Prove what your AI did.
Even years later. Even if TrustNotch is gone.

TrustNotch gives your AI agents a tamper-evident audit log. Every action you record is signed, timestamped, and anchored to Bitcoin, so you or a regulator can verify it independently. Built and hosted in the EU.

What TrustNotch is

Think of it as a flight recorder for your AI agents. When an AI system makes a decision or takes an action, TrustNotch records it so that any later change would show, including a change made by us.

If a customer disputes an outcome, an auditor asks what happened, or a regulator wants evidence, you have proof you can hand over and anyone can check for themselves. No edited logs, no screenshots, no taking your word or ours.

As AI starts taking real actions on its own, being able to show what it did is becoming a legal expectation, not just good practice. The EU AI Act requires high-risk AI systems to record their activity automatically, from 2 December 2027 for standalone systems. The law asks for the records. It does not say how to make them believable. That is the part TrustNotch does.

Who needs an AI audit log

Compliance & risk owners

You have to show what your AI did, to auditors, regulators, or a court. TrustNotch gives you records you can prove, ready for AI Act record-keeping.

Engineering & platform leads

You are shipping AI agents that act on real systems. Add a signed, tamper-evident audit trail with a few API calls, or straight through the Model Context Protocol.

Founders & product owners

You sell AI that customers have to trust. Proof of what your agents actually did turns that trust into something you can show, not just claim, the moment a buyer, a partner, or due diligence starts asking.

Security & incident response

You need to know exactly what your AI did when something goes wrong. TrustNotch gives you a signed, timestamped, tamper-evident record of every action, so your investigation starts from proof, not guesswork.

You need a tamper-evident AI audit trail when:

  • Your agents take actions that matter: moving money, changing records, sending messages, making decisions about people.
  • A customer disputes what your AI did, and you need evidence to settle it.
  • An auditor, regulator, or partner asks for a reliable record of your AI's activity.
  • You are preparing for EU AI Act record-keeping for high-risk AI systems.
  • You want a log that holds up even if someone with admin access tries to rewrite it.

From action to proof, in three steps

  1. Record an action, get a receipt

    Your agent sends an action to TrustNotch over a simple API call, and gets back a signed receipt at once. Under the hood, the receipt is an Ed25519 signature: a cryptographic commitment to the exact content you logged, so it cannot be changed later without that showing.

  2. Batched and anchored to Bitcoin

    TrustNotch groups records together and locks them to the Bitcoin blockchain. Technically, entries are batched into an RFC 6962 Merkle tree, and each batch root is anchored to Bitcoin through OpenTimestamps, giving every entry an independent, public proof of when it existed.

  3. Verify offline, without trusting us

    Anyone can confirm a record is genuine and unchanged, using free open-source software. The open-source trustnotch verifier checks the signature, the Merkle proof and the anchor proof on your own machine, so the proof stands even if our service is offline. Matching the anchor to the Bitcoin chain takes one block header, from any source you choose.

What makes it different

Verify without trusting us

Traditional audit logs tend to ask you to trust the vendor's word that nothing was changed. TrustNotch hands you proof anyone can check on their own.

Proof that outlives the vendor

Your records stay verifiable even if TrustNotch shuts down, because the proof lives on Bitcoin and in open-source software, not on our servers.

Built and hosted in the EU

Your log data is stored in the EU, on infrastructure we run in Helsinki, with no third-party trackers. The only thing that leaves is each batch's Merkle root, a hash with no content, sent to public timestamp servers for anchoring.

Made for AI agents

Agents can create their own account and log their own actions over the API or the Model Context Protocol, with no human in the loop.

Common questions

What is an AI audit log?

A record of the actions and decisions an AI system takes, kept so you can review or prove them later. A tamper-evident audit log goes further: it is built so any change to a past entry can be detected.

What does tamper-evident mean?

You cannot quietly alter a record after the fact. Every entry is signed and anchored to Bitcoin, so if a single character changes, verification fails and the change is obvious.

Do I need this for the EU AI Act?

The EU AI Act requires high-risk AI systems to record events automatically over their lifetime (Article 12), and providers and deployers must keep those logs for at least six months (Articles 19 and 26). The rules apply from 2 December 2027 for standalone high-risk uses such as hiring and credit scoring, and from 2 August 2028 for AI built into regulated products. The Act does not say how to protect logs against editing. TrustNotch makes them verifiable, so they can stand as evidence. This is not legal advice, so check how the rules apply to your own system.

Can I verify a record without trusting TrustNotch?

Yes. The verifier is free, open-source, and runs on your own machine. It checks the signature, the Merkle proof and the Bitcoin anchor proof without contacting us. To confirm the anchor against the real Bitcoin chain, you compare it with a block header from any Bitcoin node or block explorer you trust, never from us. So it works even if TrustNotch is offline or gone.

How do my AI agents send their logs?

Over a simple HTTP API, or through the Model Context Protocol so agents can log actions directly. An agent can even create its own free account and API key without a human.

Where is my data stored?

In the EU. Your log data is stored on infrastructure in Helsinki, Finland, with no third-party trackers. The only thing sent outside our servers is each batch's Merkle root, a hash with no content, which goes to public OpenTimestamps servers to be anchored to Bitcoin.

Is TrustNotch open-source?

The verifier is open-source and published on PyPI and GitHub, so anyone can inspect exactly how verification works. The service that stores and anchors your logs is run by TrustNotch.

What does it cost?

There is a free tier to start, with paid plans as you grow. See the pricing page for current tiers.

Start proving what your AI does

Free tier: 10,000 entries per month, no card required.