Skip to main content

Become a founding partner- 3 spots remaining·Shape the standard.Apply now

Independent forensic witness

Every flight has a black box. Why doesn't your AI?

Decision Keep records every automated decision outside your systems - asynchronously, immutably, and signed with your own key. The evidence belongs to you, and your auditors can verify it offline.

REC

The five pillars

Built on principles, not promises

Independent

Out-of-band witness. Outside your systems. We can't alter what we record.

Immutable

Append-only record chain. Tampering breaks the chain and is detectable by your auditors.

Verifiable

Offline tools and a public verifier. No account, no trust in the platform required.

Zero-knowledge

Your private key never leaves your environment. We never see plaintext payloads.

Sovereign

Your keys, your evidence. Always exportable and verifiable offline on your own key - no lock-in.

See how it works
Try a sample receipt

The platform

From decision to defensible evidence

A decision is signed with your key, bound into a tamper-evident chain, and provable offline by your auditors. The record is always there when you need to prove what happened.

Verify a receipt
01
Decision

Your system makes an automated decision - a credit call, a claim, a model output. Decision Keep is never in the path.

02
Signed

The decision is sealed and signed with your own Ed25519 key. The signature travels with the record.

03
Chained

Each entry binds to the previous one. The ledger is append-only; nothing is ever edited or deleted.

04
Verified

Auditors verify any receipt against your published key - offline, with no account and no trust in us.

How it works

A witness that never gets in the way

Works with your AI systems

Your agents and tools can read their own decision trail at any time. It slots into the stack you already run.

Zero impact on your apps

Recording never blocks, freezes, or breaks your software. If we're slow or down, your systems keep working.

Your keys, your evidence

Every record is signed and chained so it can be checked at any time - even offline - against your own key.

Built for procurement

Audit-ready from day one. Coverage for the EU AI Act, GDPR and APRA, with SOC 2 / ISO 27001 in progress.

Connectors

One witness. Every system you already run.

A single out-of-band witness records decisions from whatever makes them. Connect over the interfaces your teams already use - then point it at any system that emits a decision.

Interfaces

  • REST API
  • MCP server
  • SDK
See the integration docs
CelonisProcess mining
Apache KafkaEvent streaming
AWSCloud events
SalesforceCRM & flows
SAPERP events
OracleERP & AI apps
UiPathRPA
DatabricksData & AI
WorkdayHR & finance
SnowflakeData cloud
Decision
Keep

Compliance

Engineered for the agentic era

Every control is built in from day one - not bolted on later. Controls are aligned to SOC 2, ISO 27001, ISO/IEC 42001 and APRA CPS 234. Australia's automated-decision transparency rules (APP 1.7–1.9) take effect 10 December 2026.

EU AI Act
Art. 12 logging
GDPR
Storage limitation
APP 1.7–1.9
Privacy Act 1988
APRA
CPS 234 aligned

See the Forensic Witness in action

Book a personalised demo with our team, or join the waitlist to be onboarded when a slot opens.

FAQ

Questions auditors, risk and legal actually ask

What is Decision Keep?+
Decision Keep is the Forensic Witness for Automated Decisions - an independent, tamper-evident record of every automated decision your organisation makes. It signs each decision with your own Ed25519 key, so the evidence belongs to you and can be checked by your auditors offline. Unlike traditional logging, the record is immutable and verifiable without trusting the platform. Read more in our documentation or blog.
How does automated-decision auditing work with Decision Keep?+
Each automated decision is sealed with a digital signature and linked to the one before it, forming a chain that cannot be changed without detection. Auditors and regulators verify the whole ledger offline using your published key. No account and no trust in the platform required. See pricing for engagement details.
How does Decision Keep support automated-decision transparency?+
It records the system, model, version and inputs behind each automated decision, and proves exactly when and by what version it was made. That satisfies automated-decision disclosure obligations such as Australia's APP 1.7–1.9, and supports equivalent requirements in other regions. Learn more in our docs.
Does it support the EU AI Act and GDPR?+
Yes. It meets the EU AI Act's automatic logging requirement, GDPR storage-limitation obligations, and the right to erasure through signed, verifiable erasure that preserves the integrity of the record. Decision Keep is designed specifically for the compliance challenges of the agentic era. Book a demo to discuss your specific obligations.
What is an independent time stamp?+
An optional time stamp from an independent authority that proves exactly when an automated decision was signed, anchored outside your control. It adds forensic proof of "when" a decision was made. For regulated environments, we can integrate eIDAS-qualified trusted time as part of your enterprise engagement. Contact sales to learn more.
Can auditors verify receipts without an account?+
Yes. Verification is fully trustless and offline. Auditors use your published key and the exported ledger. No login, no access request, no trust in Decision Keep. Our public verifier lets anyone check a receipt in seconds, and auditors can download a signed attestation report.
How much does Decision Keep cost?+
Decision Keep is a paid product and pricing is scoped per engagement. We operate the vault and stand behind the deployment; pricing is an annual licence plus metered per-decision usage that covers the platform. Book a demo to discuss your plan.
What recording models are available?+
Decision Keep offers three recording models: Operator-signs (we hold your org key and sign on your behalf), Custodian (we host the ledger but your payload is sealed to your published key - zero-knowledge), and Client-signs (you sign in your own environment; the raw payload never reaches us). Each model is selectable per workspace. Compare models on the pricing page.
How does Decision Keep compare to traditional audit logs?+
Traditional audit logs are stored on systems you control, which means they can be altered or deleted. Decision Keep records every automated decision outside your systems as signed, immutable evidence. The chain is tamper-evident, and auditors verify offline without trusting the platform. See pricing or read our blog for more on the difference.
Is Decision Keep SOC 2 certified?+
Decision Keep is not yet SOC 2 or ISO 27001 certified. The product is engineered with security and compliance controls mapped to SOC 2, ISO 27001, EU AI Act, GDPR, APP 1.7–1.9 and APRA, and an independent audit can be scoped as a workstream in your enterprise engagement. Contact us to discuss your audit requirements.
What is an automated decision?+
An automated decision is any decision made by software without meaningful human involvement at the moment it is made - credit scoring, insurance underwriting, fraud routing, eligibility checks, content moderation and similar. If your system applies rules, a model, or an agent to reach a conclusion and act on it, that is an automated decision. Decision Keep records every one of them as a signed, verifiable receipt the moment it happens.
How does Decision Keep differ from traditional audit logs?+
Traditional audit logs live on systems you control, which means they can be altered or deleted. Decision Keep records every automated decision outside your systems as signed, immutable evidence. The chain is tamper-evident, and auditors verify it offline without trusting the platform. See pricing for the full comparison.
What compliance frameworks does Decision Keep support?+
Decision Keep is built for the compliance challenges of the agentic era. It maps to Australia's APP 1.7–1.9, the EU AI Act (Art.12 automatic logging), GDPR (storage limitation and right to erasure), US statutes including CCPA/CPRA and the Colorado AI Act, and UK GDPR. It also aligns with SOC 2, ISO 27001, ISO/IEC 42001 and APRA CPS 234. See the full compliance mapping.
Can Decision Keep integrate with my existing AI and software systems?+
Yes. Decision Keep is framework-agnostic. You can send decisions via the REST API, stream JSONL logs, or use the non-blocking TypeScript SDK. It works with any agentic system - LangChain, CrewAI, AutoGen, or custom - and the MCP server lets AI coding assistants verify decision trails natively. Explore integration options.