1. Auditability for the EU AI Act
High-risk AI systems must produce verifiable execution records. Logs are not enough.
Cryptographic proof of what every AI system did.
AI systems are making consequential decisions - approving loans, drafting clinical notes, generating legal analysis - but enterprises have no verifiable record of what was asked, what was returned, or whether it complied with policy.
SONATE fixes this. Every AI interaction produces a signed, tamper-evident Trust Receipt that anyone can verify.
Anyone can verify a receipt with no vendor trust required. The proof artifact is canonicalized, signed, linked to the prior receipt, and bound to a W3C DID identity.
What the model was asked
What it returned
Which policies were applied
Whether it complied
Who authorized it
When it happened
High-risk AI systems must produce verifiable execution records. Logs are not enough.
When AI causes harm, screenshots and vendor logs are weak evidence. Signed receipts are defensible records.
Autonomous workflows require cryptographic accountability, not hope and not retrospective reconstruction.
SONATE detects behavioural shifts before they become incidents, claims, or regulatory findings.
Open where it should be. Proprietary where it must be.
The cryptographic foundation. Every AI interaction generates a signed, hash-chained receipt.
Real-time behavioural monitoring for AI behaviour, not just model metrics.
Policy enforcement at the point of interaction through a multi-model governance gateway.
We ran seven live stress tests on a production model, ChatGPT-4o-mini. SONATE generated a signed Trust Receipt for each one.
Each receipt is independently verifiable. This is governance you can defend in court.
Unified gateway captures the AI request.
6-constraint policy engine evaluates behaviour in under 50ms.
Ed25519 signature plus a hash-link to the prior receipt.
Immutable receipt stored in W3C VC format.
Anyone can verify using the open SDK.
AI is already making decisions that carry legal, financial, and ethical consequences. Operators need evidence before the claims process starts, not after.
We have TLS for networks. We have code signing for software. We have digital signatures for transactions. We have nothing for AI execution. Until now.
Stephen Aitken, Founder & CEO. Twenty years in regulated fintech operations. Built SONATE end-to-end using AI-assisted development across more than 200K lines in seven months.