For banks, insurers, and health systems running AI on their own weights. Every decision seals into a signed receipt an examiner can recompute bit-for-bit — offline, years later, with no access to your infra. Reconstructable evidence, not a log you're asked to trust.
Capabilities
vitnify isn't detection. It gives you the primitives to contain an agent, reproduce exactly what its model computed, and prove it to anyone — the receipt is an execution certificate under the hood.
Scope every tool an agent may touch. Ungranted actions are structurally unreachable — even to a fully compromised agent.
Re-run any past run and get the identical result. Reproduce an incident exactly, for debugging or forensics.
Bind the model's exact computation, every tool call, the results, and their order into one tamper-evident, signed object.
Anyone can verify a receipt with no model, no network, and no secret. Integrity is third-party checkable.
The recompute reproduces exactly across CPU vendors and instruction sets — and on a purpose-built GPU kernel, verified bit-for-bit on Apple (Metal) and NVIDIA (CUDA). Your proof isn't tied to one machine.
Wrap existing LangGraph and MCP agents. No changes to your agent logic, no new runtime to adopt.
Validated: three models across two architecture families reproduce bit-identically on Apple, Arm, Intel, and AMD CPUs — and a purpose-built GPU kernel reproduces the same bits on Apple (Metal) and NVIDIA (CUDA) — and hold against an 18-case attack matrix — detailed in the paper.
Open source
# wrap any LangGraph or MCP agent from vitnify import Session with Session(policy="tickets.yaml") as s: result = s.run(agent, task) # -> a signed, offline-verifiable receipt s.receipt.verify() # True s.receipt.recompute() # bit-for-bit, any CPU
Built for regulated AI
Regulated teams feel it first — an examiner won’t accept a screenshot of a log. The same receipt then earns its keep anywhere the honest answer to “what did the agent actually do?” has to survive scrutiny, weeks or months later, without taking anyone's word for it.
A bank, insurer, or health system runs open-weight models (Llama, Qwen) on its own hardware — data never leaves — and still has to hand an examiner a record. Reproduce the exact computation offline, years later, by someone with no access to your infra: the reconstructable evidence EU AI Act Article 12 and SR 11-7 ask for, not a screenshot of a log.
reproduce, don't trustWhen an agent run goes wrong, reconstruct it bit-for-bit from its receipt instead of reverse-engineering what happened from partial logs. Debug the actual run, not an approximation of it.
reproduce, don't trustOne agent hands work to another. Instead of trusting it, the receiver verifies the receipt offline — no shared secret, no call home — and only builds on results it could reproduce itself.
reproduce, don't trustA tamper-evident audit trail where one changed byte breaks the seal. Keep receipts as durable proof that a control was actually enforced at the wall — not merely written to a log that could be edited.
reproduce, don't trustPublish a result a skeptic can check, not just believe. A small local model on a CPU means anyone — including an adversarial reviewer who suspects cherry-picking — reproduces the exact tokens and the signed digest themselves. Reproducibility disputes end at the receipt, not in an argument.
reproduce, don't trustVerification needs no model, no network, and no secret, and the engine is a no_std core with no runtime to trust. Built for closed and air-gapped networks: a receipt made inside the boundary is checked inside it — or outside, with nothing but the bytes.
reproduce, don't trust