AIdecisionsshouldnotvanishintothinair.
The decision doesn’t go out until it’s policy-checked and sealed.
In the path · not a log written afterwards
The film explains it. The seat lets you approve a decision, lose the evidence, and then try to break the record yourself.
We’re the authorisation layer for AI decisions.
Regulated companies can’t ship AI into decisions that matter, because they can’t prove afterwards what happened.
We sit in the path: the decision doesn’t go out until it’s policy-checked and sealed.
Proposed
A model produces a decision. Nothing has been delivered yet.
Policy-checkedGate
Evaluated against the controls in force at this moment.
Sealed
Output, policy, model state and approvals bound into one record.
Released
The decision goes out, already provable.
Fails the checkThe decision is held rather than delivered, and the refusal is itself sealed as a record, with the control that stopped it named.
Stripe for consequential AI decisions.
Every decision writes two records.
One is a log line with a retention window. One is sealed evidence. Below, eighteen months happen to both.
- Day 0 · IssueT+0
A decision ships.
An AI-assisted decision goes out the door. From this moment two accounts of it exist: one written to application logs, one sealed as evidence at the instant of issue.
Unsealedwritten to logs · retention 30 daysSealedsealed on issue · digest committed - Day 30 · Rotation+30 d
The logs begin to forget.
Retention windows close and the raw output rotates away. Nothing has gone wrong: this is infrastructure working as designed. The unsealed account is already thinning.
Unsealedraw output rotated outSealeddigest re-verifies · unchanged - Day 120 · Drift+120 d
The system moves on.
The model that made the decision is retired. Prompts are rewritten, tools are swapped. The exact configuration that produced the output no longer exists anywhere in production.
Unsealedmodel retired · prompts revisedSealedmodel state pinned inside the record - Day 365 · Turnover+1 y
The people move on.
The approving officer has left the company. The rationale survives only as memory in other people's heads. And memory is not a record.
Unsealedapprover departed · rationale is hearsaySealedapprovals still named and attributable - Day 540 · Inquiry+18 m
Produce the record.
A regulator asks precisely what was decided, under which policy revision, on what evidence, with whose approval. The demand is identical for both timelines. What differs is what remains.
Unsealedpolicy revised ×3 since decisionSealedpolicy revision 18 · bound at issue - Day 547 · Response+18 m
Reconstruction versus retrieval.
One team greps cold archives and interviews former staff toward a best-effort narrative. The other exports the sealed record. One process takes weeks; the other, seconds.
Unsealedfragments recovered · 2 of 14 linesSealedevidence pack exported · 4 s - Verdict—
One is a story. One is evidence.
An account that cannot be verified is an account, not evidence. The sealed record is admissible on its own terms: tamper-evident, complete, and verifiable without Sigilith present.
Unsealedno admissible recordSealedadmissible · verifiable · sealed
Everything above is what the void looks like. This is what comes out of it.
What a sealed decision
looks like on paper.
An evidence-grade record is not a log line. It is the exact output as delivered, bound to the policy that authorised it, the approvals that cleared it, and the context that produced it, all sealed at the moment of the decision and verifiable long after.
- Subject
- Adverse action · application #48812
- Digest
- computing…
- Output
- verbatim · as delivered
- Policy
- CRD-4.2 · revision 18
- Model
- pinned · frozen at decision time
- Approvers
- 2 of 2 · named officers
- Context
- 6 retrieved · 2 tools invoked
- Sealed
- 2026-04-17T09:41:22Z
Built for regulated environments
Automated decisions in Banking
Not technical telemetry.Institutional evidence.
Standard audit logs are insufficient for regulatory and board-level review. Three grades of record exist; only one survives examination.
Standard telemetry
Audit logs & tracesEphemeral engineering logs built for debugging and access tracking. They rotate, they mutate, and they were never designed to be shown to a regulator.
LLM observability
Engineering tracesDetailed traces of how a prompt was processed. Invaluable to engineers, but they carry no evidentiary weight, bind to no policy, and can be rewritten.
Evidence infrastructure
Sigilith recordCryptographically sealed provenance binding the output to the policy and system state that produced it. Built to be examined by someone hostile.
Sigilith is built for teams where “show your work” is a legal requirement.
Built for high-trust operational environments.
Specialised systems for institutions that need control, defensibility, and operational clarity in high-stakes workflows.
Sigilith Platform
The authorisation layer for consequential AI decisions. Policy-checked in the path, sealed at issue, and verifiable afterwards for compliance, dispute response, and model risk review.
Explore the platformSigilith Sentry
Advanced eKYC and fraud decisioning
Establish live presence in one capture with an active light challenge, weigh fraud signals jointly, and escalate ambiguity to named officers, with every verdict sealed as evidence.
Explore Sigilith SentryEvidence workflows for high-stakes AI
Regulated Communications
Prove what was said or decided, under what policy, and with whose approval.
Audits & Investigations
Reconstruct what happened with verifiable records and policy state.
Third-Party AI Governance
Hold vendors to the same evidentiary standard with verifiable records.
Get access
If AI outputs create risk in your organisation, you need evidence. Request a technical briefing on institutional provenance.