The agent evidence layer

Your AI will be questioned.
Verdict proves what happened.

Cryptographically sealed evidence records for autonomous AI agents, built for regulators, insurers, auditors, and court.

Your logs are not evidence.
Verdict is.

Run an Agent Acceptance Test →Verify a Live Record →

Get a defensible go / no-go before your agent ships.

Not a mockup — a cinematic of the real flow, ending on a genuine Sigstore Rekor entry. Seal a fact yourself →

+327%
AI-central US federal cases in one year, 22 → 94
DOAR · April 2026
82%
US P&C policies on ISO forms · AI exclusion endorsements available since Jan 1, 2026
Verisk / ISO
23%
Organizations already scaling AI agents in production
McKinsey State of AI · 2025
€35M
or 7% of global turnover · EU AI Act top-tier penalty, powers live since Aug 2, 2025
Reg. (EU) 2024/1689 · Art. 99
The Reading of the Evidence

Three forces.
One defendant.
You.

Jan 1, 2026 · ISO / Verisk
CG 40 47, CG 40 48 and CG 35 08 go live.Elective endorsements that carve liability "arising out of" generative AI out of the standard commercial general liability form. Whether one sits on your policy is a question for your schedule of forms, not an assumption in either direction.
Apr 14, 2026 · N.D. Cal.
Federal court: hosting is not a defense when the tool composes the claim.A platform whose generative AI holds "ultimate authority" over assembled content may be the maker of a fraudulent statement under Rule 10b-5. Liability precedent. Not theory.
Aug 2, 2026 · EU
The Commission's power to fine general-purpose AI providers under the AI Act takes effect. Penalty powers for the rest of the Act have been live since August 2025, up to €35M or 7% of global turnover. No fine has been confirmed issued yet. The instrument exists before the first headline.
Aug 4, 2026 · 9th Cir.
Amazon v. Perplexity decides who "accessed" a site from execution architecture, not agency doctrine. The agent's requests originated on the user's machine, so the user acted. The panel flagged that a more autonomous architecture could come out differently. Field Notes No. 01 →
Sep 4, 2026 · Reuters
OpenAI agents used a dormant German wiki as a message board for nine weeks. About 18,000 posts between May 11 and July 13; moderators deleted the pages; outside researchers rebuilt them from the wiki's preserved edit history. The record that survived was one the operator did not control. Field Notes No. 02 →
Now
You are here. Everything above has already happened. The next line is a deadline, not a headline.
Dec 9, 2026 · EU · pending
Product Liability Directive transposition deadline. Software and AI become strict-liability products in national law. A court can order disclosure of technical records, and failure to produce them triggers a presumption of defectiveness. "The model did it" stops being a defense and starts being an admission.
The Whitespace

Logs aren't evidence.
Evidence is produced
for the adversary.

CapabilityObservability
LangSmith, Arize, Datadog
Governance
Zenity, Proofpoint
VERDICT
Evidence Layer
Tamper-evident chain of custody× Mutable logs× Mutable logs Merkle + Rekor anchor
Public third-party verifiability× Vendor-held× Vendor-held Sigstore transparency log
FRE 902(13)/(14) certification support× No× No Designed for certification
Insurer-grade submission schema× Not supported× Not supported Armilla · Testudo · aiSure
Insurer underwriting credits× No× No Built to support
Open specification× Proprietary× Proprietary Apache 2.0 · SER v0.1
Hash-preserving redaction× Incompatible× Partial Selective disclosure primitive

Armilla, Testudo and aiSure name the insurer schemas a Sealed Evidence Record renders into. They are export targets, not partnerships: Verdict is not an endorsed vendor or panel partner of any carrier. Observability and governance tools are named for what they are built to do; both are often run alongside Verdict.

The Architecture

Three boundaries.
Everything between them clean.

01
Intercept

Every tool call. Every model decision. Every gate.

MCP proxy + OpenTelemetry collector + SDK wrappers for LangGraph, CrewAI, AutoGen, Claude Code. Heterogeneous frameworks normalize to one Evidence Event stream.

EmitsNormalized Evidence Event
02
Seal

Hash-chained. Merkle-rooted. Rekor-anchored.

SHA-256 content-addressing + RFC 6962 Merkle construction + Sigstore Rekor transparency log anchoring + Ed25519 HSM-bound signing. Tampering becomes computationally detectable. Forever.

EmitsSigned Sealed Evidence Record
03
Output

SOC 2. EU AI Act. FRE 902. Underwriting.

One SER renders into whatever the audience needs — SOC 2 auditor package, EU AI Act Article 12 dossier, Armilla/Testudo/aiSure insurer submission, litigation hold export. Zero rework.

EmitsReady-to-submit artifact
Read the full technology spec →
The Moat

Four compounding reasons
you can't be killed.

01

Standard Ownership

SER v0.1 is Apache 2.0. Open. Forever. Once three insurers accept SER, the format becomes the de facto standard. Every observability vendor exports it, every governance vendor ingests it, every enterprise agent needs it. Verdict runs the reference implementation, owns the certification program, convenes the Coalition. The standard IS the category.
02

Insurance Distribution

Carriers began shipping standardized GenAI exclusions in January 2026. Gartner (Apr 2, 2026): by 2030, P&C insurers will mandate strong AI risk controls for affirmative AI liability coverage. What prices the risk back in is loss-quality evidence — exactly what a Sealed Evidence Record is. Built to support underwriting credits, affirmative AI coverage, and faster claims resolution. Accountability priced as an asset, from the underwriter's side of the ledger.
03

Incident Data Flywheel

Every sealed incident feeds a precursor-pattern detection model. Armilla can't build this — no runtime data. LangSmith won't — wrong ICP. Only the evidence layer operator sees every incident at sealed fidelity. The flywheel compounds with every deployment until the detection model becomes the defensibility moat no competitor can replicate.
04

Evidence Gravity

After 18 months of sealed history, Verdict is the system of record. The SER spec is open and exports are portable — but certification, insurer acceptance, policy intelligence, and deployment history don't port. Continuity is the moat, not captivity. Deeper roots than Splunk or Datadog — without the hostage clause.
Surface the Instruments

Priced against the liability,
not the log.

Comply

from $0free · Growth $999 · Scale $4,999/mo
  • EU AI Act Annex IV auto-generation
  • Conformity + CE-marking readiness
  • Article 73 incident auto-reporting
  • EU data residency · SCC Module 2
  • Public Rekor anchor
  • Dedicated compliance reviewer (Scale)
Request Access →
Court-ready

Seal

from $2,499per month · Enterprise from $75K/yr
  • FRE 902(13)/(14)-aligned Sealed Evidence Records
  • All insurer schema exports
  • 7-year cryptographic retention (Enterprise)
  • SOC 2 Type II · HIPAA BAA
  • FRE 902(13)/(14) certification template
  • Underwriting-credit support
Request Evidence →

Edge

Customsovereign · air-gapped
  • Everything in Seal Enterprise
  • Model-weight-hash binding
  • On-device SER generation
  • Air-gap anchoring
  • HSM-backed signing
  • Self-hosted / sovereign deploy
Talk to Edge →

Services, any line: Agent Acceptance Test $7,500 · Regulated Dossier $15,000 · Evidence Readiness Retainer $3,000/mo · See what gets tested →

The Finding

When the first billion-dollar AI liability verdict lands —
and it will —
Verdict is the sealed evidence the case turns on,
the regulator accepts,
and the underwriter prices.

One sealed record. Three audiences.
We are the Verisk of the agentic economy.

Request a sealed record.

Tell us about your agent footprint. We'll send a real Sealed Evidence Record from a deployment matching your shape — within one business day.

We respond within one business day. No newsletter. No drip.