ProofStream is a customer-hosted control and evidence layer for AI agents that take actions. Enforce policy at the point of execution, require approvals for high-impact actions, and export audit-grade proof on demand.
Designed for:
Customer-hosted by default. Your data stays in your environment.
Agentic systems are probabilistic and can drift. “We reviewed the prompt” isn’t a control when the agent can take actions.
Raw logs rarely answer audit questions. You need attributable actions, policy decisions, approvals, and change history — packaged as artifacts.
Without a control plane, each agent connects to tools directly and governance fragments. ProofStream centralizes enforcement and proof.
Integrate once. Govern consistently. Export evidence on demand.
Define purpose, owner, risk tier, and allowed tools/destinations.
Output: psCore agent manifest + inventory snapshot
All tool calls route through the gateway for allow/deny, constraints, and gating.
Output: policy decision record + version hash
High-impact actions become “draft → approve → execute” with accountability.
Output: approval + exception evidence
Generate audit packages: inventory, policies, approvals, traces, containment drills.
Output: evidence bundle (SIEM/GRC-ready)
The fastest path to control and defensibility is governing actions that are difficult or impossible to undo: outbound communications and data egress.
Outbound communications (psOutbound)
Data egress (psEgress)
ProofStream turns agent autonomy into testable controls and exportable proof.
Built on the ACR Framework™
ProofStream operationalizes ACR’s pillars as enforceable controls and exportable evidence — focused on runtime actions, not just model behavior.
ProofStream is modular by design. Start with one capability and expand as your agent footprint grows.
Identity, purpose binding, ownership, and risk tiering for every agent.
Policy-as-code for agent actions — versioned, testable, and attributable.
Human oversight workflows for high-impact actions.
End-to-end traceability for executed actions.
Containment and resilience mechanisms you can test and evidence.
High-impact action modules: outbound comms and data egress.
Modules are additive. Start with psCore + psPolicy + one action module (psOutbound or psEgress).
ProofStream plugs into the systems you already use. Customer-hosted by default, with exports to your security stack.
Start with one connector, expand as needed.
Ideal for “agent closes tickets” governance.
Evidence belongs in your systems of record.
ProofStream is designed to be agent-framework-agnostic. MCP can be one integration path, but it’s not required. The control point is the executed action (tool call), regardless of how the agent plans or reasons.
Customer-hosted by default: your data stays in your environment.
No. Guardrails often focus on content. ProofStream governs executed actions: tool calls, outbound comms, and data egress — with approvals and audit-ready evidence.
No. ProofStream is designed to be agent-framework-agnostic. MCP can be one integration path, not a requirement.
No. ProofStream produces structured evidence and exports it into your existing SIEM/GRC workflows. It’s the runtime evidence mechanism for agent actions.
Start with irreversible external actions: outbound communications and data egress. These are high-impact, easy to define policy for, and immediately auditable.
If your organization is deploying agents that can act, we’ll help you govern them — and prove it.
Tell us what actions your agents can take today (email, Slack/Teams, uploads, ticket updates, etc.). We’ll share a recommended ProofStream baseline (psCore + psPolicy + one action module) and a customer-hosted deployment path.
Note: “audit-ready” means you get attributable actions, policy decision records, approvals/exceptions, and exportable evidence bundles. It does not replace full model risk management or training data governance.
Built on the ACR Framework™ · Customer-hosted by default · Designed for enterprise auditability