Every framework mapped. Every export signed. Every question answered without a call to the vendor. The AI compliance platform and AI risk management layer for EU AI Act, SOC 2, HIPAA, and SR 11-7 audits.
A quarter of prep. Screenshots, exported logs, Slack threads, manually reconciled spreadsheets. Every artifact is mutable and every record is one keystroke from being wrong.
One signed regulator pack. Cryptographic hash. Framework mapping baked in. The auditor downloads, verifies the signature offline, and closes the engagement.
“You hand them the pack. They verify. You never touch it again.”
Audit stops being a quarterly panic when the evidence is signed at source, the chain-of-custody is immutable, and every action is attributed to a principal. Three of Veldt’s pillars turn compliance from a scramble into a query.
Every action lands in a hash-linked, cryptographically signed evidence chain. Retention runs 25 years. Framework mapping is baked in for SOC 2, ISO 27001, HIPAA, PCI, SR 11-7, NYDFS, MiCA, DORA: 32 frameworks total. The auditor verifies offline.
Evidence →Auditors don’t care about your controls document. They care whether the specific action they’re examining can be tied to a signed principal. Every action, whether human, agent, or service account, carries an unbroken attribution chain.
Authority →The evidence isn’t assembled at audit time. It’s signed at the moment of action, under 50ms. The chain records what was allowed, what was blocked, and what was escalated. The auditor sees the same record you did, when you did.
Runtime Governance →SOC 2, HIPAA breach investigation, NYDFS attestation, on-site bank examination, and the internal-vs-external audit split. Every one of them collapses to the same operation: hand over the signed pack.
The Type II window runs a full year. When the auditor asks about a control operating on March 14, you rebuild the story from four different tools, three ticketing systems, and the memory of an engineer who left in Q3.
The evidence pack covers the whole window. Every control has its signed evidence chain. When the auditor asks about March 14, you export the block, they verify the signature, and move to the next question.
Type II · weeks → days.A breach is suspected. OCR wants the PHI-touch log: which principal, which patient, which purpose. Reconstructing it from EHR audit logs and application traces takes weeks and misses the AI-agent hops entirely.
Every PHI touch is a signed block: principal, patient, purpose, clinician attestation. The breach-window query returns the exact chain. Retention proof is baked into the pack.
OCR ready · same day.500.17 requires an attestation that cybersecurity and BSA/AML programs are running. The CISO signs. If the signed statement isn’t backed by an attributable action log, the attestation is a risk in itself.
The attestation is signed against the underlying evidence chain. Every BSA/AML action, every access review, every escalation is in the pack. The CISO signs what the chain shows.
CISO · defensible signature.Examiners land on-site and want a workspace. Giving them live production access is a governance nightmare. Giving them exported artifacts loses the chain-of-custody the examination is supposed to establish.
Examiners get an auditor workspace: a signed, offline-verifiable pack. No live system access needed. The pack answers their questions. The chain of custody survives the examination.
On-site · offline pack.Internal audit runs continuous. External auditors show up quarterly. The two scopes overlap and diverge, and neither trusts the other’s spreadsheet. Every audit becomes a reconciliation exercise.
Both sides work off the same signed chain. Internal audit exports the pack; external auditors verify the same signatures. The reconciliation exercise disappears. The chain is the source of truth.
One chain · two audiences.Bring a real audit surface: the SOC 2 window, the HIPAA log, the NYDFS attestation. Thirty minutes: see the signed pack, offline verification, and the exact answer for the auditor’s next question.
Book a demo → Read the Evidence docs