Written at the moment of the action, not reconstructed from logs afterwards.

02

Witness

Countersign

The record is co-signed by an independent witness outside your infrastructure and bound to the record before it. From that point neither your team nor ours can change it without the break becoming visible.

03

Verify

Arithmetic

Hand any record to an auditor, a regulator or a customer’s lawyer. They check it against the chain themselves. Verification is arithmetic they can run, not a claim they have to take from you.

Who it’s for

Teams whose agents do things that get disputed.

Banks and insurers

Payments agent

Agents that move money, settle claims or speak to customers. When one is disputed eleven months later, you produce the record instead of an argument.

Neobrokers and fintechs

Ops agent

You shipped agents faster than you built an operations team. This is the evidence layer you would otherwise write yourself, badly, under audit pressure.

Voice-agent platforms

Voice agent

Your buyers are regulated; their compliance review is your longest sales cycle. Ship them a verifiable trail and the review stops being your problem.

Firms with AI assistants

Drafting agent

Legal and professional work where the file has to show who decided what, and when — including the parts a machine drafted.

One witness, every agent

Same record, different desk.

  1. Agent
    payments-agent/eu-desk-04
  2. Action
    transfer.execute
  3. Payee
    DE89 3704 0044 0532 0130 00
  4. Amount
    EUR 12,400.00
  5. At
    2026-08-20T09:41:07.284Z
Desk
Bank

The transfer your customer disputes eleven months later.

One plate is one record: struck as the agent acted, sealed before anyone wanted it different.

Adapters & backends

It meets your stack where it runs.

Sealing happens at whichever layer you trust least — framework, transport, or tool protocol — and lands in storage nobody can rewrite.

Core

Core SDK

Framework-agnostic core. One conformance contract that every adapter has to satisfy.

1 / 9Turn the dial

Planned adapters · OpenAI Agents SDK · Claude Agent SDK · OpenTelemetry GenAI export

The claim we make

Tamper-evident, not “tamper-proof”.

Anyone with root can delete a database. We are not going to tell you otherwise, and you should be wary of anyone who does.

The claim is narrower and more useful: nothing can be changed quietly. Every record is bound to the one before it and co-signed outside your reach, so an alteration does not vanish — it announces itself, to anyone who checks.

Record 4,419, the latest sealed record on the stack
Record4,419
Digest

payments-agent/eu-desk-04·sealing record 4,419·

Put it behind one agent.

Start with the action that would hurt most in a dispute. Thirty minutes to see whether the record we produce is the one your auditors would accept.