Evidence Vault · Write-once compliance evidence
Every certified attestation, approved AI Impact Assessment, shadow-AI decision, and weekly governance health report is sealed into write-once storage the moment it happens, encrypted under your organization's own key, and verifiable with standard tools by anyone you hand it to.
Why it exists
Evidence assembled for an audit is, by definition, assembled after the fact. Screenshots, an exported spreadsheet, a shared folder someone remembered to update. It proves that a person prepared a file. It does not prove that a governance event happened as recorded, or that nothing changed since.
Evidence Vault reverses the order. The record is a consequence of the event itself, written the moment it happens, locked for the term your retention profile requires, and checkable by anyone you hand it to, with tools PulseAI did not write.
The ledger is a pointer. The locked record is the evidence. Every download and every verification is pinned to the exact stored version the record's receipt names, never to "whatever is current."
Captured automatically
Each record carries the framework and clause mappings that were active when it was captured, frozen inside the record. An attestation certified while OSFI E-23 is active keeps its E-23 sections permanently, whatever changes in your framework configuration later.
01 · Sealed on capture
Each attestation an accountable owner certifies, with the framework and clause mappings active at that moment frozen inside the record.
02 · Sealed on capture
The assessment as approved, captured at the moment it reaches completion rather than reconstructed later.
03 · Sealed on capture
Every sanction, flag, ignore, or reopen decision on a discovered AI application, recorded as the decision it was.
04 · Sealed on capture
The scheduled health report, sealed whether or not anyone remembers to run it.
How it works
01 · Capture
The moment a governance event happens, PulseAI writes a record of it to write-once storage, encrypted under your organization's own key. No button, no filing step, no one to forget.
02 · Lock
Each record sits under a compliance-mode retention lock for the full term of your retention profile. No tenant administrator, no PulseAI operator, and no root user of the hosting account can alter or delete it before the lock expires.
03 · Seal
Once a week, a signed digest seals your organization's complete receipt set and diffs it against the previous week. A record altered or removed from the ledger surfaces in the next link, and that finding is itself sealed.
04 · Verify
Open any record and press Verify integrity: PulseAI re-fetches the exact stored version and re-hashes it against the receipt, live. Or export a signed bundle and verify it offline with standard tools.
Two dates, on purpose
Locked until is the storage lock actually enforced. Retain until is the business retention your compliance profile requires. They answer different questions, and the ledger never conflates them.
Live, never cached
Verify integrity recomputes the hash every time you press it. A green check you did not just run would be a claim you could not falsify, which is exactly what this feature exists to replace.
Auditor bundles
An administrator exports a signed ZIP of every record in the current filter scope: a manifest, a detached signature, each record's raw stored bytes, and a summary PDF. Anyone holding it can check it offline. No PulseAI account, no PulseAI software, no network access.
Bundles are capped at 5,000 records and never truncated: an over-cap scope fails loudly rather than producing a partial bundle that could pass as a complete one. Each bundle is recorded as a disclosure, with its scope, record count, requester, and artifact hash, and sealed into the weekly chain. "What exactly did we give the auditor in March?" has a verifiable answer.
The published production signing keys, their fingerprints, the rotation history, and the command-level procedure are on the trust page. Evaluation environments use their own keys, supplied with the evaluation materials.
Step 1
Download PulseAI's published signing key and check its SHA-256 fingerprint against the published value. A key that arrives by any other route, including from whoever handed you the bundle, is not a trust root.
Step 2
Check manifest.sig against manifest.json with openssl. "Verified OK" means PulseAI produced this manifest and it has not changed since.
Step 3
Each receipt names the SHA-256 of that record's raw stored bytes. Re-hash the payload files with shasum and compare. A payload that fails while the signature passed was altered after signing.
Step 4
The record count must equal the number of receipts, and the payload folder must hold exactly the files the manifest names. A file no receipt names sits outside everything the signature covers.
The claim boundary
A limit you were told about first is worth more than a claim you discover later. These are stated in the product, in the bundle's own signed manifest, and here.
Proves
A valid signature means PulseAI produced this manifest and it has not been altered since.
Proves
Re-hashing the payloads against their receipts proves the files are the ones the manifest names.
Does not prove
A bundle cut mid-week can hold records the weekly chain has not sealed yet. The manifest states that number itself, as unsealedCount, rather than leaving it to be inferred.
Does not prove
Write-once storage proves integrity after acceptance. The chain is fork-resistant, not fork-proof: PulseAI holds the signing key. We say so because an auditor will test it.
Erasure, stated plainly
At contractual offboarding, your organization's encryption key is destroyed. Every record and every bundle becomes unreadable at once. It is all or nothing, so it can never alter or selectively remove individual records. PulseAI organizes the evidence and makes its integrity checkable; whether it satisfies a given obligation remains your organization's determination, and no third party has attested the Evidence Vault.
Retention profiles
Your retention profile is set when the vault is enabled for your organization, matched to your obligations. In production, the storage lock runs for the profile's full term, and the lock itself is what stops deletion, not a policy document.
3yrs
Global minimum
6yrs
US HIPAA
7yrs
Canada baseline
10yrs
EU AI Act provider
From your AI assistant
Through the PulseAI MCP server, two read-only tools return each record's metadata and receipt, so an assistant can cite a record in a memo rather than assert that evidence exists. Where an attestation or assessment is described, the assistant is told whether the vault holds a sealed record of it. It cannot download or verify a payload; both need the web application, which reads under your organization's key.
Roles and access
The evidence ledger is readable by administrators and managers. Generating, listing, and downloading bundles is an administrator action, with no exception for the person who requested one: a bundle is the whole scoped corpus in one file, and "I asked for it" is not authorization for the vault.
Questions auditors ask
Available now
Hosting in the United States and the European Union is available on request. Tell us about your organization and we will walk you through the vault, the ledger, and a bundle you can verify yourself.
No commitment required · partnerships@pulseai.now