For GRC & compliance leads
Evidence your auditor can verify. Not a binder they must trust.
Your AI systems make thousands of decisions a day, and the audit asks for proof of how they behaved. AnchorGate sits in the request path and signs every decision as it happens — so the evidence exists because the traffic flowed, not because someone remembered to collect it.
The problem
Why after-the-fact evidence keeps failing you
The screenshot problem
Quarterly screenshots and CSV exports are evidence assembled after the fact — mutable, unverifiable, and graded L1 on any maturity ladder. They prove someone made a slide, not that a control ran.
Tools that were never in the path
GRC platforms manage documents, attestations, and workflows — from outside the systems they describe. They can hold your AI policy; they cannot tell you whether last Tuesday’s traffic followed it.
Agents don’t fill in questionnaires
Agentic workloads act — they call tools, touch data, and chain decisions. When one of those chains goes wrong, “what exactly happened?” needs an answer at the event level, with the policy version that applied.
What the gate gives your program
Signed Evidence
Every decision signed with ECDSA P-256 over RFC 8785 canonical JSON, appended to an immutable ledger, graded L1–L5. An auditor can replay who acted, what was touched, and which policy fired.
Learn more →
Compliance Posture
Control catalogues for the EU AI Act, ISO/IEC 42001, and SOC 2 map directly onto decision evidence. Posture is computed from what the gates actually did — not from a policy document.
Learn more →
Policy Enforcement
A deterministic policy DSL — IF condition THEN redact, alert, or block — compiled, human-approved, and evaluated before a request leaves. No LLM judging LLMs: the same input always gets the same verdict.
Learn more →
Governance & evidence
Evidence that survives the question “says who?”
One export: a manifest of scope and thresholds, the signing public key, and every decision event with its exact canonical payload and signature. Your auditor re-verifies each record offline — against the key, not against our word. If a byte changed anywhere, verification fails. Every record maps onto EU AI Act, ISO/IEC 42001, and SOC 2 control catalogues.
- No dashboard access required — the packet is self-contained.
- Signatures cover a stored canonical payload, so verification never depends on database round-tripping.
- Each record carries its DEMM grade: how far up the ladder from “screenshot” to “reconstructable” it stands.
Design partners
No borrowed logos. A standing offer instead.
AnchorGate is v0.1. We don’t have testimonials yet, and we won’t invent them — what we have is a program for the first teams who put real traffic through the gate. We’d rather build with five serious teams than sell to fifty.
Who it’s for
- Platform and GRC teams facing an EU AI Act, ISO/IEC 42001, or SOC 2 conversation this year
- Agentic workloads — RAG, copilots, MCP tool use — running in regulated environments
- Teams that want enforcement and evidence from the same gate their traffic already crosses
The exchange
You get
- A direct line to the maintainers, not a ticket queue
- Deployment support in your VPC
- Your governance requirements shaping the roadmap
We get
- Your ugliest governance requirements, stated plainly
- Feedback from a real deployment — not a demo
FAQ
What GRC teams ask us
- Can our auditor work with this without an AnchorGate login?
- Yes — that’s the design. The Trust Packet is self-contained: manifest, public key, and every signed event. Your auditor verifies it offline with the CLI, no dashboard access needed. If they do want the dashboard, there’s a read-only auditor role that can check everything and change nothing.
- How does this fit alongside our existing GRC platform?
- Below it, not instead of it. Your GRC platform runs the program — policies as documents, attestations, workflows. AnchorGate produces the runtime evidence layer those programs usually lack: signed records of what AI traffic actually did, mapped to controls. The two meet where your platform ingests evidence.
- We’re not high-risk under the EU AI Act — is this still relevant?
- The Act is one catalogue of three: ISO/IEC 42001 and SOC 2 mappings ship too, and PII redaction, MCP security, and signed evidence are worth having regardless of classification. If your obligations are lighter, the same ledger simply becomes easier to satisfy them with.
Bring one AI workload. Leave with a ledger.
Route a single workload through the gate in verify mode and watch the evidence accumulate — signed, graded, exportable. That’s a better afternoon than another spreadsheet review.
Become a design partneror email hello@anchorgate.ai