Guardian Agent Platform · For risk & compliance leaders

Prove your AI agents were governed. Independently, without trusting the vendor.

Your AI agents are executing regulated work right now. When a regulator or your board asks for proof that an action was authorized, your AI platform cannot vouch for itself. Kinetic is the independent check: it produces evidence your own auditor can verify, without taking your word, your platform's word, or ours.

Pilot-stage Reference architecture Canadian-controlled Independent & auditor-verifiable NATO NCAGE L13Z9 (eligibility, not accreditation)
Built for design partners
Chief Risk & Compliance Officers at regulated firms, the CISOs and Big 4 risk partners who support them, and teams running LangGraph, AutoGen, CrewAI, or Copilot Studio agents with no independent execution record.
The Independence Problem

A system cannot audit its own behavior.

The platforms building your AI agents are now also selling the tools to govern them: the same entity grading its own homework, inside its own trust boundary. When your regulator asks for proof, a log the platform wrote about itself is not independent evidence.

A bank cannot sign its own audit opinion. A Copilot agent cannot generate proof that its own execution was properly governed.

Kinetic runs outside the system it governs: separate process, separate credentials, separate trust boundary. That separation is exactly what an auditor and a regulator are looking for, and it is the one thing a self-governing platform structurally cannot offer.

We hold ourselves to the same standard. Independent attestation of Kinetic's own controls (third-party security review, then SOC 2 Type I) is planned. You should not have to take the word of the people who built the audit layer either.

Read the paper: The Independence Gap
Platform governs its own agentsself-certified
In-process governance layersame trust boundary
Audit log written after executionno prevention
Kinetic checks before executionaction can be stopped
Kinetic independent, verifiableauditor confirms offline
What You Can Put In Front Of A Regulator

Three things your AI platform can't give you.

Kinetic turns every agent action into evidence a third party will accept. In plain terms, here is what that buys you.

01 · INDEPENDENT

Evidence that counts as third-party

The record is produced outside the agent and the platform, so it stands as independent proof, not a self-issued log. It is the difference between a bank's own spreadsheet and an external auditor's opinion.

02 · PRE-EXECUTION

Risky actions stopped before they happen

Every action is checked before it runs and can be blocked, not just logged after the damage. A blocked action has a blast radius of zero. Nothing executes unwitnessed.

03 · VERIFIABLE

Your auditor confirms it, offline, without us

You get a portable certificate your own team or auditor can verify independently, with no call to Kinetic and no access to our systems. Trust the math, not the vendor.

The Proof, For Your Auditors And Engineers

Three cryptographic layers. Each with its honest boundary.

The outcomes above rest on standard, off-the-shelf cryptography your security team can inspect. Here is exactly what each layer proves, and what it does not.

LAYER 1 · INTEGRITY

SHA-256 hash chain

Each ledger entry is chained to the last. Any alteration, deletion, or insertion breaks the chain and every hash after it. Verified by verify_chain.py: pure Python, run without contacting us.

Detective by design: any alteration is caught out-of-band by the hash mismatch. The ledger proves integrity; it complements, not replaces, your own database access controls.
LAYER 2 · BINDING

Payload fingerprint + replay

A SHA-256 fingerprint of the agent's submitted context is bound into the record. Deterministic replay re-derives the decision and hash from the stored inputs: VERIFIED if they match, DIVERGED if not.

Proves the integrity of the agent's input, not the authority or truth of the source system it read.
LAYER 3 · ATTESTATION

Ed25519 signature

Each record's hash is signed with an Ed25519 key and verified against a published public key. This is authority-attested integrity: a portable governance certificate an auditor verifies offline.

Authority-attested integrity today; hardware-rooted non-repudiation (HSM-backed signing) is on the roadmap. Key-custody details shared with design partners under NDA.

What you can verify yourself: no server, no trust assumption

  • Run the verifier: python verify_chain.py --verify-signatures --kinetic-pubkey-file kinetic_pubkey.pem: pure Python + hashlib, no dependency on Kinetic.
  • Prove immutability: attempt an UPDATE on the ledger in the sovereign demo; Postgres refuses it: ERROR: append-only ledger table.
  • Replay a decision: the deterministic replay re-derives the exact outcome and hash from stored inputs.
The Research

The Independence Gap

The argument in full: why a system cannot produce trustworthy evidence about its own behavior, why in-process governance fails the auditor's independence test, and what out-of-process cryptographic verification makes possible for regulated AI.

The Offer

The 30-Day Governance Certificate Pilot

Not a sale, a proof. No procurement, no license, no security-clearance gate. You bring one agent workflow (or a synthetic test case); we produce evidence you can hand to an auditor.

FREE · design partners only

What you walk away with

  • 3 governance certificates, each a record your auditor accepts: the ledger entry, its signature, and a deterministic replay result.
  • An independent verification session: your team (or your auditor) confirms the evidence locally. No dependency on our infrastructure.
  • A replay report: a clear pass or fail for each action, tied to the exact policy version that governed it.
  • A one-page limitations memo: precisely what this does not cover. We include it because independence requires stating the boundary.

What you provide: pick one phase

PhaseIntegrationTime
1 · ZeroA single manual call to the evaluation endpoint with a sample agent action.~30 min
2 · LightOne decorator on one function in your existing agent.2-4 hrs
3 · FullProxy / connector integration. Not required for the pilot; reserved for a funded follow-on.N/A

You can also run the sovereign demo bundle entirely inside your own boundary (zero cloud account, zero external network) and prove immutability yourself before engaging our hosted engine.

Read Before You Evaluate

What Kinetic is not, yet

We list these on purpose. Knowing the boundary is what makes the proof credible.

Not a source-truth validator. We bind the agent's payload; we do not independently reconcile it against the raw AWS/GitHub/IAM source. That module is a design concept, not built.
Not an independently-attested product. No SOC 2 attestation exists yet; SOC 2 Type I is planned, not started. Framework mappings are references, not audits.
Not hardware-rooted non-repudiation yet. Today's signing provides authority-attested integrity; HSM-backed signing is planned. Custody specifics shared under NDA.
Not tactical-edge hardware. Air-gapped, sovereign-deployable (a container inside your boundary) is real. Ruggedized battlefield hardware is a future profile, not the current product.
Not a cross-classification, cross-tenant view. The design is federated enclaves: one isolated tenant per domain, aggregated metadata only.
Not kernel-layer enforcement. The interceptor governs at the API layer. Syscall/kernel enforcement is a future tier.
Framework Mapping

Mapped to the regimes you answer to.

The ledger and replay produce evidence structured against the frameworks governing AI in regulated finance and government.

OSFI E-23
BMA AI Governance
EU AI Act
NIST AI RMF
ISO/IEC 42001
Ontario Bill 194

Framework mapping only, not an attestation. Kinetic has no completed independent audit yet; SOC 2 Type I is planned. Each mapping is an evidence structure with a documented gap register, not a certification.

Start

Get proof your auditor can verify.

A 30-minute walkthrough, then the pilot. For risk, compliance, and security leaders.