Provenance for AI · Now in Private Beta

Prove what
actually happened.

Apotrope seals every action — agent, human, or system — into a tamper-evident, evidence-grade chain of custody. Verifiable by your auditors and examiners. Runs in your perimeter; you hold the keys.

Built to satisfySOXHIPAAFDA 21 CFR Part 11EU AI Act
Cryptographically signedEvidence-gradeRuns on-prem
Worked example · IRS tax-return review

An AI-augmented tax-return exam, with proof at every step.

What an IRS examination could look like with Apotrope: an agent screens the return and drafts the adjustment on an examiner's authority, a human signs off, and the Master File posting carries cryptographic proof end to end.

signed · chain of custodyverifiable · tamper-evident
#prev-hash#prev-hash#prev-hash#prev-hash#prev-hashsignedReturn filedmef.intake · validatee-file · form 1040signedAgent screeningrrp.screen · 1099.matchon-behalf-of · examiner@irshashedDraft adjustmentworkpaper · cp2000.draftinputs content-hashedsignedExaminer approvalapprove · adjustmentmanager review ✓ · exam@irssignedMaster File posttc.post · record.writesvc-acct · IRS master fileVerifychain intact
Why Apotrope

The system of record for what your agents and people did.

Every action — by an agent, a person, or a system — sealed into one chain you can prove, not just log.

Tamper-evident chain of custody.

Every step — agent, human, or system — is signed and hash-linked into one chain, with the exact inputs it consumed content-hashed. Alter anything after the fact and verification breaks visibly.

Hash-linkedSigned recordsInput provenance

Identity on every action.

Each step records who acted and on whose authority — agents run on-behalf-of an employee through your own IdP, scoped per step. No shared service accounts, no anonymous automation.

On-behalf-ofScoped per stepYour IdP

Human approvals, cryptographically bound.

Reviews and sign-offs are first-class nodes in the same chain, bound to the content hash of exactly what the person saw. Four-eyes and separation-of-duties are enforced structurally, not by policy memo.

Four-eyesContent-boundSeparation of duties

Verifiable & audit-ready.

Independent parties — auditors, QSAs, examiners, courts — can confirm the chain is authentic and untampered. Real cryptographic proof, not self-attested logging you ask people to trust.

Auditor-verifiableTamper-evidentEvidence-grade

Runs in your perimeter, you hold the keys.

Workers, identity resolution, and signing keys live inside your network. Data and credentials never leave. Because you hold the trust anchor, Apotrope itself can't forge your chain.

On-prem / hybridCustomer-held keysNo data egress

Works with your stack.

Neutral by design: any IdP, any cloud, any LLM — agentic or not. Standards-based (OIDC, SAML, RFC 8693), so the proof layer slots into the identity, infrastructure, and models you already run.

Any IdPAny cloudAny model
Works with your stack

Any IdP. Any cloud. Any model.

Okta
Microsoft Entra
Auth0
AWS
Google Cloud
Databricks
Snowflake
PostgreSQL
OpenAI
Okta
Microsoft Entra
Auth0
AWS
Google Cloud
Databricks
Snowflake
PostgreSQL
OpenAI
Anthropic
Hugging Face
Ollama
Salesforce
Jira
Confluence
GitHub
Datadog
Anthropic
Hugging Face
Ollama
Salesforce
Jira
Confluence
GitHub
Datadog
Talk to the founders

See it prove your own workflow.

Book a working session. We'll stand up a chain of custody on a workflow you care about and verify it end to end — agents, approvals, and all.

Request a demo
Not ready to talk? Get the technical brief.
no spam · work email only · unsubscribe anytime
✓ Thanks — check your inbox to confirm.