For teams accountable for what AI decides.

AI acts.Keep the receipt.

Policy before the model call. One signed record per decision. Verifiable without us.

Sample
When
Before the model ran
Policy
Personal data check
Outcome
Signing…

Checking

Checking this receipt in your browser

Signed record

Checked in this browser. No call to Aqta.

Open verifier on npmChange one field above. The signature breaks.

Works with the models you already use.

  • Anthropic
  • Bedrock
  • Azure OpenAI
  • Mistral
  • xAI
  • Cohere
  • Kimi

Most tools audit after the fact. AqtaCore runs before the action.

When audit asks what the AI decided, you already have the signed receipt.

ATTESTATION-v1Open spec + test vectors

A hand-painted record slip under an anglepoise lamp on a wooden desk at dusk, a pencil and a brass key beside it.
signing historyProduction gateway live
Signature schemeEd25519, canonical JSON

from runtime to independent proof

The receipt leaves with the decision. You keep the proof.

Policy runs before the model call. A reviewer checks the same receipt later with the published key. No callback to Aqta.

At the decision point

Blocked? The model is not called. The receipt remains.

Sample receiptATTESTATION-v1

decision
PASSED
policy
PII redaction
signature
Ed25519

Issued at runtime. Checkable later.

Outside Aqta

Independent check

A reviewer checks the same receipt with the published key.

  • Published public key
  • No call to Aqta
  • Clear pass or fail
Run the public verifier

For your engineering team

Three steps.
No SDK rewrite.

Get the receipt. Pin the policy. Drop in the proxy.

  1. 01

    Sign every AI call

    An Ed25519-signed receipt per call. Verifiable offline. No Aqta in the trust path.

    • Open verifier on npm
    • Verified offline, no callbacks
  2. 02

    Pin the policy

    Set per-user budgets, declare PII and PHI rules, detect loops. Every receipt records which policy version ran.

    • Policies versioned by Git SHA
    • Exported in audit bundles
  3. 03

    Drop in the proxy

    Point your OpenAI-compatible client at AqtaCore. One endpoint for any model.

    • Any OpenAI-compatible SDK works
    • Zero application rewrites

product

AqtaCore is the product.

Signed at runtime, verifiable offline, for regulated AI teams. Bounds Pro sits beside it for on-device redaction.

AqtaCore

Fintech · Insurtech · Healthtech · Banking · Public sector

Signed at runtime. Verifiable offline.

  • Pre-execution policy check, one signed receipt per call
  • Hash-chained and exportable as an evidence pack
  • Maps to DORA, EU AI Act, GDPR and MiFID II

Bring your hardest question.