Skip to main content
← All posts
2 min readProduct Updates

Introducing Decision Keep: the Forensic Witness for Automated Decisions

Why we built Decision Keep, the problem we exist to solve, and how we help organisations prove - not just claim - that every automated decision they make is fair, intact and defensible.

About the author+

Jamil Luketic

Executive Director at Decision Keep

Former Data & Tech Leader at Oracle, Mastercard, Coles, Optus, and Reece.

Connect on LinkedIn
Illustration for Introducing Decision Keep: the Forensic Witness for Automated Decisions

Most organisations can describe what their AI decided. Very few can prove it.

If an auditor, regulator, or your own risk committee asked you tomorrow - "what did your AI decide, and can you prove the record hasn't been changed?" - what would you hand over?

For most enterprises, the honest answer is: a story. Logs scattered across vendors. Screenshots. A console someone can edit. That gap - between claiming a decision was made correctly and proving it - is the problem we exist to solve.

Why we built Decision Keep

We came from the side of the room where the questions get asked: audit, risk, compliance, and the engineers who have to defend their systems to people who didn't build them.

We kept seeing the same pattern. Teams had adopted AI fast, governance slow - McKinsey's 2025 state of AI research shows organisations moving from experimentation to value, and Gartner predicts responsible AI governance will be a board-level priority. The models worked, the dashboards looked healthy, and then a regulator or a customer wanted evidence. Not a metric. Not a screenshot. Evidence that a specific decision was made, by a specific model version, at a specific time, and that nobody had quietly rewritten the record afterwards.

That evidence did not exist - because no one had built the recorder. So we built it.

Decision Keep is the Forensic Witness for Automated Decisions. Every automated decision your organisation makes is sealed in a tamper-evident record, signed with your own key, and verifiable offline by the people who need to trust it.

Our mission

Make every automated decision provable - so AI can be adopted with confidence, not blind faith.

We believe the biggest barrier to trustworthy AI is not the models. It is the missing evidence trail. Organisations are freezing good AI projects, or shipping them with unmanaged risk, because they cannot answer a basic question: can you prove what happened?

Our job is to make that answer exist by default - for every decision, on every system, in a form an auditor can verify without our involvement.

We are deliberately narrow. We do not build models. We do not compete with your observability stack. We do one thing: produce the Forensic Witness for your automated decisions, and keep it sovereign to you.

What we believe

A few convictions shape how Decision Keep works:

  • The evidence should belong to you. Your keys, your evidence. We operate the vault and stand behind the record as your independent assurance authority - like the auditor whose name is on a clean opinion - but the evidence is always yours and verifiable offline on your own key.
  • Trust must be verifiable, not requested. "Trust us" is not a control. Auditors should be able to check a receipt against your published key, offline, with no account.
  • Raw personal data should not be the audit trail. We store references and hashes, not copies of people's information - so proving a decision doesn't create a second privacy problem.
  • Deletion and defensibility are not opposites. When retention expires, content is cryptographically erased while a signed proof keeps the chain intact. You can satisfy the right to erasure and stay auditable.
  • You pick the custody posture. We operate the vault (managed by Decision Keep). In Custodian mode we host the ledger but seal each payload to your key, so we never see the plaintext and never hold the key to read it.

How Decision Keep helps your organisation

If you are the person who owns the automated-decision risk gap, here is what changes when you turn Decision Keep on:

  • You can prove every automated decision. Each one is signed with your Ed25519 key and linked into a hash chain. Change any entry and the break is detectable.
  • You can anchor time. An independent RFC 3161 timestamp proves exactly when an automated decision was signed - turning "we think it was Tuesday" into "signed at 2026-07-16T09:31:02Z, independently witnessed."
  • Your auditors verify offline. No login, no trust in us. They check receipts against your published key, in a script or in a regulator's office.
  • You satisfy the frameworks at once. The same evidence chain maps to the EU AI Act, GDPR, ISO/IEC 42001, SOC 2 and Australia's APP 1.7-1.9 - one record, many obligations.
  • You stay sovereign. The evidence is always yours and verifiable offline on your own key.

Who Decision Keep is for

  • Compliance, risk and audit teams who must answer to regulators and the board - and are tired of answering with metaphors.
  • Engineering and ML leads who want to ship AI responsibly without bolting a forensic trail onto every service by hand.
  • Public-sector and regulated industries - credit, insurance, recruitment, fraud, healthcare triage - where automated decisions carry legal weight.
  • Any organisation adopting agents and autonomous workflows that need a durable, queryable memory of what was decided and why.

A five-minute mental model

Think of each automated decision as a line in a flight recorder:

  1. The system decides -> Decision Keep captures the model version, inputs (references, not raw PII), output and routing outcome.
  2. The record is signed with your key and chained to the previous one.
  3. An independent timestamp anchors when.
  4. Your auditors verify the whole chain offline, against your published key.

No black box of our own. The evidence is yours, and so is the proof.

Where to start

You do not need to rip out your models. Decision Keep sits beside them and quietly produces the evidence your governance team already owes the regulator.

  • See it work: verify a sample receipt with no account.
  • Understand the format: read the receipt specification.
  • Talk to us: book a demo and we'll map Decision Keep to your automated-decision obligations.

FAQ

Questions auditors, risk and legal actually ask

What is Decision Keep?+
Decision Keep is the Forensic Witness for Automated Decisions - the independent, tamper-evident record of every automated decision your organisation makes. Each decision is signed with your own key, sealed in a chain that cannot be changed without detection, and verifiable offline by your auditors.
Why does the world need a 'Forensic Witness' for automated decisions?+
Every flight has a black box; most automated decisions have nothing. When an auditor, regulator or your own risk committee asks what an automated decision was and whether the record is intact, most organisations can only offer a story. Decision Keep exists so the answer is evidence: a signed, chained, time-anchored record your organisation controls.
What problem does Decision Keep actually solve?+
The gap between claiming a decision was made correctly and proving it. Logs can be edited, screenshots can be forged, and vendor consoles can disappear. Decision Keep produces evidence an independent party can verify offline, which is what audits, the EU AI Act, GDPR and Australia's APP 1.7-1.9 actually require.
How is Decision Keep different from model monitoring or observability?+
Observability tells you how a system is behaving now; Decision Keep proves what a specific automated decision was, when, by which model version, and whether the record is intact. They are complementary - monitoring is operational, the record is juridical.
Do we have to trust Decision Keep with our data?+
You choose the recording model. In Custodian mode we host the ledger but seal each payload to your published key, so we never see the plaintext and never hold the key to read it. In Client-signs mode you sign in your own environment and the raw payload need never reach us. In Operator-signs mode we host and sign on your behalf. Either way only content hashes - not raw personal data - are published, and verification is fully trustless: auditors check receipts against your published key with no account and no trust in us.
Who is Decision Keep for?+
Any organisation that uses AI to make or support decisions with real consequences - credit, insurance, recruitment, fraud, healthcare triage, public services - and the auditors, risk, legal and compliance teams who must answer for those decisions.

Sources

References & further reading

Independent analysis and standards cited in this article.

Prove every AI decision

Decision Keep gives your organisation a tamper-evident, verifiable record of every automated decision. Book a demo to see it on your stack.

Keep reading

Documentation

Go deeper in the docs