Open source · provable AI for regulated industries

Prove what your agent actually did.

For banks, insurers, and health systems running AI on their own weights. Every decision seals into a signed receipt an examiner can recompute bit-for-bit — offline, years later, with no access to your infra. Reconstructable evidence, not a log you're asked to trust.

▸
input
chat · API
event · agent
wrapped by vitnify
the model runs, step by stepidle
vitnify records the exact logits at every step — not just the token the model picked — so the whole run recomputes bit-for-bit, and every tool call is allowed or blocked at the wall.
Receipt
········
bit-for-bit
sealing…
then, independently —
Examinertheir hardware · 2 yrs later · no access to your infra
re-runs from the receipt alone…CPU · Apple · NVIDIA
········
one run in — one receipt out
Contain what an agent may do Replay any run exactly Certify what happened Verify offline, no secrets drop-in: LangGraph · MCP

Capabilities

Everything a run needs to be provable.

vitnify isn't detection. It gives you the primitives to contain an agent, reproduce exactly what its model computed, and prove it to anyone — the receipt is an execution certificate under the hood.

⛬

Capability containment

Scope every tool an agent may touch. Ungranted actions are structurally unreachable — even to a fully compromised agent.

↻

Deterministic replay

Re-run any past run and get the identical result. Reproduce an incident exactly, for debugging or forensics.

◈

Bit-for-bit receipts

Bind the model's exact computation, every tool call, the results, and their order into one tamper-evident, signed object.

✓

Offline verification

Anyone can verify a receipt with no model, no network, and no secret. Integrity is third-party checkable.

≡

Runs bit-identical on any CPU

The recompute reproduces exactly across CPU vendors and instruction sets — and on a purpose-built GPU kernel, verified bit-for-bit on Apple (Metal) and NVIDIA (CUDA). Your proof isn't tied to one machine.

⧉

Drop-in integration

Wrap existing LangGraph and MCP agents. No changes to your agent logic, no new runtime to adopt.

Validated: three models across two architecture families reproduce bit-identically on Apple, Arm, Intel, and AMD CPUs — and a purpose-built GPU kernel reproduces the same bits on Apple (Metal) and NVIDIA (CUDA) — and hold against an 18-case attack matrix — detailed in the paper.

Open source

Built in the open. Yours to verify.

# wrap any LangGraph or MCP agent
from vitnify import Session

with Session(policy="tickets.yaml") as s:
    result = s.run(agent, task)

# -> a signed, offline-verifiable receipt
s.receipt.verify()      # True
s.receipt.recompute()   # bit-for-bit, any CPU
  • LicenseApache-2.0 — open core, no lock-in.
  • Enginevitni-tensor, a no_std Rust crate. 103 unit tests, 5 quant kernels + F32.
  • IntegrationsLangGraph and Model Context Protocol, no agent-logic changes.
  • Signinged25519 self-verifying receipts; TPM optional.
  • PaperReconstructable Execution Certificates for Tool-Using AI Agents.

Built for regulated AI

When a log isn’t evidence.

Regulated teams feel it first — an examiner won’t accept a screenshot of a log. The same receipt then earns its keep anywhere the honest answer to “what did the agent actually do?” has to survive scrutiny, weeks or months later, without taking anyone's word for it.

§

Regulated agents on your own weights

A bank, insurer, or health system runs open-weight models (Llama, Qwen) on its own hardware — data never leaves — and still has to hand an examiner a record. Reproduce the exact computation offline, years later, by someone with no access to your infra: the reconstructable evidence EU AI Act Article 12 and SR 11-7 ask for, not a screenshot of a log.

reproduce, don't trust
⟲

Incident forensics

When an agent run goes wrong, reconstruct it bit-for-bit from its receipt instead of reverse-engineering what happened from partial logs. Debug the actual run, not an approximation of it.

reproduce, don't trust
⇄

Agent-to-agent trust

One agent hands work to another. Instead of trusting it, the receiver verifies the receipt offline — no shared secret, no call home — and only builds on results it could reproduce itself.

reproduce, don't trust
⊞

Compliance evidence

A tamper-evident audit trail where one changed byte breaks the seal. Keep receipts as durable proof that a control was actually enforced at the wall — not merely written to a log that could be edited.

reproduce, don't trust
≟

Eval & benchmark integrity

Publish a result a skeptic can check, not just believe. A small local model on a CPU means anyone — including an adversarial reviewer who suspects cherry-picking — reproduces the exact tokens and the signed digest themselves. Reproducibility disputes end at the receipt, not in an argument.

reproduce, don't trust
⊘

Air-gapped & defense

Verification needs no model, no network, and no secret, and the engine is a no_std core with no runtime to trust. Built for closed and air-gapped networks: a receipt made inside the boundary is checked inside it — or outside, with nothing but the bytes.

reproduce, don't trust

Stop hoping your logs are complete.
Start proving it.