Logs are kept by the platform.
Your agent platform writes its own audit log. It can also change it. A regulator has only the platform's word.
AI agents now approve claims, answer customers, and move records inside banks and ministries. When a regulator, an auditor, or your own board asks what an agent did, the answer shouldn't depend on trusting whoever kept the log. Firmantia turns your agent platform's audit trail into a signed, hash-chained, time-stamped record that anyone can check offline.
In development. Early access open for regulated teams in the UAE and Qatar.
Every action from the platform's audit log, sealed in batches and time-stamped.
| Time | Agent and call | Policy decision | Approval |
|---|---|---|---|
| 10:41:52 | Loan intake assistant tool crm.updateApplication | Allowed | Signed off by Layla |
| 10:41:07 | KYC document checker model gpt-4.1 | Allowed | Not required |
| 10:39:44 | Treasury report drafter tool mail.send | Refused | Not required |
| 10:38:30 | Loan intake assistant tool payments.schedule | Allowed | Escalated by Omar |
Example data. Names made up.
Your agent platform writes its own audit log. It can also change it. A regulator has only the platform's word.
Platform audit trails are kept for months. Examinations and disputes come years later.
An auditor can read a log. They can't prove it wasn't edited after the fact.
step 1
Reads your agent platform's audit export (Microsoft Agent 365 and Purview first; others to follow). Every agent action becomes a record: which agent, what it did, a hash of the input, a hash of the output, where it ran when the platform reports it, when. Content is never stored, only hashes.
Morestep 2
Records are batched into chain entries. Each entry hashes its records, links to the previous entry, is signed with a key held by you, and is time-stamped by an independent time-stamp authority.
Morestep 3
An evidence pack: the records, the chain, the public keys, the time-stamp tokens. One file you can hand to anyone.
Morestep 4
One HTML file, opened from disk, no internet, no account. Seven checks. VERIFIED, or FAILED with the exact reason and the exact record.
MoreAnswering their regulator's questions about AI oversight and audit trails.
Deploying agents under national AI and cybersecurity policy.
Who need evidence they can verify without taking a vendor's word.
Who need a governed-agent story their regulated clients will accept.
Built to keep data in country. Records and keys are meant to live in the UAE or Qatar. Content never leaves; the only thing sent out is one hash per batch, to the time-stamp authority.
Time-stamping by an in-country authority when one is designated; an independent public authority until then.
Evidence set against the questions UAE and Qatar regulators ask about AI agents: what the record proves.
Arabic and English reports. In development
If one byte of the record changes, verification fails and names the record. Not the bank, not the platform, not Firmantia can edit history quietly.
What the record proves sets out the UAE and Qatar instruments, and the evidence the record produces for each. Firmantia produces evidence; whether it satisfies an obligation is for the organization and its regulator to decide.
That each action the platform's audit log reported is recorded as it was reported, with the policy decision and the human approval that go with it, and that nothing in the record has changed since its batch was sealed and time-stamped. It proves what the platform reported and when. It cannot prove the platform reported everything, and it says so.
No. A record keeps a SHA-256 hash of each input and output, never the content itself. What leaves is one hash per sealed batch, sent to the time-stamp authority, and a hash reveals nothing about the record.
No. Firmantia reads the platform's audit log after the fact; it never sits in the agent's path.
Not yet. It is in development. The first milestone is a working demonstration: an Agent 365 audit export in, an evidence pack out, verified offline. Early access teams see it first.