An AI agent read a medical record, moved money, deleted a file, or was refused. Somewhere there is a log. inferX turns that log into evidence a court can use: independently re-verified, sorted into the facts a legal finding needs, graded by how far it can be trusted, and re-sealed so the work itself is provable.
The AI cybersecurity company. Authors of the Agent Audit Trail standard and AgentPass.
Reproducible legal-accountability typing and trust-grading of machine-generated evidence.
Agent Audit Trail for the record, Typed-Evidence Record for the evidence. Anyone can implement either format.
Recording what an agent did, proving what the record establishes, and taking it to court are three different jobs. inferX does the second. It sits on top of the record standard and underneath legal practice, and it does not pretend to be either.
Signed, hash-chained, offline-verifiable records of what an AI agent did: who acted, on what, under which authority, with which model, with or without a human. Proves a record was not altered. Does not say what it legally means. aat-standard.org
Re-verifies every record, renders it as a plain legal narrative, sorts it into the fifteen facts a finding turns on, grades the source A, B or C, flags anything uncertain, and re-seals the result as a new signed record. Produces the evidence pack in the Typed-Evidence Record format. Does not interpret law.
Admissibility, chain of custody, expert evidence, presentation. inferX output is designed as the input to that work: every fact carries its source hash, its grade and its reproducibility proof, so the legal layer starts from verified material rather than a screenshot.
The ledger records it. inferX sorts and proves it. Counsel takes it to court.
The order matters. Nothing is sorted until it has been verified, nothing is graded until it has been sorted, and nothing leaves the pipeline unsealed. The same input produces byte-identical output, which is what lets the result be challenged and defended.
Recompute each record's hash from its content, verify the signature against the published key, test the chain link to the record before it. Nothing is taken on trust from the producer. An unknown signing scheme is reported as inconclusive, never as tampering.
Each record is rendered as a plain sentence and sorted into a fixed, versioned set of slots: who, whose, what, to what, to whom, which model, under what authority, allowed or refused, human or not, when. These are the slots a legal finding turns on.
Every record is graded A, B or C by how far it can be independently trusted: whether the model is pinned and attested, whether the record is signed and anchored, or whether it is an unattested log, export or screenshot.
Each extracted fact carries a confidence margin. Facts near the decision boundary are flagged fragile for human review. Reproducibility risk is quantified on the page, not hidden behind a single pass mark.
"No human approval on record" is itself a typed, signed fact. The categories a record does not satisfy are listed, so the gaps in an organisation's evidence are as visible as the evidence.
Every typing is wrapped as a new signed, hash-chained record carrying the tool version, the model fingerprint and the source record's hash. The extraction can be verified offline, by anyone, with the public key in the pack.
Questions are answered only from the signed record. Every factual sentence cites a record. If the answer is not in the record, the witness says so. Each answer is signed with the hash of the facts it saw. Runs locally; nothing leaves the machine.
Source records, verification report, typed and graded facts, the re-sealed chain, the public key, the Expert Witness transcript and a method appendix, as a PDF and as machine-readable JSON. Re-verifiable without us.
Signed logs prove a record was not altered. They do not say who acted, on whose behalf, under what authority, with which model, or whether a human was involved. Those are the questions a court, a regulator or an insurer asks, and they have to be answered from the record, reproducibly.
Logs, exports and screenshots with no signature and no model pin. They assert provenance; they cannot prove it. inferX makes that visible, and shows the exact upgrade path: record to the standard and you are at B; pin and attest the model and you are at A.
EU AI Act record-keeping and human-oversight duties, financial-services accountability regimes, data-protection authorities and courts all want the same things: who, what, on whose data, under what authority, when, and was a human in the loop. Those are the fifteen categories.
An expert who says "I read the logs" is a witness. A method that produces the same typed output byte for byte on every run, from a pinned tool and a fingerprinted model, is a procedure the other side can repeat. That is the difference between testimony and evidence.
The most consequential finding is often an absence: no human approval, no authority basis, no recipient recorded. inferX records absence as a fact, so an organisation sees its exposure before a claimant does.
Evidence whose claims can only be checked by the party that made them is not evidence. Every pack re-verifies with a public key and nothing else. Not our servers, not your servers, not anyone's goodwill.
Every pack says what was verified, what each record establishes, and how far it can be trusted. Verified, typed, graded. The layout is identical from case to case so differences in a pack are differences in evidence, not in formatting.
Hash reproduced or not, signature valid or not, chain intact or not, and under which scheme. Per layer when a bundle mixes producers. HMAC-sealed sources are reported honestly as integrity-only.
For each record: the legal narrative, the extracted facts with confidence and robustness, the categories not present, the grade and the reason for it, and the full source hashes and provenance carried through verbatim.
The chain of typing records with tool version, model fingerprint and source hashes, the public key to verify it, and the Expert Witness transcript with each answer signed against the facts it was shown.
Signed record, open-weight model pinned by digest, inference configuration present, hardware attestation where available. The decision can be re-run and compared, not just re-read.
Signed and anchored record. The model is hosted or closed, so the act cannot be re-run, but the record is independently verifiable by a third party.
No signature, no model pin. A raw log, an export, a screenshot, pasted text. inferX still types it, so the reader sees what it claims, but it needs corroboration.
What the format is not. inferX types records into legal categories and proves the typing. It does not interpret law, judge admissibility, assess weight or replace a lawyer. Reproducible does not mean correct. Those judgements belong to the legal layer, which this format is built to feed.
inferX reads records produced to the standard and the exports of the systems that implement it, and it degrades gracefully: raw text is accepted and typed, honestly graded C.
Five steps, all inside your own cloud. Nothing is added to the agent's request path and nothing leaves your boundary. You end up with facts your legal counsel can use under their own methodology.
AgentPass for AI agents and tool calls, or the Trust Gateway for sensors and industrial systems. Every action an agent takes, and every refusal, becomes a signed record with the agent's identity, its trust level and whether a human approved it. Your agents and tools do not change.
The AgentPass Evidence ledger runs in your cloud as the single place records are sealed: hashed, signed with your KMS or HSM key, chained in order, stored write-once. It is the court-grade evidence ledger. Its exports are inferX-compatible by design.
Export the records that relate to a question, an incident, an audit or a claim. One file, with the public keys inside it, that anyone can verify without access to your systems.
inferX runs in your cloud too. It re-verifies every record, sorts each one into the facts a legal finding needs, grades how far each can be trusted, flags anything uncertain, and seals the result so the work itself is provable.
The pack goes to your legal counsel, who apply their own methodology to admissibility, procedure and presentation. They start from verified facts with a known provenance and grade, which is what lets them support the case rather than reconstruct it.
Gateway, ledger and inferX are all delivered as software and run inside your own environment. "Nothing left the building" is a provable statement, not a promise.
inferX is licensed to organisations that need defensible evidence of what their AI agents did: regulated enterprises, critical infrastructure operators, law firms and forensic practices, and the platforms that serve them. Evaluation deployments are available.
We reply with a scoped evaluation, the deployment container, and a commercial proposal. Standard terms cover a per-deployment licence with support and model updates; enterprise and partner terms are available.
contact@agentsign.dev →For legal practices and methodology partners we offer co-branded packs and a hand-off designed around your procedure.
We publish the formats at the IETF so that evidence outlives any vendor, including us. The Typed-Evidence Record is the flagship: it defines what inferX produces. The Agent Audit Trail is what it consumes. We license the method in between.
draft-sharif-typed-evidence-record, IETF Internet-Draft, revision 00 published 3 October 2026. The format of what inferX produces: the fifteen legally operative categories, the trust grade, the verification verdict and the re-sealed record, so any party can read, verify and build on a pack without inferX.
draft-sharif-agent-audit-trail, an IETF Internet-Draft series by Raza Sharif, CyberSecAI Ltd, with independent implementations. The record layer inferX consumes. Home: aat-standard.org.
Method and system for reproducible legal-accountability typing and trust-grading of machine-generated evidence. CyberSecAI Ltd. Further applications across the AgentPass evidence stack are filed in the United Kingdom with international filings in progress.
CyberSecAI™ is a registered trade mark application of CyberSecAI Ltd (UK00004362551, classes 9 and 42). AgentPass™ and inferX are marks of CyberSecAI Ltd. The LATS schema, corpus and method are © 2026 CyberSecAI Ltd and are licensable.
No. It verifies, types, grades and seals. Admissibility, weight and procedure are for counsel and the court. The pack is built to make that work faster and harder to challenge, not to replace it.
No. inferX runs in your cloud or on your hardware with no outbound dependency. The typing model ships inside the container. The Expert Witness runs on a local model. Nothing is sent to CyberSecAI or anyone else.
Yes. Every pack carries the public keys and enough structure to recompute every hash, verify every signature and walk every chain with standard cryptographic tooling. The open aat-mcp verifier does it in one command.
They still go through. HMAC-sealed records are reported as integrity-only: hash and chain reproduced, non-repudiation not available without the shared secret. Plain logs are typed and graded C. The pack makes the upgrade path obvious, and recording to the standard is the first step up.
Yes. Fixed compute configuration, pinned tool version, fingerprinted model, no sampling. The same record produces byte-identical typed output on every run, and the pack records the fingerprints that let a later run be compared.
The fifteen categories are jurisdiction-neutral: attribution, provenance and authority are what every regime asks about. They map directly onto EU AI Act record-keeping and human-oversight duties, data-protection accountability, and financial-services accountability regimes. Jurisdiction-specific interpretation is the legal layer's job.
The platform and the AgentPass and MCP plugin are available to licensees today. A command-line client that talks to a licensee's own inferX deployment is on the roadmap.