Skip to main content

Documentation

Technical reference for your engineers, auditors and buyers. Decision Keep is the independent, out-of-band forensic witness for AI and automated decisions – zero-knowledge infrastructure that sits outside your organisation's systems. These pages describe the public evidence format, the dkr-1 receipt specification, and the integration surface. Safe to share during evaluation. Live operator surfaces (the ledger, audit trail and exports) remain behind authentication.

Capture & integrate

Three ways to get decisions into the ledger: the dashboard, the /api/decisions endpoint, and streaming ingest. Includes the payload-minimisation rule and zero-knowledge recording models (Custodian, Client-signs).

Decision record (JSON)

The exact shape of a recorded decision. Every field, its type, and what the system computes versus what you supply. Signed with your organisation's own Ed25519 key – this is the artifact auditors verify offline.

Receipt format (dkr-1)

The vendor-neutral, open receipt format: content hash, chain hash, Ed25519 signature, RFC 3161 timestamps. Any auditor can verify a receipt without Decision Keep software, account, or trust.

API reference

Enterprise API: authentication, all endpoints, request/response schemas, examples, status codes and rate limits. The verification endpoint requires no account and no trust in the platform – integrate recording and verification into any system.

SDK

Non-blocking TypeScript SDK for capturing automated decisions from any app. Zero blast radius, bounded retry buffer, sendBeacon unload flush, and observable drop rate.

MCP server

Model Context Protocol server for AI agents and coding assistants. Verify decision trails natively without sitting in the pipeline. Exposes verify_receipt, get_receipt, export_ledger, and get_attestation tools.

Compliance & standards

How the immutable, out-of-band ledger maps to AU APP 1.7–1.9, the EU AI Act (Art.12), GDPR, and US statutes, and the Minimum vs Gold Standard audit posture.

Security & procurement

Security posture, who touches your evidence, the SOC 2 control mapping, and how to request a DPA and security questionnaire for procurement. Zero-knowledge by design – we never see plaintext payloads.

Trust Center

Control-to-code mapping for SOC 2 and ISO/IEC 27001. See exactly which security controls are implemented, tested, and ready for your auditors.

Glossary & resources

Plain-language definitions of every concept above, audit readiness checklists, and links to the regulations and standards Decision Keep is built for.

Verify anything, anywhere

The ledger is trustless: auditors verify receipts at /verify with no account, or run the offline verifier npm run verify:ledger against your exported ledger and published key.

See the Forensic Witness on your stack

Book a personalised demo and we'll map Decision Keep to your automated-decision obligations and show the evidence trail end to end.