Audit and Attestations

    Signed proof for every decision.

    Every run becomes a signed record: its AI BOM (AI Bill of Materials), the rules it was checked against and how each one came out. Hand it to your auditor as is.

    AISquare · Reasoning

    RUN 8823 · SUPPORT AGENT · REFUND.CREATE

    Why the $1,250 refund was blocked

    4 claims · 1 unsupported
    CLAIMEVIDENCESTATUS
    Customer identity verifiedID check, session 8823Supported
    Outage fell inside the SLA windowStatus incident INC-2291, Sep 12Supported
    Customer is owed $1,250Assumed from 3 days of downtimeAssumption
    $1,250 is within the refund capRule 4.2 caps refunds at $500Unsupported

    Agent decision

    $1,250 refund blocked. Sent for manager approval.

    Rule 4.2 · refund cap $500 · Why?

    Attestation

    RUN 8823 · REFUND.CREATE

    Signed by AISquare RuntimeSigned and tamper-evident
    Key ID
    ais-runtime-key-01
    Signed at
    Sep 12, 2026 · 14:32 UTC
    Decision
    Blocked, sent for approval
    Rules
    4.2, sla.window, privacy.pii
    Evidence
    Ticket 8823, INC-2291

    AI BOM entry sealed

    The problem

    When an auditor asks why, logs can't answer.

    Logs show what an agent did. They can't prove why, or that nothing changed since.

    Audit requestRefund 8823 · Sep 12
    Which model made the decision?Unknown
    Which prompt was live?Unknown
    Which rule applied?Unknown
    Has the record changed since?Can't tell

    Rebuilt by hand from logs, weeks later. Editable, so not evidence.

    Inside a record

    Four layers, sealed together.

    AI BOM

    gpt-4o-mini · v7 · 3 tools

    Verdicts

    3 rules · 1 blocked

    Reasoning

    4 claims · 1 unsupported

    Signature

    Signed and tamper-evident

    1. 01

      AI BOM

      What the agent used: model, system prompt version, tools and tool calls.

    2. 02

      Verdicts

      Each rule it was checked against, the version that was live, and the result.

      How rules are enforced →
    3. 03

      Reasoning

      The claims the agent made and the evidence behind them.

      See RML →
    4. 04

      Signature

      Every rule verdict and the run itself are signed and tamper-evident. Change anything and verification fails.

    What's inside an AI BOM

    Run 8823 · Support agent

    Export · CycloneDXJSON
    How exports work →

    Model

    gpt-4o-mini

    Provider and version recorded

    System prompt

    v7

    Version recorded

    Tools called

    crm.lookupstatus.incidentsrefund.create

    Data used

    Refund policy 4.2Ticket 8823INC-2291

    Rulebook

    Support Rulebook v4

    Continuous evidence

    No audit project. The run documents itself.

    Time from decision to evidence

    Compiled after the fact

    Weeks pass
    Questionnaires
    Evidence hunt
    Report
    weeks later

    AISquare

    Sealed with the run
    Signed

    Evidence is written while the agent works, not reconstructed weeks later.

    Compliance packs

    See each record against the frameworks you answer to.

    Map the same signed records to the frameworks your auditors ask about.

    EU AI Act

    High-risk AI obligations

    OWASP Top 10 for LLMs

    LLM application risks

    NIST AI RMF

    AI risk management

    ISO/IEC 42001

    AI management system

    SR 11-7

    Model risk management

    DoD AI principles

    Responsible, traceable, governable

    Your internal controls

    Your own policies and SOPs

    And more, mapped to the same signed records.

    Talk to us about your framework →

    Example · EU AI Act pack

    EU AI Act

    Support agent · last 30 days
    RequirementWhere the evidence comes fromStatus
    Art. 12 Record-keepingEvery step of every run, recorded and signedCovered
    Art. 13 TransparencyReasoning for each decision in RMLCovered
    Art. 14 Human oversightRules, corrections and escalations to your teamCovered
    Art. 15 Accuracy and robustnessRule verdicts and failures across runsCovered
    Incident reconstructionReopen and replay any past runCovered
    Art. 9 Risk managementYour risk process, with run evidence attachedNeeds your input

    The evidence layer, not a certificate.

    No tool makes you compliant on its own. AISquare gives your auditors the records, mapped to the frameworks they check.

    Export and share

    Hand it over without a fire drill.

    Export one or many

    Export a single record or a whole set of runs at once.

    Share with auditors

    Give your auditor access to the records they need to review.

    Verify anywhere

    Anyone can check that a record hasn't changed since it was signed.

    Export formatsPDFJSONDSSE / in-totoCycloneDX AI BOM

    Built for every reviewer

    One record. Every reviewer.

    Risk and compliance

    Sign off with evidence, not assurances.

    See every decision against your compliance packs.

    Internal audit

    Sample any decision and read it end to end.

    Check the signature yourself.

    Engineering

    Reconstruct what happened, step by step.

    Fix what keeps failing with Learnings →

    For developers

    Pull your compliance summary over the API.

    curl -s -H "X-API-KEY: $EXPLAINABILITY_API_KEY" "$EXPLAINABILITY_GATEWAY_URL/v1/studios/$STUDIO_ID/policy/compliance"

    Returns the recent compliance rate, violations and the rules that fail most.

    FAQ

    Questions, answered.

    What is a decision record?

    A signed record of one agent run: what it used, which rules it was checked against, the result of each, and the reasoning behind it.

    What exactly is signed?

    Each rule verdict and the run itself. Both are tamper-evident, so any later change fails verification.

    What is an AI BOM?

    The record of the model, system prompt version, tools and tool calls a run used. Exportable as CycloneDX.

    Which formats can I export?

    PDF, JSON, DSSE / in-toto envelopes and a CycloneDX AI BOM.

    Can I export many runs at once?

    Yes. Export one record or a whole set of runs.

    Can I share records with an auditor?

    Yes. Give your auditor access to the records they need, and they can verify each one.

    Which frameworks can I map to?

    Compliance packs include the EU AI Act, OWASP Top 10 for LLM applications, NIST AI RMF, ISO/IEC 42001, SR 11-7 and the DoD AI ethical principles, plus your own internal controls.

    Does this make us compliant?

    No tool does that on its own. AISquare gives you the evidence layer: signed records mapped to the frameworks your auditors check.

    Give your auditors proof, not logs.

    Every decision your agents make, signed and ready to hand over.