Prove what your AI did.
Even years later. Even if TrustNotch is gone.

TrustNotch gives your AI agents a tamper-evident audit log. Every action you record is signed, timestamped, and anchored to Bitcoin, so you or a regulator can verify it independently. Built and hosted in the EU.

What TrustNotch is

Think of it as a flight recorder for your AI agents. When an AI system makes a decision or takes an action, TrustNotch writes it into a record no one can change afterward, not even us.

If a customer disputes an outcome, an auditor asks what happened, or a regulator wants evidence, you have proof you can hand over and anyone can check for themselves. No edited logs, no screenshots, no taking your word or ours.

As AI starts taking real actions on its own, being able to show what it did is becoming a legal expectation, not just good practice. The EU AI Act will require high-risk AI systems to keep automatic, tamper-resistant records of what they do. TrustNotch is built for exactly that.

Who needs an AI audit log

Compliance & risk owners

You have to show what your AI did, to auditors, regulators, or a court. TrustNotch gives you records you can prove, ready for AI Act record-keeping.

Engineering & platform leads

You are shipping AI agents that act on real systems. Add a signed, tamper-evident audit trail with a few API calls, or straight through the Model Context Protocol.

Founders & product owners

You sell AI that customers have to trust. Proof of what your agents did turns that trust into something you can show, not just claim.

You need a tamper-evident AI audit trail when:

  • Your agents take actions that matter: moving money, changing records, sending messages, making decisions about people.
  • A customer disputes what your AI did, and you need evidence to settle it.
  • An auditor, regulator, or partner asks for a reliable record of your AI's activity.
  • You are preparing for EU AI Act record-keeping for high-risk AI systems.
  • You want a log that holds up even if someone with admin access tries to rewrite it.

From action to proof, in three steps

  1. Record an action, get a receipt

    Your agent sends an action to TrustNotch over a simple API call, and gets back a signed receipt at once. Under the hood, the receipt is an Ed25519 signature: a cryptographic commitment to the exact content you logged, so it cannot be changed later without that showing.

  2. Batched and anchored to Bitcoin

    TrustNotch groups records together and locks them to the Bitcoin blockchain. Technically, entries are batched into an RFC 6962 Merkle tree, and each batch root is anchored to Bitcoin through OpenTimestamps, giving every entry an independent, public proof of when it existed.

  3. Verify offline, without trusting us

    Anyone can confirm a record is genuine and unchanged, using free open-source software. The open-source trustnotch verifier checks the signature and the Bitcoin anchor by itself, so the proof stands even if our service is offline.

What makes it different

Verify without trusting us

Traditional audit logs tend to ask you to trust the vendor's word that nothing was changed. TrustNotch hands you proof anyone can check on their own.

Proof that outlives the vendor

Your records stay verifiable even if TrustNotch shuts down, because the proof lives on Bitcoin and in open-source software, not on our servers.

Built and hosted in the EU

Your data stays in the EU, on infrastructure we run in Helsinki. No third-party trackers, no data leaving the region.

Made for AI agents

Agents can create their own account and log their own actions over the API or the Model Context Protocol, with no human in the loop.

Common questions

What is an AI audit log?

A record of the actions and decisions an AI system takes, kept so you can review or prove them later. A tamper-evident audit log goes further: it is built so any change to a past entry can be detected.

What does tamper-evident mean?

You cannot quietly alter a record after the fact. Every entry is signed and anchored to Bitcoin, so if a single character changes, verification fails and the change is obvious.

Do I need this for the EU AI Act?

The EU AI Act requires providers of high-risk AI systems to keep automatic logs of what their systems do, under Article 12. Those obligations are being phased in over the next couple of years. TrustNotch gives you records designed to meet that kind of requirement. This is not legal advice, so check how the rules apply to your own system.

Can I verify a record without trusting TrustNotch?

Yes. The verifier is free and open-source. It checks the signature and the Bitcoin timestamp by itself, so it works even if TrustNotch is offline or gone.

How do my AI agents send their logs?

Over a simple HTTP API, or through the Model Context Protocol so agents can log actions directly. An agent can even create its own free account and API key without a human.

Where is my data stored?

In the EU. TrustNotch is built and hosted on infrastructure in Helsinki, Finland, with no third-party trackers and no data leaving the region.

Is TrustNotch open-source?

The verifier is open-source and published on PyPI and GitHub, so anyone can inspect exactly how verification works. The service that stores and anchors your logs is run by TrustNotch.

What does it cost?

There is a free tier to start, with paid plans as you grow. See the pricing page for current tiers.

Start proving what your AI does

Free tier: 10,000 entries per month, no card required.