PILLAR · GOVERN & PROVE
Evidence a regulator can check without trusting you
Verify signed, chained decisions with exportable evidence.
HMAC-SHA256
Signed at capture
Daily roots
Anchored off host
8 frameworks
Pre-mapped controls
Exit codes
Verifier runs in CI
Signing chain
A tamper-evident chain, not just a log
Signed at capture
Each emitted SDK or gateway decision record is HMAC-SHA256 signed before delivery; supported policy changes join the server-side sealed evidence stream.
Loss is declared, not hidden
The optional atomic outbox persists and replays signed records, while other sender-visible loss is declared with gap markers and pre-persistence death remains outside the guarantee.
A chain, not a pile
Each signature includes the previous event's signature, so altering one breaks the chain and deleting one gaps the sequence.
Server countersignature
Ingest re-signs every accepted event with a server-held key and rejects replays, so a compromised client cannot fabricate records.
Inside a record
What one governed decision leaves behind
Delete or alter any event and the signatures stop matching. Tampering is detectable without trusting obsvr.
Anchoring
Proof that outlives the host
Qualified WORM retention
Hosted deployments can anchor roots in S3 Object Lock governance mode, with authorized-principal bypass disclosed and compliance mode available by agreement.
Daily roots, anchored twice
Each day's events are hashed into a Merkle tree whose root is committed to S3 Object Lock and a dedicated GitHub repo.
Ed25519-signed roots
Anyone can verify a daily root with the published public key alone, with no obsvr credential and no obsvr backend in the loop.
Point-in-time provenance
The resolved model snapshot and policy version are hash-sealed into the daily root, so what was live last quarter stays provable.
Independent verification
Nobody has to take our word for it
obsvr-verify-bundle
The standalone verifier recomputes the Merkle root offline and checks the Ed25519 signature with the public key alone.
obsvr-verify, in the SDK
Checks the client chain and separates two things a single pass/fail hides: a record that was altered, and one that is intact but incomplete.
Verification travels with the evidence
The script, daily roots, and anchoring status travel inside the evidence package, so your auditor confirms the chain without calling you.
Prove what was live. Months later.
$ obsvr-provenance --at 2026-01-14
model gpt-4o-2024-08-06 · resolved snapshot, hash-sealed
policy c9a1f3e · hash-sealed in the daily root
✓ sealed by anchored root · roots/…/2026-01-14.jsonCompliance
The chain is the compliance story
Security posture