EPI seals recorded agent runs into a portable .epi file — Ed25519 signature, SHA-256 hash chain — that an auditor can verify offline. The seal proves integrity after sealing, not that every call was captured.
pip install epi-recorder$ epi verify demo.epi ⚠ UNVERIFIED IDENTITY — EPI Verification Report DECISION: PASS Policy: standard IDENTITY (who sealed — required for claim trust) Status: NOT_PINNED Fingerprint: 6090c0d9… SEAL (objective proofs — not identity) Integrity: Verified Signature: Valid Forensic: PASS Notarized: Not available Seal is valid. Identity is not pinned — anyone can re-sign a rebuilt chain with a fresh key.
In insurance, finance, and healthcare, AI agents approve claims and move money. When a decision is challenged, today's answer is a log your vendor wrote about itself.
A dashboard is written, hosted, and editable by the same party it describes. Under adverse review — litigation, examination, a claim dispute — that's not evidence.
$ cat vendor-log.txt
2026-08-22 09:41:02 agent ran ✓
# edited 2026-08-24 (nobody can tell)
EPI records every instrumented step into an append-only ledger as the agent executes, then seals it cryptographically when the run closes. Scope is declared per artifact: each file carries a manifest stating what was captured — and what wasn't.
$ epi verify claim.epi --policy strict SEAL valid · ed25519 CHAIN 142/142 steps intact IDENTITY LOCAL — not claim-ready → pin org keys for strict mode
The format and verifier are MIT-licensed open source. If EPI Labs disappeared tomorrow, your evidence would still verify — offline, forever, with open tools.
$ pip install epi-recorder
$ epi verify archive/run.epi
valid — no account, no server,
no EPI Labs required.
Three moments, three guarantees. Each one is a property of the file — not a promise from us.
One context manager wraps any framework. Every instrumented prompt, tool call, and output lands in an append-only ledger as the run executes.
SHA-256 over every member, Ed25519 over the canonical manifest, optional timestamp. One altered byte breaks the signature.
Auditors, insurers, regulators — re-verify offline with open tools. No dashboard login, no EPI server required.
Runs entirely in this tab. Your file is not uploaded. Download sample.epi · Full verify tool
Amber SEAL VALID · IDENTITY NOT PINNED is the expected result for an unpinned sealer — the hashes and Ed25519 signature passed; the page does not know who the signer is. That is not a broken seal. Green identity requires a pinned org key (epi keys trust / CLI strict policy).
or click to browse · verification stays in this browser
Insurance and audits fail on one word: prove it. A sealed .epi answers before the question is asked.
Carriers can't price agent-liability coverage from questionnaires. Sealed artifacts are verifiable evidence of what an agent actually did, bound to the moment it happened — raw material for pricing risk instead of guessing at it.
Hand auditors a file they verify offline with open tools — no dashboard access, no vendor trust required.
Reconstruct the exact decision trail — inputs, tool calls, approvals — when an action is disputed.
The .epi file is the case file. Cryptographic continuity from the run to the courtroom.
EPI is a portable record of what an agent did — useful wherever "show me the run six months later" matters.
Credit, fraud, refund, and underwriting agents. Seal the trail for audit and model-risk review.
Clinical decision support. Signed execution snapshots for review — not a 510(k) certificate by itself.
Claims and underwriting agents. Full step trails for reconstruction of "what the system did."
Benefits, procurement, casework. Offline-verifiable evidence for oversight bodies.
Red-team runs as sealed artifacts — reproducible evidence of what was tested.
Verifiable trails for "what did the agent do on this matter."
Marketing that collapses seal, identity, and policy into one green badge is wrong.
We built the code so it can't lie about that.
The product loop — not a dashboard setup wizard.
MIT-licensed, offline, no account.
Production: EPI gateway proxy (defaults: fail-closed, full-content, loopback bind, no CORS, auth when configured). Quickstart: record().
Integrity + signature offline. Identity separate.
Forensic timeline in any browser. No login.
Integrations: OpenAI · Anthropic · LangChain · LangGraph · LiteLLM · OTel · pytest · AGT — details
The code separates these on purpose. A green seal is not a moral judgment — and LOCAL identity is not a failed seal. Select a layer to see what it actually checks.
When a decision is challenged, the format of your record decides how much it's worth.
| Capability | App logs | Vendor dashboard | Sealed .epi |
|---|---|---|---|
| Independent verification | ✗ | ✗ | ✓ offline, open tools |
| Tamper-evident after the fact | ✗ | editable | ✓ 1 byte breaks it |
| Works without the vendor | partial | ✗ | ✓ MIT format + verifier |
| Attributable to an org key | ✗ | ✗ | ✓ strict mode |
| Verifiable in 5 years | maybe | ✗ | ✓ offline, forever |
| Auditor needs an account | sometimes | ✗ always | ✗ never |
Every ✓ in the sealed column is a property of the file format — not a promise from us.
Different roles, same question: prove it.
Cryptographic evidence instead of questionnaires. Strict mode enforces org-pinned signers before anything counts as claim-ready.
Verify offline with open tools, on your terms. The record survives us — MIT-licensed format and verifier.
Price coverage on sealed run history instead of self-reported logs. Identity pinning ties evidence to an org key.
One context manager wraps any framework. Evidence ships with the run — not bolted on for the audit later.
Verification stays free forever. Standard plans check out in two minutes; custom scopes get founder attention.
Recorder, verifier, viewer, format. Unlimited offline. Verification will never cost money.
pip installStandard plans for teams sealing agent runs — country-localized pricing, cancel anytime, checkout by Paddle.
See plans & pricingEvidence Sprint, custom pilots, org keys, procurement support. For scopes beyond the standard tiers.
Book a sprintCompare all tiers on the plans page →
The seal proves integrity after sealing, not completeness of capture. A signed file shows the run wasn't altered since the seal; it cannot prove everything was recorded. Full list: KNOWN_LIMITATIONS.md
Evidence starts with one command
Control plane in development — get early access
Founding pricing for design partners. No spam — one update when the pilot program opens.