1. Auditability for the EU AI Act
High-risk AI systems must produce verifiable execution records. Logs are not enough.
SONATE generates cryptographic proof of what every AI system did and whether it can be trusted.
AI systems are making consequential decisions - approving loans, drafting clinical notes, generating legal analysis - but enterprises have no verifiable record of what was asked, what was returned, or whether it complied with policy.
SONATE fixes this. Every AI interaction produces a signed, tamper-evident Trust Receipt that anyone can verify.
A Trust Receipt is verifiable evidence - not a log.
It captures what was asked, what was returned, and whether it complied, in a form anyone can verify independently.
What the model was asked
What it returned
Which policies were applied
Whether it complied
Who authorized it
When it happened
High-risk AI systems must produce verifiable execution records. Logs are not enough.
When AI causes harm, screenshots and vendor logs fail under scrutiny. Signed receipts are defensible evidence.
Autonomous systems make decisions without human review. Accountability must be built in, not reconstructed later.
Drift, bias, and manipulation rarely trigger alerts. SONATE makes them visible before they become incidents.
From proof to detection to enforcement.
Open where it should be. Proprietary where it must be.
The cryptographic foundation. Every AI interaction generates a signed, hash-chained receipt.
Real-time behavioural monitoring for AI behaviour, not just model metrics.
Policy enforcement at the point of interaction through a multi-model governance gateway.
We ran seven live stress tests on a production model, ChatGPT-4o-mini. SONATE generated a signed Trust Receipt for each one.
Each receipt is independently verifiable. This is governance you can defend in court - with evidence.
Unified gateway captures the AI request.
Evaluates behaviour across six governance principles in under 50ms.
Ed25519 signature plus a hash-link to the prior receipt.
Immutable receipt stored as signed JSON, with platform support for DID / VC-style envelopes.
Anyone can verify using the open SDK.
AI is already making decisions that carry legal, financial, and ethical consequences. Operators need evidence before the claims process starts, not after.
We have TLS for networks. We have code signing for software. We have digital signatures for transactions. We have nothing for AI execution. Until now.
Start verifying AI decisions in minutes. Scale to governed production.
Stephen Aitken, Founder & CEO. Twenty years in regulated fintech operations. Built SONATE using AI-assisted development across 200K+ lines of code in seven months.