For AI vendors

Your agent works. The deal stalled in security review. Unstall it.

The day a CISO had to vet your AI application, a one-week review ran eight. kolm audits the agent and everything it touches from the logs you already have, and hands you a signed evidence report your buyer verifies offline, against your own key. The review compresses back to days.

Ed25519 signed · verifies offline No kolm server in the trust path SOC 2 · ISO 42001 · NIST AI RMF
01 / The stall

A CISO will not take your word for it.

The contract sits in legal. The champion goes quiet. Nothing is wrong with your product. There is just no way to prove the application is safe except your say-so, and a security team does not sign off on say-so.

4 to 8 wks a from-scratch agent review, once a CISO is in the loop
1 deal six figures, agreed in principle, parked in review
Days the same review when you walk in with signed, verifiable evidence

Put your own pipeline through the math: estimate what a stalled review costs.

01b / Your path

Your situation, what kolm does, the proof to check.

One line of sight from the stalled deal to the signed artifact the buyer can verify. Each step carries the concrete output it produces.

YOUR PATH / STALL TO SIGNATURElive
Your situation

The CISO wants proof

Your agent works, but a security team will not sign off on a questionnaire. The six-figure deal is parked in review while they ask for something testable.

4 to 8 wksa from-scratch review
What kolm does

Audits the agent, signs the result

kolm reads the logs you already have, runs the controls across permissions, audit trail, egress and injection, and seals the findings into one signed report.

Ed25519one signed report
Proof to check

The buyer verifies it offline

They open the report, check the signature against your public key in their own browser, and trace each finding to a control they enforce. No kolm server in the path.

Daysreview compresses
OUTCOME review compresses to days verified
02 / Why the form fails

A questionnaire no longer clears it.

A form was enough when software was deterministic. An agent decides at runtime, so the reviewer wants something they can check, not read.

highASR-1 · least privilege

More access than the job needs

The first thing a reviewer flags, and a form cannot un-flag it.

In the signed sample, the support agent grants 10 tools, uses 4, on one shared key.
highASR-2 · audit trail

A trail nobody can trust

If the record of what your agent did can be edited after the fact, it is not evidence.

Reviewers want it append-only and hash-chained, not asserted.
mediumASR-6 · evidence

Say-so does not scale

Every hand-written answer is work the buyer's team must take on faith or redo.

They want proof they can run themselves, against a key, with no portal.
03 / The report

What you hand the buyer.

One canonical object (bytes in a fixed order)A canonical object is the report serialized in one fixed byte order, so the same content always produces the same bytes. That is what the signature covers, which is why editing any field breaks the seal., signed with Ed25519 (a public-key signature)Ed25519 is a public-key signature scheme. You sign with a private key; the buyer confirms the bytes with your matching public key, with no server in the loop., mapped to the controls the review group already cites. They verify it offline against your public key and trace every finding to a standard they enforce.

kolm · readiness report signed · ed25519
Support & billing agents asrr_sample
findings13 · 7 high · 4 medium · 1 low · 1 info
high
Over-permission on a shared key
support-agent on shared-prod-key grants 10 tools, uses 4
ASR-1 least privilege → SOC 2 CC6
+ 12 more findings, each inside the signed object
signatureed25519:9kWQBu5kLlJ8qSaPgyu39K335ewB8hS8-ckKlcB9i9IDhxmYf0ojWdqJfvECIIYh89ljitxhSq4MIV1gaG9aDw
key410302c93becdcc3...✓ verifies offline

Canonical payload

Edit one field, the seal breaks

Key-sorted, whitespace-free JSON. The signature covers the exact bytes, so a downgraded finding or an inflated score is self-evident the instant the buyer checks.

Self-contained

Your key travels in the report

Signature and public key ship together. The verifier runs offline in the buyer's browser and needs nothing from us.

Crosswalk

Their vocabulary, not yours

Every finding maps to the control your buyer names: SOC 2, ISO 42001, NIST AI RMF, EU AI Act, OWASP, MITRE ATLAS.

ControlWhat it checksMaps to
ASR-1 Least privilegeScopes the agent holds versus the scopes it usesSOC 2 CC6 · OWASP ASI03 · NIST MANAGE-1
ASR-2 Audit trailAppend-only, hash-chained, retained activity logEU AI Act Art.12 · SOC 2 CC7
ASR-3 Data egressDestinations, approved sub-processors, redactionOWASP LLM02 · EU AI Act Art.10
ASR-4 InjectionInstruction hijack, indirect injection, guardrail bypassOWASP LLM01 · MITRE ATLAS
ASR-5 ProvenanceModel and dependency provenanceISO 42001 · NIST MAP-1
ASR-6 EvidenceSigned, logged, offline-verifiable reportSOC 2 CC7 · ISO 42001

Scope is contractual. Permission posture, redaction and audit-trail integrity are assessed. Injection is tested and reported, not warranted.

04 / Two clocks

Minutes for the scan. Days for a signature with a name on it.

We are candid about which clock needs a person.

The machine clock · minutes

No human waits here

Permission reads, audit-trail and egress checks, the prompt-injection battery, control-mapping and signing are compute. Nobody in the loop, re-run on every deploy.

The human clock · days

A name behind the result

When a CISO wants a person to stand behind the finding, a named co-signer reviews and signs alongside the math. Days, bounded by an SLA, against the four to eight weeks a from-scratch review takes.

PIPELINE / MACHINE CLOCKreproducible
Input

Agent logs

Import or sidecar. The same logs you already keep, read in without a rewrite.

logsin
Engine

Audit run

Controls ASR-01 .. ASR-08 run across permissions, audit trail, egress and injection.

ASR-01..08controls
Output

Signed report

One Ed25519 envelope. Same logs in, same signature out, every run.

Ed25519envelope
Buyer

Verify

The buyer checks the bytes against the embedded public key, offline.

offlinecheck
PIPELINE same logs in, same signature out reproducible end to end

The crypto proves the bytes were not altered. The name proves a person reviewed them. Most deals clear on the automated report alone. How this differs from Vanta, Drata and runtime guardrails.

05 / Pricing

Start free. Sign when the deal needs it.

Every fee is flat and listed in full. No quote, no per-seat meter, no contingency.

Scanstart here
Watermarked findings from your own logs, in minutes. Self-serve from the first upload.
Free
Signed Readiness Report
The full audit across permissions, audit trail, egress and injection, Ed25519-signed, with a remediation checklist for every finding. Yours to hand over.
$750one-time
Continuous
Re-attested weekly or on every deploy, behind a stable trust link any buyer can re-check. A point-in-time report goes stale on your next deploy.
$299/$999per month
Reviewed Attestation
A named co-signer reviews and signs beside the math. The deal-closer.
$25,000flat
Design partners this quarter: the Full Readiness audit at its listed $15,000 fixed fee · full pricing · talk to us Run the free scan →

Clear the review in days.

Run the scan tonight. Hand the reviewer signed evidence tomorrow.

Ed25519-signed Offline-verifiable Sample report

Caveats: Scope is contractual. Permission posture, redaction and audit-trail integrity are assessed. Injection is tested and reported, not warranted.