Prove what your
people asked the AI.
Months later.
Evidarch records every prompt, document and answer that leaves your organization for ChatGPT, Claude, Gemini, coding agents or a server-side pipeline. Each record is hash-chained and tied to a named person, so it still verifies months later, when nobody remembers the conversation.
On-premises, your own cloud, or SaaS. Content redacted on the device before it leaves. We never use your data for anything.
Real SHA-256, computed in your browser. Edit a record and the chain answers.
Your AI policy is currently an honour system.
Staff paste customer records into chatbots. Engineers hand source code to coding agents. Someone uploads the acquisition model to get a summary of it. None of that shows up in your DLP, your SIEM or your SaaS logs. To the browser it is ordinary typing on an ordinary website.
So when a regulator or your own board asks what happened, the honest answer is that nobody knows. Evidarch is built to answer that question, and to make the answer hold up when somebody doubts it.
Capture at the edge. Chain on arrival. Prove on demand.
Each claim links to the tab that substantiates it.
Capture
Collectors sit where the AI actually is: the browser, your gateway, your coding agents, your own hardware. They record the interaction as it happens, rather than reading a log that might never be written.
What it sees →Chain
Each event is hashed together with the one before it. Alter a record, remove one, reorder two, and every link after the change stops verifying. You cannot stop somebody editing a database. You can make sure it shows.
The architecture →Prove
Re-verify the whole chain and export a signed attestation. Your auditor can re-check it against your live ledger using their own code. They do not have to trust ours.
What it satisfies →What the record actually looks like.
Three views, each backing up one of the claims above. These are real captures from a seeded demo organization. The people in them are invented.
Most tools log. Evidence has to survive being doubted.
Redacted before transmission
Detection for secrets, credentials and personal data runs on the device. The control plane stores the finding and a hash of the original. Never the secret itself.
Witnessed outside the database
Chain heads are published somewhere an attacker with database access cannot reach. That makes a rewritten history detectable, not just unlikely.
Deletable without breaking proof
Erase a person's content for a subject request and the event rows and hash chain stay verifiable. You keep proof the interaction happened without keeping what was said.
Yours to host
Run it on-premises, in your own cloud account, or as a service we operate. Whichever pathway you pick, we never read your content, train on it or sell it. That is a contractual term rather than a preference.
Bring one hard question.
A feature tour is not much use. Bring the question you would struggle to answer today. Which of our staff sent customer data to an AI tool last quarter? Can you prove the answer was not edited afterwards? We will show you the record that settles it.