Sealed manifest at every action
Each AI decision the system makes is bound to a signed manifest — model version, prompt version, retrieved context hash, tool invocations, output, reviewer signoff. Tampering breaks the seal; verification is offline.
Proofroom is the evidence engine that turns AI decisions into audit-defensible artifacts. Sealed manifests. Examiner-runnable verification. A binder shaped like the ones bank model-risk boards already accept. It is the runtime the Innorve Academy graduates ship into — and the spine of our regulated-enterprise pilots.
Each AI decision the system makes is bound to a signed manifest — model version, prompt version, retrieved context hash, tool invocations, output, reviewer signoff. Tampering breaks the seal; verification is offline.
A regulator or examiner re-verifies any decision with the same command an internal engineer would run. No trust in our infrastructure. The verification transcript is the audit deliverable.
Every pilot kit ships a folder a model-risk reviewer can open: model cards, prompt registers, eval reports, governance attestations, signed receipts. Same shape as the binders that pass bank model-risk boards.
Proofroom runs in your environment. Tenant data never crosses an Innorve boundary. We hold no copies, no logs, no caches. Your engineers operate the system; we provide the spine.
Two-week installation against one workflow you already run. Generates a Cascade Report PDF, an AGRS scorecard, and a CCO-runnable verification kit. Outcome: you can hand the kit to your auditor before next quarter.
12-week pilot with weekly operate scorecards, evidence intake from existing channels (SFTP, secure upload, email ingress), and red-team coverage. Outcome: the AI workflow produces audit-defensible evidence on a continuous cadence.
Your engineers — most of them Academy alumni — operate Proofroom as part of your AI stack. We license the methodology, you own the runtime. We do not install. We do not lock in. We do not charge for seats.
Proofroom is single-tenant, single-process, and auditable from the disk up. The production doctor refuses to start unless signing keys, session secrets, operator hashes, audit log, and kit storage all probe green. The same doctor runs in CI for every release.
| Signing | ED25519 keypairs, 32-byte seeds, never logged, doctor-verified. |
| Audit log | Append-only JSON-line log, doctor-probed for write integrity on boot. |
| Tenant isolation | Per-kit ledger, runs, AGRS stores. No cross-kit reads, ever. |
| Operator auth | Scrypt password hashing, session secret enforcement, allowed-kits ACL. |
| Hosted footprint | Render (or your own VPC), persistent disk, single-process Next.js. Cost: ≈ $8/mo at pilot scale. |
Innorve Academy trains the discipline. Proofroom is the runtime that discipline ships into. The Assure-tier capstone runs through Proofroom, so an Assure-tier graduate has already produced a sealed manifest, an evidence binder, and a CCO-runnable verification transcript before they walk into your interview.
We never bcc. We never use a CRM auto-responder. The first reply is from Sushanth.