Fraud, underwriting, claims. Every AI decision signed to the principal that made it, verifiable years later without calling us.
A compliance officer takes screenshots when the regulator asks. The evidence is mutable, unsigned, and impossible to correlate with the AI decision it’s meant to justify.
Every AI decision is a signed block in a hash-linked chain. The examiner downloads the pack, verifies the signatures offline, and never picks up the phone.
“Regulator asks. Chain answers.”
SR 11-7 wants a model risk story. NYDFS 500.17 wants attested action chains. DORA wants operational-resilience evidence. Three of Veldt’s platform pillars carry the compliance surface for all of them at once.
Every AI decision, every model version, every escalation lands in a hash-linked, cryptographically signed evidence chain. Retention runs 25 years. The auditor verifies offline. No vendor call, no live system access.
Evidence →An adverse-action denial isn’t just a score. It’s a chain: customer application, human underwriter, model version, signed decision. Every hop is a linked principal. Adverse-action letters write themselves from the chain.
Authority →Fraud rings coordinate across accounts, tenants, and agents. Attack-chain detection correlates action sequences across the whole fleet at 89% detection, catching the pattern mid-flight, not in next month’s post-mortem.
Attack Chains →The examiner doesn’t care about your model card. They care whether the decision that hit the customer can be reproduced, attributed, and defended. These five scenarios show the surface.
An AI-assisted underwriting model denies a loan. The applicant demands an adverse-action rationale. The bank has a score, a model card, and no chain from the applicant’s file to the signed decision.
The decision is a signed block: applicant record, model version, feature values, human sign-off. The adverse-action letter is generated from the chain. The regulator verifies the signatures offline.
Adverse action · defensible.Fraudsters coordinate across account-opening, transaction, and customer-service agents. Each agent sees only its slice. By the time the pattern surfaces in the monthly review, the money is gone.
Attack-chain detection correlates action sequences across every agent and tenant. Multi-step fraud patterns are caught in flight, not post-mortem. 89% detection on real chains.
Caught mid-chain.A claim moves from the customer to an intake bot to a specialist agent to a signed payout. Each hand-off loses attribution. When the customer disputes the outcome, no one can reconstruct who authorized what.
Every hand-off is a signed delegation. Customer → intake bot → specialist → payout: one chain, four principals, one signed decision. Disputes get resolved from the chain, not from Slack threads.
Chain of custody preserved.A trading algo drifts. The desk needs a kill-switch the regulator can attest was armed, tested, and effective, not a screenshot of a runbook. Every action needs to attribute to a signed principal.
The kill-switch is a signed governance rule at the runtime layer. Every algo action carries a signed principal chip. When the switch fires, the chain shows exactly when, by whom, and against which action.
Kill-switch attested.A SAR gets filed off an AI-generated alert. The regulator wants the decision chain: what data, which model, which analyst reviewed, which supervisor signed. Reconstructing it takes weeks.
The SAR is the tail of a signed chain: raw signal, model verdict, analyst review, supervisor sign-off. The regulator downloads the pack, verifies each hop, and closes the case without a call.
SAR chain · verifiable.Bring a real decision surface: an underwriting model, a fraud pipeline, an AML alerting system. Thirty minutes: see the signed chain, the offline verify, and the exact answer for the SR 11-7 questionnaire.
Book a demo → Read the Evidence docs