The record of what your AI agents did. Verifiable by anyone.

AI agents now approve claims, answer customers, and move records inside banks and ministries. When a regulator, an auditor, or your own board asks what an agent did, the answer shouldn't depend on trusting whoever kept the log. Firmantia turns your agent platform's audit trail into a signed, hash-chained, time-stamped record that anyone can check offline.

In development. Early access open for regulated teams in the UAE and Qatar.

firmantia.dev/board
Firmantia
Evidence record
Example data
Tuesday, 10:42

Every action from the platform's audit log, sealed in batches and time-stamped.

1,284
Actions
31
Refused
46
Approvals
14
Batches
Agent actions
TimeAgent and callPolicy decisionApproval
10:41:52
Loan intake assistant
tool crm.updateApplication
Allowed
10:41:07
KYC document checker
model gpt-4.1
Allowed
10:39:44
Treasury report drafter
tool mail.send
Refused
10:38:30
Loan intake assistant
tool payments.schedule
Allowed

Example data. Names made up.

The problem

Logs are kept by the platform.

Your agent platform writes its own audit log. It can also change it. A regulator has only the platform's word.

Retention is short.

Platform audit trails are kept for months. Examinations and disputes come years later.

Nobody can check it independently.

An auditor can read a log. They can't prove it wasn't edited after the fact.

What Firmantia does

step 1

Ingest

Reads your agent platform's audit export (Microsoft Agent 365 and Purview first; others to follow). Every agent action becomes a record: which agent, what it did, a hash of the input, a hash of the output, where it ran when the platform reports it, when. Content is never stored, only hashes.

More

step 2

Seal

Records are batched into chain entries. Each entry hashes its records, links to the previous entry, is signed with a key held by you, and is time-stamped by an independent time-stamp authority.

More

step 3

Export

An evidence pack: the records, the chain, the public keys, the time-stamp tokens. One file you can hand to anyone.

More

step 4

Verify

One HTML file, opened from disk, no internet, no account. Seven checks. VERIFIED, or FAILED with the exact reason and the exact record.

More

Who it's for

Banks and insurers

Answering their regulator's questions about AI oversight and audit trails.

Government entities and critical infrastructure

Deploying agents under national AI and cybersecurity policy.

Auditors and certification bodies

Who need evidence they can verify without taking a vendor's word.

Integrators and agent builders

Who need a governed-agent story their regulated clients will accept.

Built for the Gulf

Built to keep data in country. Records and keys are meant to live in the UAE or Qatar. Content never leaves; the only thing sent out is one hash per batch, to the time-stamp authority.

Time-stamping by an in-country authority when one is designated; an independent public authority until then.

Evidence set against the questions UAE and Qatar regulators ask about AI agents: what the record proves.

Arabic and English reports. In development

Proof, not trust.

If one byte of the record changes, verification fails and names the record. Not the bank, not the platform, not Firmantia can edit history quietly.

Questions

Which regulations does it relate to?

What the record proves sets out the UAE and Qatar instruments, and the evidence the record produces for each. Firmantia produces evidence; whether it satisfies an obligation is for the organization and its regulator to decide.

What does the record prove?

That each action the platform's audit log reported is recorded as it was reported, with the policy decision and the human approval that go with it, and that nothing in the record has changed since its batch was sealed and time-stamped. It proves what the platform reported and when. It cannot prove the platform reported everything, and it says so.

Does any of our content leave our boundary?

No. A record keeps a SHA-256 hash of each input and output, never the content itself. What leaves is one hash per sealed batch, sent to the time-stamp authority, and a hash reveals nothing about the record.

Does it slow the agents down?

No. Firmantia reads the platform's audit log after the fact; it never sits in the agent's path.

Is it available today?

Not yet. It is in development. The first milestone is a working demonstration: an Agent 365 audit export in, an evidence pack out, verified offline. Early access teams see it first.