Evidence that captures itself.
Proof that verifies offline.

Every certified attestation, approved AI Impact Assessment, shadow-AI decision, and weekly governance health report is sealed into write-once storage the moment it happens, encrypted under your organization's own key, and verifiable with standard tools by anyone you hand it to.

Built for the moment someone says "show me."

Evidence assembled for an audit is, by definition, assembled after the fact. Screenshots, an exported spreadsheet, a shared folder someone remembered to update. It proves that a person prepared a file. It does not prove that a governance event happened as recorded, or that nothing changed since.

Evidence Vault reverses the order. The record is a consequence of the event itself, written the moment it happens, locked for the term your retention profile requires, and checkable by anyone you hand it to, with tools PulseAI did not write.

The ledger is a pointer. The locked record is the evidence. Every download and every verification is pinned to the exact stored version the record's receipt names, never to "whatever is current."

Four governance events. No "save evidence" button.

Each record carries the framework and clause mappings that were active when it was captured, frozen inside the record. An attestation certified while OSFI E-23 is active keeps its E-23 sections permanently, whatever changes in your framework configuration later.

01 · Sealed on capture

Certified attestations

Each attestation an accountable owner certifies, with the framework and clause mappings active at that moment frozen inside the record.

02 · Sealed on capture

Approved AI Impact Assessments

The assessment as approved, captured at the moment it reaches completion rather than reconstructed later.

03 · Sealed on capture

Shadow-AI discovery decisions

Every sanction, flag, ignore, or reopen decision on a discovered AI application, recorded as the decision it was.

04 · Sealed on capture

Weekly governance health reports

The scheduled health report, sealed whether or not anyone remembers to run it.

Capture, lock, seal, verify.

01 · Capture

The moment a governance event happens, PulseAI writes a record of it to write-once storage, encrypted under your organization's own key. No button, no filing step, no one to forget.

02 · Lock

Each record sits under a compliance-mode retention lock for the full term of your retention profile. No tenant administrator, no PulseAI operator, and no root user of the hosting account can alter or delete it before the lock expires.

03 · Seal

Once a week, a signed digest seals your organization's complete receipt set and diffs it against the previous week. A record altered or removed from the ledger surfaces in the next link, and that finding is itself sealed.

04 · Verify

Open any record and press Verify integrity: PulseAI re-fetches the exact stored version and re-hashes it against the receipt, live. Or export a signed bundle and verify it offline with standard tools.

Two dates, on purpose

Locked until is the storage lock actually enforced. Retain until is the business retention your compliance profile requires. They answer different questions, and the ledger never conflates them.

Live, never cached

Verify integrity recomputes the hash every time you press it. A green check you did not just run would be a claim you could not falsify, which is exactly what this feature exists to replace.

Hand over a bundle. Let them verify it themselves.

An administrator exports a signed ZIP of every record in the current filter scope: a manifest, a detached signature, each record's raw stored bytes, and a summary PDF. Anyone holding it can check it offline. No PulseAI account, no PulseAI software, no network access.

Bundles are capped at 5,000 records and never truncated: an over-cap scope fails loudly rather than producing a partial bundle that could pass as a complete one. Each bundle is recorded as a disclosure, with its scope, record count, requester, and artifact hash, and sealed into the weekly chain. "What exactly did we give the auditor in March?" has a verifiable answer.

The published production signing keys, their fingerprints, the rotation history, and the command-level procedure are on the trust page. Evaluation environments use their own keys, supplied with the evaluation materials.

  1. Step 1

    Confirm the key

    Download PulseAI's published signing key and check its SHA-256 fingerprint against the published value. A key that arrives by any other route, including from whoever handed you the bundle, is not a trust root.

  2. Step 2

    Verify the signature

    Check manifest.sig against manifest.json with openssl. "Verified OK" means PulseAI produced this manifest and it has not changed since.

  3. Step 3

    Re-hash every payload

    Each receipt names the SHA-256 of that record's raw stored bytes. Re-hash the payload files with shasum and compare. A payload that fails while the signature passed was altered after signing.

  4. Step 4

    Check the set is exact

    The record count must equal the number of receipts, and the payload folder must hold exactly the files the manifest names. A file no receipt names sits outside everything the signature covers.

What it proves, and what it does not.

A limit you were told about first is worth more than a claim you discover later. These are stated in the product, in the bundle's own signed manifest, and here.

Proves

Authenticity

A valid signature means PulseAI produced this manifest and it has not been altered since.

Proves

Internal consistency

Re-hashing the payloads against their receipts proves the files are the ones the manifest names.

Does not prove

Completeness

A bundle cut mid-week can hold records the weekly chain has not sealed yet. The manifest states that number itself, as unsealedCount, rather than leaving it to be inferred.

Does not prove

Authenticity of origin

Write-once storage proves integrity after acceptance. The chain is fork-resistant, not fork-proof: PulseAI holds the signing key. We say so because an auditor will test it.

Erasure, stated plainly

At contractual offboarding, your organization's encryption key is destroyed. Every record and every bundle becomes unreadable at once. It is all or nothing, so it can never alter or selectively remove individual records. PulseAI organizes the evidence and makes its integrity checkable; whether it satisfies a given obligation remains your organization's determination, and no third party has attested the Evidence Vault.

Locked for the term your obligations require.

Your retention profile is set when the vault is enabled for your organization, matched to your obligations. In production, the storage lock runs for the profile's full term, and the lock itself is what stops deletion, not a policy document.

3yrs

Global minimum

6yrs

US HIPAA

7yrs

Canada baseline

10yrs

EU AI Act provider

From your AI assistant

The ledger, readable from Claude, ChatGPT, or Copilot

Through the PulseAI MCP server, two read-only tools return each record's metadata and receipt, so an assistant can cite a record in a memo rather than assert that evidence exists. Where an attestation or assessment is described, the assistant is told whether the vault holds a sealed record of it. It cannot download or verify a payload; both need the web application, which reads under your organization's key.

Roles and access

Read widely. Disclose deliberately.

The evidence ledger is readable by administrators and managers. Generating, listing, and downloading bundles is an administrator action, with no exception for the person who requested one: a bundle is the whole scoped corpus in one file, and "I asked for it" is not authorization for the vault.

Answered the way we answer them.

Can PulseAI staff edit or delete evidence records?
No. Every record is stored under a compliance-mode retention lock for the full term of your retention profile. For that term, no tenant administrator, no PulseAI operator, and no root user of the hosting account can alter or delete it. The one named exception is whole-organization cryptographic erasure at contractual offboarding, which destroys every record at once and cannot alter or selectively remove individual ones.
Can an auditor verify an evidence bundle without a PulseAI account?
Yes. A bundle is a signed ZIP: a manifest, a detached signature, each record's raw stored bytes, and a summary PDF. The signature verifies with standard openssl against PulseAI's published signing key, and every payload re-hashes with shasum. No PulseAI account, no PulseAI software, and no network access are required.
Does a verified bundle prove we are compliant?
No. The signature proves authenticity and re-hashing proves internal consistency. Neither proves completeness, and a bundle can describe a narrower scope than an auditor asked for. PulseAI organizes the evidence and makes its integrity checkable; whether it satisfies a given obligation remains your organization's determination.
How long is evidence retained?
Retention follows the profile set for your organization: 3 years (global minimum), 6 years (US HIPAA), 7 years (Canada baseline), or 10 years (EU AI Act provider). In production, the storage lock runs for the full term of the profile. Every record shows both its locked-until date and its retain-until date.
What happens to the evidence when we leave PulseAI?
Erasure is cryptographic. At contractual offboarding, your organization's encryption key is destroyed, which makes every record and every bundle unreadable at once. Export the bundles you need beforehand; a bundle verifies offline for as long as you keep it.

Live in Canada today.

Hosting in the United States and the European Union is available on request. Tell us about your organization and we will walk you through the vault, the ledger, and a bundle you can verify yourself.

No commitment required · partnerships@pulseai.now