Evidence of what your AI agents sent and received

Trust Layer is a proxy between your agents and the APIs they call. It fingerprints each request and response, signs the record, and anchors it with an independent timestamping authority and the Sigstore public log. An auditor can check those anchors without taking our word for it.

Free tier: 500 proofs a month, no credit card. Open source (MIT).

Proof record prf_20260914_194825_a747d0
Spec version3.1
Issued2026-09-14T19:48:25Z
Upstreamcorpus.arkforge.tech (HTTP 200)
Request hashsha256:2058278a1e29e24e…
Response hashsha256:387dcaed3079c39d…
Chain hashsha256:842240b6d39d33b0…
Signatureed25519:AVSK8y8_hafkhgLR… (ArkForge key)
Batch anchorleaf 34 of 35, root sha256:1a575a9cde65…
RFC 3161 tokenfreetsa.org, on the batch root
Rekor log index2834496977, on the batch root

How a proof is built, and who can check each part

Four steps. The first two happen while the call is in transit. The last two cover a batch of proofs and land within 10 minutes; each proof carries its path to the anchored batch root.

StepWhat happensWhat it establishesCheckable without ArkForge
1. Fingerprint SHA-256 of the request and the response. Each field gets its own commitment, and the chain hash is their Merkle root. The record is internally consistent. Yes, but on its own it proves little: a forged proof can be consistent too.
2. Signature Ed25519 signature over the chain hash, with ArkForge’s key published at /.well-known/did.json. ArkForge issued this proof. No. It relies on ArkForge’s key.
3. Timestamp The batch root is sent to an RFC 3161 authority: FreeTSA, with DigiCert and Sectigo as fallbacks. The proof existed at that time. Yes, with the authority’s certificate.
4. Public log The batch root is recorded in Sigstore Rekor, an append-only log run under the Linux Foundation. The record was published at that time and has not been rewritten since. Yes, on rekor.sigstore.dev.

Until its batch closes, a proof carries steps 1 and 2 only, so ArkForge alone vouches for it during that window.

What your logs cannot show

A log proves you recorded something. It is written by the party whose conduct is in question, on a clock that party controls.

What a proof does not establish

These limits are part of the specification. Read them before you rely on a proof.

Read the proof specification

One HTTP call. No SDK.

Send the call to the proxy with the target URL and the payload. The upstream response comes back with the proof next to it.

Request
curl -X POST https://trust.arkforge.tech/v1/proxy \
  -H "X-Api-Key: $ARKFORGE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "target": "https://api.example.com/v1/run",
    "payload": {"task": "analyze", "text": "hello"}
  }'
Response (abridged)
{
  "service_response": {
    "status_code": 200,
    "body": { … }
  },
  "proof": {
    "proof_id": "prf_20260914_194825_a747d0",
    "spec_version": "3.1",
    "hashes": { "request": …, "response": …, "chain": … },
    "arkforge_signature": "ed25519:…",
    "batch_anchor": { "status": "pending" },
    "verification_url": "https://trust.arkforge.tech/v1/proof/…"
  }
}

To check a proof yourself, run the standalone verifier (Python standard library and openssl): python3 verify_proof.py prf_20260914_194825_a747d0. How verification works.

For compliance and risk teams

CISOs, DPOs and legal teams at EU-regulated companies who need records of AI system behaviour for internal audits, regulatory requests or contractual disputes.

Each anchored proof carries an RFC 3161 token and a Rekor log index that an auditor checks directly with those services. Keep the proof JSON with your records: those two anchors remain checkable even if ArkForge stops operating.

For engineering teams

The free tier includes 500 proofs a month. Integration is one HTTP call per request: no SDK, no new dependency, no agent rewrite.

Trust Layer is not tied to a model or a provider. It certifies calls to OpenAI, Anthropic, Mistral, internal APIs and any HTTP endpoint in the same chain.

Start with the free tier

500 proofs a month, no credit card. Paid plans from €29 a month.