What your AI agents did
vs. what they said
A read-only evidence engine in your own cloud account. It corroborates what your agents claim against the records your infrastructure already keeps — AWS, GCP, Azure, Kubernetes, GitHub — and surfaces the divergence as auditor-ready, signed evidence.
Nothing installs in the agent path. One read-only role connects it.
three bearings — a position fix. Toggle a stream to add or drop a bearing.
A navigator never trusts one bearing. Neither should you trust the claim alone.
A cross bearing fixes a position from independent reference lines: no single line is enough, but where several cross, the true position is pinned. crossbearing does the same with your agents — it crosses what an agent says it did against the records your clouds keep anyway.
What the agent says it did — its own telemetry, receipts, tool logs, CI output.
What your infrastructure actually logged — AWS, GCP, Azure, Kubernetes, GitHub.
Where the two disagree — an action with no claim, a claim with no record, a human nobody can name.
Five record streams, validated against real data. Each is a bearing.
AWS is the live bearing — read live from your own account and signed with your own KMS key. GCP, Azure, Kubernetes, and GitHub corroborate from the audit logs they already keep.
The more independent streams cross the same window, the smaller the region they pin down — and the harder it is for an action to hide.
One agent session against AWS — and every way the story can diverge.
The agent claimed a handful of read-only calls. CloudTrail tells the fuller story: a write where it claimed a read, a production bucket it never mentioned that no human owns — pinned to the agent’s own proven credential — plus a call that left no record, and one it never claimed. The real engine, run offline.
how to read this report
Neither line is a finding alone. The agent announced the read; the delete is the Grafana service account doing what it does all day. Only crossing the bearings connects them — and whether it was wrong is your call, not ours.
Two records. Two audit planes. No shared principal, credential or ARN.
Signed with your key. Hash-chained. Verifiable without us.
Each link is sha256(prev ‖ finding). Edit, reorder, or drop one finding and every hash downstream changes — and the signature no longer verifies.
Re-fetchable
Every finding points at the raw event it came from, with a digest — evidence an auditor re-derives, never an assertion.
Tamper-evident
Findings are hash-chained and signed with your own KMS key. Edit, reorder, or remove one and the chain breaks visibly.
Independently verified
A separate, MIT-licensed, zero-dependency verifier checks the chain and signature offline — mapped to SOC 2 controls.
If your customers are asking what your AI agents are allowed to do, we should talk.
We are taking a small number of design partners — AI-product teams under SOC 2 / ISO 42001 pressure. You bring the agents and the clouds; we bring the evidence.