Your AI agents are executing regulated work right now. When a regulator or your board asks for proof that an action was authorized, your AI platform cannot vouch for itself. Kinetic is the independent check: it produces evidence your own auditor can verify, without taking your word, your platform's word, or ours.
The platforms building your AI agents are now also selling the tools to govern them: the same entity grading its own homework, inside its own trust boundary. When your regulator asks for proof, a log the platform wrote about itself is not independent evidence.
Kinetic runs outside the system it governs: separate process, separate credentials, separate trust boundary. That separation is exactly what an auditor and a regulator are looking for, and it is the one thing a self-governing platform structurally cannot offer.
We hold ourselves to the same standard. Independent attestation of Kinetic's own controls (third-party security review, then SOC 2 Type I) is planned. You should not have to take the word of the people who built the audit layer either.
Read the paper: The Independence GapKinetic turns every agent action into evidence a third party will accept. In plain terms, here is what that buys you.
The record is produced outside the agent and the platform, so it stands as independent proof, not a self-issued log. It is the difference between a bank's own spreadsheet and an external auditor's opinion.
Every action is checked before it runs and can be blocked, not just logged after the damage. A blocked action has a blast radius of zero. Nothing executes unwitnessed.
You get a portable certificate your own team or auditor can verify independently, with no call to Kinetic and no access to our systems. Trust the math, not the vendor.
The outcomes above rest on standard, off-the-shelf cryptography your security team can inspect. Here is exactly what each layer proves, and what it does not.
Each ledger entry is chained to the last. Any alteration, deletion, or insertion breaks the chain and every hash after it. Verified by verify_chain.py: pure Python, run without contacting us.
A SHA-256 fingerprint of the agent's submitted context is bound into the record. Deterministic replay re-derives the decision and hash from the stored inputs: VERIFIED if they match, DIVERGED if not.
Each record's hash is signed with an Ed25519 key and verified against a published public key. This is authority-attested integrity: a portable governance certificate an auditor verifies offline.
Authority-attested integrity today; hardware-rooted non-repudiation (HSM-backed signing) is on the roadmap. Key-custody details shared with design partners under NDA.python verify_chain.py --verify-signatures --kinetic-pubkey-file kinetic_pubkey.pem: pure Python + hashlib, no dependency on Kinetic.UPDATE on the ledger in the sovereign demo; Postgres refuses it: ERROR: append-only ledger table.The argument in full: why a system cannot produce trustworthy evidence about its own behavior, why in-process governance fails the auditor's independence test, and what out-of-process cryptographic verification makes possible for regulated AI.
Not a sale, a proof. No procurement, no license, no security-clearance gate. You bring one agent workflow (or a synthetic test case); we produce evidence you can hand to an auditor.
| Phase | Integration | Time |
|---|---|---|
| 1 · Zero | A single manual call to the evaluation endpoint with a sample agent action. | ~30 min |
| 2 · Light | One decorator on one function in your existing agent. | 2-4 hrs |
| 3 · Full | Proxy / connector integration. Not required for the pilot; reserved for a funded follow-on. | N/A |
You can also run the sovereign demo bundle entirely inside your own boundary (zero cloud account, zero external network) and prove immutability yourself before engaging our hosted engine.
We list these on purpose. Knowing the boundary is what makes the proof credible.
The ledger and replay produce evidence structured against the frameworks governing AI in regulated finance and government.
Framework mapping only, not an attestation. Kinetic has no completed independent audit yet; SOC 2 Type I is planned. Each mapping is an evidence structure with a documented gap register, not a certification.
A 30-minute walkthrough, then the pilot. For risk, compliance, and security leaders.