Open source under MIT · v4.5.0 on PyPI · See how sealing works →
Evidence layer for AI agents

Your agent's deal is stuck on "prove it." Hand them a file.

EPI seals recorded agent runs into a portable .epi file — Ed25519 signature, SHA-256 hash chain — that an auditor can verify offline. The seal proves integrity after sealing, not that every call was captured.

pip install epi-recorder
✓ No account required✓ Offline from first run✓ MIT · free forever✓ Python 3.11+
MIT open source Offline verify v4.5.0 on PyPI JCS-style canonical
Offline-verifiableEd25519 signaturesSHA-256 step chainJCS-style canonicalization (RFC 8785)MIT-licensed verifierVerification free forever
3 questions
One artifact answers
Seal · Identity · Policy — separated in code, never collapsed into one green badge.
0 servers
Required to verify
Verification is fully offline — CLI or this website's tab. No EPI server, no login.
$0
Cost of verification
Free forever, by design. Trustless evidence can't sit behind a paywall.
1 byte
Breaks the seal
A single altered byte fails the signature. That is the entire trust model.
01 / Why EPI exists

Agents make decisions.
Evidence has to outlive them.

In insurance, finance, and healthcare, AI agents approve claims and move money. When a decision is challenged, today's answer is a log your vendor wrote about itself.

The gap

Self-reported logs carry no independent weight

A dashboard is written, hosted, and editable by the same party it describes. Under adverse review — litigation, examination, a claim dispute — that's not evidence.

  • Logs can be edited after the fact
  • Dashboards require trusting the vendor
  • Six months later, nobody can reconstruct what happened
 vendor-log.txt — self-report
$ cat vendor-log.txt
2026-08-22 09:41:02 agent ran ✓
# edited 2026-08-24 (nobody can tell)
The mechanism

A sealed file, made at run time

EPI records every instrumented step into an append-only ledger as the agent executes, then seals it cryptographically when the run closes. Scope is declared per artifact: each file carries a manifest stating what was captured — and what wasn't.

  • Ed25519 signature over the canonical manifest (JCS-style, RFC 8785)
  • SHA-256 hash chain across every recorded step on the SDK path (gateway exports: signed manifest, step chaining in progress)
  • Optional RFC 3161 token at seal time (presence only — signature not validated)
  • One altered byte breaks the signature — visibly
 run.epi — sealed evidence
$ epi verify claim.epi --policy strict
SEAL     valid · ed25519
CHAIN    142/142 steps intact
IDENTITY LOCAL — not claim-ready
→ pin org keys for strict mode
The consequence

Evidence that survives us

The format and verifier are MIT-licensed open source. If EPI Labs disappeared tomorrow, your evidence would still verify — offline, forever, with open tools.

  • No dashboard login required to trust a record
  • No vendor key escrow, no phone-home
  • Open format and verifier — anyone can audit the code
 any machine, any year
$ pip install epi-recorder
$ epi verify archive/run.epi
valid — no account, no server,
no EPI Labs required.
02 / How it works

Verifiable evidence across the agent lifecycle

Three moments, three guarantees. Each one is a property of the file — not a promise from us.

Before · Record

Capture while it happens

One context manager wraps any framework. Every instrumented prompt, tool call, and output lands in an append-only ledger as the run executes.

with record("run.epi"): ...
At close · Seal

Cryptographically close the file

SHA-256 over every member, Ed25519 over the canonical manifest, optional timestamp. One altered byte breaks the signature.

SEAL ed25519 · sha256 · rfc3161 ✓ tamper-evident from this moment
After · Prove

Anyone verifies, anywhere

Auditors, insurers, regulators — re-verify offline with open tools. No dashboard login, no EPI server required.

$ epi verify claim.epi --policy strict SEAL valid · identity pinned · chain intact
03 / Proof, not promises

Drop a .epi — watch the seal resolve

Runs entirely in this tab. Your file is not uploaded.  Download sample.epi · Full verify tool

Amber SEAL VALID · IDENTITY NOT PINNED is the expected result for an unpinned sealer — the hashes and Ed25519 signature passed; the page does not know who the signer is. That is not a broken seal. Green identity requires a pinned org key (epi keys trust / CLI strict policy).

epi verify — browser engine

Drop a .epi file here

or click to browse · verification stays in this browser

01 · Structure
02 · File hashes
03 · Signature
04 · Step chain
05 · Identity (browser)
06 · Full audit → CLI
04 / From evidence to coverage

Why underwriters and auditors need a file

Insurance and audits fail on one word: prove it. A sealed .epi answers before the question is asked.

Underwriting with real data

Carriers can't price agent-liability coverage from questionnaires. Sealed artifacts are verifiable evidence of what an agent actually did, bound to the moment it happened — raw material for pricing risk instead of guessing at it.

✓ sealed run history · org-pinned signer · offline-verifiable

Audits that don't stall

Hand auditors a file they verify offline with open tools — no dashboard access, no vendor trust required.

Incident forensics

Reconstruct the exact decision trail — inputs, tool calls, approvals — when an action is disputed.

Claims defense in minutes

The .epi file is the case file. Cryptographic continuity from the run to the courtroom.

$ epi verify claim.epi --policy strict SEAL valid · chain intact · 142/142 steps
05 / Industries

Where sealed evidence changes outcomes

EPI is a portable record of what an agent did — useful wherever "show me the run six months later" matters.

Marketing that collapses seal, identity, and policy into one green badge is wrong.
We built the code so it can't lie about that.

— The EPI trust model · read it at /trust
05 / For builders

Four steps. One file.

The product loop — not a dashboard setup wizard.

01 / Install

One pip install

MIT-licensed, offline, no account.

$ pip install epi-recorder
02 / Record

Observe the run

Production: EPI gateway proxy (defaults: fail-closed, full-content, loopback bind, no CORS, auth when configured). Quickstart: record().

$ epi gateway serve
03 / Verify

Prove integrity

Integrity + signature offline. Identity separate.

$ epi verify run.epi
04 / View

Open the timeline

Forensic timeline in any browser. No login.

$ epi view run.epi

Integrations: OpenAI · Anthropic · LangChain · LangGraph · LiteLLM · OTel · pytest · AGT — details

06 / Trust model

Three different questions

The code separates these on purpose. A green seal is not a moral judgment — and LOCAL identity is not a failed seal. Select a layer to see what it actually checks.

epi verify run.epi

        
A valid seal proves consistency under some key — not whose. Full trust model →
07 / Evidence, compared

What holds up under review

When a decision is challenged, the format of your record decides how much it's worth.

CapabilityApp logsVendor dashboardSealed .epi
Independent verification✗✗✓ offline, open tools
Tamper-evident after the fact✗editable✓ 1 byte breaks it
Works without the vendorpartial✗✓ MIT format + verifier
Attributable to an org key✗✗✓ strict mode
Verifiable in 5 yearsmaybe✗✓ offline, forever
Auditor needs an accountsometimes✗ always✗ never

Every ✓ in the sealed column is a property of the file format — not a promise from us.

08 / Who it's for

Built for the people accountable when agents act

Different roles, same question: prove it.

CISOs & risk officers

Cryptographic evidence instead of questionnaires. Strict mode enforces org-pinned signers before anything counts as claim-ready.

Auditors & compliance

Verify offline with open tools, on your terms. The record survives us — MIT-licensed format and verifier.

Insurers & underwriters

Price coverage on sealed run history instead of self-reported logs. Identity pinning ties evidence to an org key.

Engineering teams

One context manager wraps any framework. Evidence ships with the run — not bolted on for the audit later.

09 / Plans & custom

Free to verify. Self-serve to scale.

Verification stays free forever. Standard plans check out in two minutes; custom scopes get founder attention.

Open source

$0
MIT · forever

Recorder, verifier, viewer, format. Unlimited offline. Verification will never cost money.

pip install
Self-serve · checkout

Pro

Hosted · Team
monthly or yearly

Standard plans for teams sealing agent runs — country-localized pricing, cancel anytime, checkout by Paddle.

See plans & pricing

Custom & enterprise

From $1,500
founder-led

Evidence Sprint, custom pilots, org keys, procurement support. For scopes beyond the standard tiers.

Book a sprint

Compare all tiers on the plans page →

Known limitations — read them before you rely on this.

The seal proves integrity after sealing, not completeness of capture. A signed file shows the run wasn't altered since the seal; it cannot prove everything was recorded. Full list: KNOWN_LIMITATIONS.md

Evidence starts with one command

Make your agents insurable.

pip install epi-recorder Book a sprint — $1,500

Control plane in development — get early access

Founding pricing for design partners. No spam — one update when the pilot program opens.