How it works

From the audit log to evidence anyone can check.

Your agent platform already writes an audit log. Firmantia reads it, seals every action into a signed, hash-chained, time-stamped record, and hands you a pack an auditor checks on their own machine.

In development. Early access open for regulated teams in the UAE and Qatar.

step 1

Ingest

What goes in
The audit export your agent platform already writes: Microsoft Agent 365 and Purview first, others to follow.
What comes out
One record per agent action, and a policy decision record for each action, allowed or refused, against the rules you set.
What is true afterwards
Each record's hash is the SHA-256 of its exact bytes, and each record is stored append only, linked to the one before. Ingesting the same export twice stores nothing new.
Example
$ firmantia ingest --source agent365 --file audit-export.csvingest agent365: 212 records stored, 0 already stored, 2 events skipped

What a record contains

  • Agent identifier
  • Action type
  • Tool or model called
  • Input hash and output hash
  • Inference region, when the platform reports it
  • Timestamp
  • Policy decision (allowed or refused)
  • The platform's reference id

What it never contains

  • Prompt text
  • Response text
  • Customer data
  • Personal data

Hashes only.

Example
{
  "agentId": "loan-intake",
  "runId": "run-7f2c",
  "kind": "tool_call",
  "name": "crm.updateApplication",
  "inputHash": "9b1e...c04a",
  "outputHash": "52d7...e911",
  "inferenceRegion": null,
  "at": "2030-01-15T10:41:52Z",
  "policyDecision": "c3a0...7d12",
  "source": "agent365",
  "rawRef": "audit-record-id"
}
step 2

Seal

What goes in
The records stored since the last chain entry.
What comes out
A chain entry: one per batch, closed every so many records or every few minutes.
What is true afterwards
Editing or removing any record changes the entry's hash and breaks every link after it. The signature shows which registered key sealed the entry; the time-stamp token shows the entry existed by that time.

What a chain entry contains

  • The list of record hashes
  • The previous entry's hash
  • A sequence number
  • The signer registry it was signed under
  • The signer's key id, and the signature
  • The time-stamp token
The chain
  • Batch 14
    212 records, signed by SHA256:q3Fv...e8
    Stamped 10:40:03
  • Batch 13
    198 records, signed by SHA256:q3Fv...e8
    Stamped 10:20:01
  • Batch 12
    240 records, signed by SHA256:q3Fv...e8
    Stamped 10:00:02
Verified offline: every record, link, signature and time stamp.

Keys

  • P-256 ECDSA.
  • Held by the customer.
  • Rotation by validity window: old entries stay verifiable under the key that signed them.

Time-stamping

  • RFC 3161.
  • The authority signs the hash and the time.
  • The token travels in the pack and is checked offline against the authority's certificate.
Example
$ firmantia sealseal: entry 2030-01-15 (close 14), 424 records, signed by SHA256:q3Fv...e8  tsa: time stamped at 2030-01-15T10:40:03Z
step 3

Export

What goes in
The stored records and the chain.
What comes out
An evidence pack, one file: every record byte for byte, the chain with its signatures and time-stamp tokens, and every version of the key registry the chain cites.
What is true afterwards
The pack holds everything needed to check the record. It does not hold trust: the verifier brings its own trusted authorities, so whoever produced the pack cannot choose what the auditor trusts.
Example
$ firmantia export --out pack.jsonexport: 1,284 records and 14 chain entries to pack.json
step 4

Verify

What goes in
The evidence pack, and the verifier: one HTML file, opened from disk.
What comes out
VERIFIED, or FAILED with the exact reason and the exact record.
What is true afterwards
Nothing in the record has changed since it was sealed and time-stamped, every entry was signed by a key registered for it, and every human approval was signed by the approver's own key. No internet, no account, no contact with us.
Example
$ firmantia verify pack.jsonVERIFIEDPASS  formatPASS  records-intact: 1,284 records hash to their hashes, in one linked sequencePASS  records-sealed: every record is in exactly one chain entryPASS  chain-links: 14 entries recompute and link without a gapPASS  anchors: 14 entries time stamped by a trusted authorityPASS  entry-signatures: 14 signed by a registered key inside its windowPASS  approvals: 46 approvals signed by the approver's own key

The seven checks, one line each, are on Verify.

Status

What is not built yet

  • A hosted service.
  • Hardware key storage (the demonstration uses a key file).
  • An in-country time-stamp authority (the demonstration uses an independent public one).
  • Connectors beyond Microsoft Agent 365.

These are configuration and integration, not architecture. The commands above are shown with example output; firmantia is in development.

See it on your own audit log first.

Early access teams see the first demonstration before anyone else.