The part a company cannot build for itself.
Your own audit logs are worthless to a regulator, auditor, or insurer, because you control them and could rewrite them. NOCTRYS makes the record independently verifiable and non-equivocable. This is what turns "trust us" into "verify it yourself," and it is the part a single company cannot build alone.
Why your own logs aren’t enough
It is exactly like accounting: you keep your own books, but you still need an independent auditor, because your word about yourself is not evidence. A self-hosted, self-anchored log can be quietly edited by whoever runs it. NOCTRYS breaks that by anchoring the audit on a neutral chain you do not control (AERE) and by having a quorum of independent witnesses cosign each checkpoint, so no party, not even NOCTRYS, can present two different histories to two different verifiers.
How verification works
What makes the proof unforgeable
Anchored on AERE
Every action is hash-chained and its root anchored on the independent AERE chain, a neutral ledger you don’t control.
Witness cosigning
A 2f+1 quorum of independent witnesses cosigns each checkpoint, so no party, not even us, can show two different histories.
Public verifier
A regulator or auditor verifies a NOCTRYS seal themselves, in their browser. Try it →
Collective defense
An attack blocked at one customer protects them all. Privacy-preserving, and stronger with every deployment.
Execution receipts
The record proves not just what was allowed, but what actually executed and returned.
Assurance levels
Every agent earns an objective L0 to L4 governance grade that auditors and buyers can compare.
Deeper guarantees, same audit chain
A quorum, not a single witness
A checkpoint counts only when a 2f+1 quorum of independent witnesses cosigns the same hash-linked header, with diversity rules spreading witnesses across organizations and jurisdictions. A witness that signs two conflicting histories yields a compact equivocation proof anyone can verify with its public key alone, and it is excluded for good.
Transparency for the keys themselves
An RFC 6962-style key-transparency log for enforcer and witness keys: inclusion and consistency proofs, terminal revocation, and a head checkpointed into the witness mesh. A substituted key or a rewritten key history is detectable by anyone.
Disclosure-evidence records
Signed, time-stamped, tamper-evident records that an agent disclosed its artificial nature and on whose behalf it acts, sealed into the same audit chain: the record you produce when asked to demonstrate disclosure under EU AI Act Article 50. How this maps →
Policy edits that provably only narrow
A policy change can carry a machine-checkable narrowing proof: one clause per policy dimension, with the evidence inline. Any third party re-checks it against the two manifests alone, using the verify-narrowing CLI, with no trust in us or in you required. Fail-closed by construction: a manifest field outside the decidable fragment refuses a proof, and coverage is conservative, so a widening edit is never certified as narrowing.
Be one of our first five design partners
Free pilot. A two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.
Request a pilot →