Skip to content

Compliance and audit

Prove what your AI agent did. And what it could not have done.

Autonomous agents are reaching production faster than the frameworks that govern them. When the question arrives, from an auditor, a customer, a regulator, or your own incident review, the answer has to be evidence, not screenshots. InnerWarden builds that evidence at runtime, on your infrastructure.

The evidence stack
local to auditor-grade
RecordAll tiers

Every verdict hash-chained in a local decision log.

AnchorAll tiers

Off-host commitment your CI can fail on a non-zero exit.

SignaturePro & Enterprise

Ed25519-signed anchor, tamper-evident to an auditor.

EnforcementLinux · armed

On Linux, the Execution Gate bounds what could run at all.

Record, anchor, sign, enforce: a trail that survives a root-level attacker.

The evidence stack

Four layers, from local log to auditor-grade proof.

  1. Record
    All tiers

    A hash-chained record of every decision

    Every verdict on every agent action, allowed or denied, lands in a local decision log where each record carries the SHA-256 of the one before it. Edit or remove a record and the chain breaks visibly. Nothing depends on a cloud service to exist.

  2. Anchor
    All tiers

    Anchors that survive a root-level attacker

    An internal chain cannot prove the whole log was not deleted and regrown. The audit anchor CLI emits a compact commitment to the log tip that you record off the host; verification later proves the live log still holds it, and your monitoring or CI can fail the check automatically if verification ever breaks.

  3. Signature
    Pro & Enterprise

    Ed25519-signed anchors for auditors

    The paid tier signs the anchor with an off-host key, making the commitment tamper-evident even to a third party: evidence you can hand to an auditor, not just to yourself.

  4. Enforcement
    Pro & EnterpriseLinux · armed

    Prove what could not have happened

    With the Execution Gate armed, unknown binaries are denied at exec in the kernel. That upgrades your audit trail from a record of what happened to a provable statement about what was impossible: the agent could not have run anything outside the pre-authorized set.

Framework readiness

Built to answer the questions frameworks ask.

Emerging AI regulation and existing security frameworks converge on the same demands: know what your automated systems did, show who approved what, and keep records that survive tampering. InnerWarden is designed to produce exactly that record for agent activity, locally, without shipping your data to a third party to get it.

  • 13 ISO 27001 controls mapped, with the audit trail served from a local API
  • MITRE ATT&CK coverage with a Navigator export for your security team
  • Admin-action audit: operator overrides are first-class, hash-chained records
  • Syslog CEF output for your existing SIEM, plus Prometheus metrics

Why this is different

Most audit trails describe. This one constrains.

A conventional log tells you what an agent did, written by software the attacker may control. InnerWarden pairs the record with enforcement: on Linux hosts, the Execution Gate bounds what the agent could execute at all, and the anchor chain makes rewriting history detectable. The record and the constraint back each other up.

See the kernel evidence

Regulated teams

Bring us your audit requirement.

If your organisation needs to account for what autonomous agents do on its infrastructure, tell us which framework you answer to and what evidence your auditors expect. We will show you what the trail looks like on a real host.

The trail, at a glance

01Record
All tiers
02Anchor
All tiers
03Signature
Pro & Enterprise
04Enforcement
Pro & Enterprise

Talk to security

Read by the founders

One minute to fill in. We reply with what the evidence trail looks like on a real host.

Sent to our self-hosted Mautic instance. By submitting, you agree that we may contact you about InnerWarden early access. See our privacy policy.