How it works
From the audit log to evidence anyone can check.
Your agent platform already writes an audit log. Firmantia reads it, seals every action into a signed, hash-chained, time-stamped record, and hands you a pack an auditor checks on their own machine.
In development. Early access open for regulated teams in the UAE and Qatar.
step 1
Ingest
- What goes in
- The audit export your agent platform already writes: Microsoft Agent 365 and Purview first, others to follow.
- What comes out
- One record per agent action, and a policy decision record for each action, allowed or refused, against the rules you set.
- What is true afterwards
- Each record's hash is the SHA-256 of its exact bytes, and each record is stored append only, linked to the one before. Ingesting the same export twice stores nothing new.
Example
$ firmantia ingest --source agent365 --file audit-export.csvingest agent365: 212 records stored, 0 already stored, 2 events skipped
What a record contains
- Agent identifier
- Action type
- Tool or model called
- Input hash and output hash
- Inference region, when the platform reports it
- Timestamp
- Policy decision (allowed or refused)
- The platform's reference id
What it never contains
- Prompt text
- Response text
- Customer data
- Personal data
Hashes only.
Example
{
"agentId": "loan-intake",
"runId": "run-7f2c",
"kind": "tool_call",
"name": "crm.updateApplication",
"inputHash": "9b1e...c04a",
"outputHash": "52d7...e911",
"inferenceRegion": null,
"at": "2030-01-15T10:41:52Z",
"policyDecision": "c3a0...7d12",
"source": "agent365",
"rawRef": "audit-record-id"
}step 2
Seal
- What goes in
- The records stored since the last chain entry.
- What comes out
- A chain entry: one per batch, closed every so many records or every few minutes.
- What is true afterwards
- Editing or removing any record changes the entry's hash and breaks every link after it. The signature shows which registered key sealed the entry; the time-stamp token shows the entry existed by that time.
What a chain entry contains
- The list of record hashes
- The previous entry's hash
- A sequence number
- The signer registry it was signed under
- The signer's key id, and the signature
- The time-stamp token
The chain
- Stamped 10:40:03Batch 14212 records, signed by SHA256:q3Fv...e8
- Stamped 10:20:01Batch 13198 records, signed by SHA256:q3Fv...e8
- Stamped 10:00:02Batch 12240 records, signed by SHA256:q3Fv...e8
Verified offline: every record, link, signature and time stamp.
Keys
- P-256 ECDSA.
- Held by the customer.
- Rotation by validity window: old entries stay verifiable under the key that signed them.
Time-stamping
- RFC 3161.
- The authority signs the hash and the time.
- The token travels in the pack and is checked offline against the authority's certificate.
Example
$ firmantia sealseal: entry 2030-01-15 (close 14), 424 records, signed by SHA256:q3Fv...e8 tsa: time stamped at 2030-01-15T10:40:03Z
step 3
Export
- What goes in
- The stored records and the chain.
- What comes out
- An evidence pack, one file: every record byte for byte, the chain with its signatures and time-stamp tokens, and every version of the key registry the chain cites.
- What is true afterwards
- The pack holds everything needed to check the record. It does not hold trust: the verifier brings its own trusted authorities, so whoever produced the pack cannot choose what the auditor trusts.
Example
$ firmantia export --out pack.jsonexport: 1,284 records and 14 chain entries to pack.json
step 4
Verify
- What goes in
- The evidence pack, and the verifier: one HTML file, opened from disk.
- What comes out
- VERIFIED, or FAILED with the exact reason and the exact record.
- What is true afterwards
- Nothing in the record has changed since it was sealed and time-stamped, every entry was signed by a key registered for it, and every human approval was signed by the approver's own key. No internet, no account, no contact with us.
Example
$ firmantia verify pack.jsonVERIFIEDPASS formatPASS records-intact: 1,284 records hash to their hashes, in one linked sequencePASS records-sealed: every record is in exactly one chain entryPASS chain-links: 14 entries recompute and link without a gapPASS anchors: 14 entries time stamped by a trusted authorityPASS entry-signatures: 14 signed by a registered key inside its windowPASS approvals: 46 approvals signed by the approver's own key
The seven checks, one line each, are on Verify.
Status
What is not built yet
- A hosted service.
- Hardware key storage (the demonstration uses a key file).
- An in-country time-stamp authority (the demonstration uses an independent public one).
- Connectors beyond Microsoft Agent 365.
These are configuration and integration, not architecture. The commands above are shown with example output; firmantia is in development.
See it on your own audit log first.
Early access teams see the first demonstration before anyone else.