For AI vendors
Your agent works. The deal stalled in security review. Unstall it.
The day a CISO had to vet your AI application, a one-week review ran eight. kolm audits the agent and everything it touches from the logs you already have, and hands you a signed evidence report your buyer verifies offline, against your own key. The review compresses back to days.
A CISO will not take your word for it.
The contract sits in legal. The champion goes quiet. Nothing is wrong with your product. There is just no way to prove the application is safe except your say-so, and a security team does not sign off on say-so.
Put your own pipeline through the math: estimate what a stalled review costs.
Your situation, what kolm does, the proof to check.
One line of sight from the stalled deal to the signed artifact the buyer can verify. Each step carries the concrete output it produces.
The CISO wants proof
Your agent works, but a security team will not sign off on a questionnaire. The six-figure deal is parked in review while they ask for something testable.
4 to 8 wksa from-scratch reviewAudits the agent, signs the result
kolm reads the logs you already have, runs the controls across permissions, audit trail, egress and injection, and seals the findings into one signed report.
Ed25519one signed reportThe buyer verifies it offline
They open the report, check the signature against your public key in their own browser, and trace each finding to a control they enforce. No kolm server in the path.
Daysreview compressesA questionnaire no longer clears it.
A form was enough when software was deterministic. An agent decides at runtime, so the reviewer wants something they can check, not read.
More access than the job needs
The first thing a reviewer flags, and a form cannot un-flag it.
In the signed sample, the support agent grants 10 tools, uses 4, on one shared key.A trail nobody can trust
If the record of what your agent did can be edited after the fact, it is not evidence.
Reviewers want it append-only and hash-chained, not asserted.Say-so does not scale
Every hand-written answer is work the buyer's team must take on faith or redo.
They want proof they can run themselves, against a key, with no portal.What you hand the buyer.
One canonical object (bytes in a fixed order)A canonical object is the report serialized in one fixed byte order, so the same content always produces the same bytes. That is what the signature covers, which is why editing any field breaks the seal., signed with Ed25519 (a public-key signature)Ed25519 is a public-key signature scheme. You sign with a private key; the buyer confirms the bytes with your matching public key, with no server in the loop., mapped to the controls the review group already cites. They verify it offline against your public key and trace every finding to a standard they enforce.
Canonical payload
Edit one field, the seal breaks
Key-sorted, whitespace-free JSON. The signature covers the exact bytes, so a downgraded finding or an inflated score is self-evident the instant the buyer checks.
Self-contained
Your key travels in the report
Signature and public key ship together. The verifier runs offline in the buyer's browser and needs nothing from us.
Crosswalk
Their vocabulary, not yours
Every finding maps to the control your buyer names: SOC 2, ISO 42001, NIST AI RMF, EU AI Act, OWASP, MITRE ATLAS.
| Control | What it checks | Maps to |
|---|---|---|
| ASR-1 Least privilege | Scopes the agent holds versus the scopes it uses | SOC 2 CC6 · OWASP ASI03 · NIST MANAGE-1 |
| ASR-2 Audit trail | Append-only, hash-chained, retained activity log | EU AI Act Art.12 · SOC 2 CC7 |
| ASR-3 Data egress | Destinations, approved sub-processors, redaction | OWASP LLM02 · EU AI Act Art.10 |
| ASR-4 Injection | Instruction hijack, indirect injection, guardrail bypass | OWASP LLM01 · MITRE ATLAS |
| ASR-5 Provenance | Model and dependency provenance | ISO 42001 · NIST MAP-1 |
| ASR-6 Evidence | Signed, logged, offline-verifiable report | SOC 2 CC7 · ISO 42001 |
Scope is contractual. Permission posture, redaction and audit-trail integrity are assessed. Injection is tested and reported, not warranted.
Minutes for the scan. Days for a signature with a name on it.
We are candid about which clock needs a person.
The machine clock · minutes
No human waits here
Permission reads, audit-trail and egress checks, the prompt-injection battery, control-mapping and signing are compute. Nobody in the loop, re-run on every deploy.
The human clock · days
A name behind the result
When a CISO wants a person to stand behind the finding, a named co-signer reviews and signs alongside the math. Days, bounded by an SLA, against the four to eight weeks a from-scratch review takes.
Agent logs
Import or sidecar. The same logs you already keep, read in without a rewrite.
logsinAudit run
Controls ASR-01 .. ASR-08 run across permissions, audit trail, egress and injection.
ASR-01..08controlsSigned report
One Ed25519 envelope. Same logs in, same signature out, every run.
Ed25519envelopeVerify
The buyer checks the bytes against the embedded public key, offline.
offlinecheckThe crypto proves the bytes were not altered. The name proves a person reviewed them. Most deals clear on the automated report alone. How this differs from Vanta, Drata and runtime guardrails.
Start free. Sign when the deal needs it.
Every fee is flat and listed in full. No quote, no per-seat meter, no contingency.
Clear the review in days.
Run the scan tonight. Hand the reviewer signed evidence tomorrow.
Caveats: Scope is contractual. Permission posture, redaction and audit-trail integrity are assessed. Injection is tested and reported, not warranted.