A record is assembled, not logged.
The decision is checked against policy and sealed before it goes out, then verifiable afterwards for compliance, dispute response, and model risk review.
Check · bind · seal · release · export
What a record is made of.
Six constituents exist the moment an output is produced, scattered across as many systems. Below, they are gathered, aligned, and struck into one thing.
- Stage 01 · Capture
Six things exist, and none of them are together.
At the moment an output is produced, everything needed to defend it is real but scattered: the text in one system, the policy in another, the approvals in a third. Capture takes all six at creation, before any of them drift.
- Constituents
- 6 identified
- Registration
- unaligned
- Binding
- none
- State
- ephemeral
- Stage 02 · Bind
Aligned on one axis.
The constituents are registered against each other: this output, under this policy revision, from this model state, with these approvals. Binding is what makes the set a record rather than six files that happen to share a timestamp.
- Constituents
- 6 of 6 bound
- Registration
- aligned
- Binding
- content-addressed
- State
- assembled
- Stage 03 · Seal
Struck once, and never again.
A digest is taken over the assembled whole and committed. From this instant any alteration to any constituent produces a different digest, which is the entire mechanism by which the record defends itself.
- Digest
- SHA-256 · committed
- Chain
- linked to predecessor
- Mutability
- tamper-evident
- State
- sealed
- Stage 04 · Index
Findable years later, by the terms an auditor uses.
Sealing is worthless if the record cannot be retrieved. Records are indexed by case, policy, counterparty, model, and time: the axes an investigation actually searches on, not the ones a database happened to key.
- Indexed by
- case · policy · time
- Retrieval
- sub-second
- Retention
- policy-governed
- State
- indexed
- Stage 05 · Export
Handed over in a form that survives scrutiny.
An evidence pack leaves as a self-contained artefact: the record, its chain, and the means to verify both. It is checkable by someone who does not trust you and does not run Sigilith.
- Pack
- self-contained
- Verification
- offline capable
- Dependency
- none on Sigilith
- State
- exportable
Don't take tamper-evidence on faith. Break it.
This is a live record with a real seal. Alter any constituent and watch the digest recompute. The committed seal cannot follow it.
The recomputed digest no longer matches the committed seal. The alteration is detected without needing to know what changed: only that the record is no longer the one that was sealed.
Evidence primitives for regulated AI.
Three building blocks that make outputs defensible across systems and across time.
Verifiable output records
Cryptographically signed records created at generation, so every output carries a defensible chain of custody from the moment it exists.
Policy-linked context
Outputs are tied to the governing policy state, approvals, and operational context, so a review gets the whole story, not a fragment of it.
Audit-ready evidence packs
Exportable evidence for regulators, disputes, investigations, and board review, produced on demand instead of scrambled together from logs.
Built for governance under real audit pressure.
What
The authorisation layer for consequential AI decisions: policy-checked and sealed before the decision goes out.
For who
Compliance, legal, risk, security, and model governance teams, starting in financial services and insurance.
Why now
AI is moving into regulated workflows. Audits, disputes, and model risk reviews require evidence, not screenshots.
How
Check the decision against the policy in force, bind approvals and context, seal it at issue, and generate evidence packs on demand.
The path to the evidence layer.
Start with high-risk outputs. Expand into system-of-record infrastructure.
Regulated outputs, customer and regulator facing
Start where audit exposure is immediate: support responses, disclosures, notices, and other outward-facing high-stakes outputs.
Internal decisioning and approvals
Extend evidentiary capture to underwriting, claims, credit support, and internal workflows tied to governance gates.
Authorisation across the AI supply chain
Every consequential decision policy-checked and sealed in the path, across models, tools, vendors, and the systems they depend on.
Sigilith Sentry
One-shot liveness verification, server-side fraud adjudication, and human review in one controlled workflow for regulated onboarding, with every decision exiting as a record of the kind assembled above.
You already have GenAI. Now you need proof.
Request access to the pilot and we'll walk you through evidence packs, policy binding, and sealing against your own workflows.