Krynix · The independent assurance layer for AI agents
Prove your agents stayed in bounds.
Krynix is the independent assurance and evidence platform for AI agents. Bring your own enforcement — Microsoft AGT, LangChain, our gateway, or none — and Krynix independently verifies what your agents actually did, holds tamper-evident proof no one can alter, and continuously monitors your controls. The proof your own logs can't give an auditor.
The problem
Your agents act now. Can you prove they stayed in bounds?
Blocking bad actions is becoming a commodity — even Microsoft ships it free. The unsolved problem is independent assurance: proof an auditor, a regulator, or your insurer will actually trust — evidence you can verify yourself, controls monitored continuously, and the one thing your enforcer can never do — independently check its own work.
“An auditor or insurer wants tamper-evident proof our agents are governed — our own logs are just our word.”
See the evidence layerDid the guardrails hold?“We block bad actions — but we can't independently verify what our own enforcer let through.”
See how it fitsIs this allowed?“Each agent action looks legitimate on its own — together they quietly exfiltrate data.”
See the optional gatewayHow it works
Emit. Hold. Verify. Prove.
Your agents — and whatever you use to govern them — emit decisions. Krynix holds them in independent custody, independently verifies what actually happened, monitors your controls, and turns it into evidence anyone can check. We sit above your stack; we don’t replace it.
Emit
Whatever you already use to govern agents — Microsoft AGT, LangChain, your own code, or the Krynix gateway — sends its decisions to Krynix over OpenTelemetry or a one-line HTTP contract. No enforcer yet? Our drop-in gateway emits for you.
Hold
Every decision lands in an independent, append-only store and is hash-chained on arrival, so any later edit or deletion is detectable. Normalized into one evidence model across every agent stack you run — not one silo per framework.
Verify
Krynix re-checks what your enforcer claimed — an enforcer can't audit itself. It flags discrepancies (allowed-but-shouldn't-have), evidence gaps, and integrity breaks, and turns named controls into a live pass/fail status across your fleet. (Independent verifier & continuous controls: in build with design partners.)
Prove
Export auditor-ready evidence bundles mapped toward the frameworks that matter — SOC 2, the EU AI Act audit file, FINRA retention — plus the business-impact figures your board and insurer ask for: exposure avoided and an audit-readiness score. Anyone can verify a bundle's integrity offline. (Signed bundles & offline verification: built on Ed25519 primitives, wiring into the hosted product. Business-impact analytics: on the roadmap.)
Design principles
Built on three principles that decide what Krynix does and what it deliberately won't.
Independent custody, not self-attestation
A log the audited party generates and holds is just their word. Krynix records are held by a neutral third party — the operator can read and query them, but cannot alter or delete history. Separation of duties is the entire design, because it is what makes the record count as evidence to someone outside the company.
Sit above your stack, not replace it
Your existing enforcer blocks the action; Krynix holds the proof and independently re-checks what it claimed — because an enforcer can't audit itself. Decisions arrive over open standards and are normalized into a single evidence model across every framework you run — so the control plane stays yours, and the assurance stays neutral.
Verify it yourself, don't trust us
Records are tamper-evident and checkable with an open verifier, against an open format — trust is structural, not a promise. And by design we capture structured, non-sensitive evidence only: never raw prompts, argument values, or PII, so it is easier to retain and to defend.
Get started
From your existing stack to continuous, independent assurance in four steps.
Keep your enforcement
Already block bad actions with your own enforcer, a framework's guardrails, or our drop-in gateway? Keep it. Krynix doesn't replace your control plane — it sits above whatever you run.
Point decisions at Krynix
Send your agents' decisions to Krynix over OpenTelemetry or a one-line HTTP contract. No code rewrite, no per-framework wiring, no lock-in. If you have nothing yet, the Krynix gateway is a transparent MCP proxy that emits for you.
Verify independently
Every decision lands in a tamper-evident, independently-held record — the operator can query it but can't alter history. Krynix re-checks what your enforcer claimed and flags discrepancies, gaps, and integrity breaks, then rolls it into named controls with a live pass/fail status. (Verifier & continuous controls: in build with design partners.)
Prove it to anyone
Export auditor- and insurer-ready evidence with the business impact attached — exposure avoided, audit-readiness score. Anyone can verify a record's integrity with the open verifier, no trust in us required. Become a design partner and we'll shape the evidence format to exactly what your regulator, customer, or insurer asks for.
Early access
Become a design partner.
Two minutes, seven questions. We’re early and selecting a small group of design partners — companies deploying agents that touch sensitive data or take real actions. We reply within five business days.
- Shape the evidence format around your auditor's requirements.
- Priority Slack / Discord channel with the team.
- Hands-on help wiring your first integration.
Powered by Tally · Responses → admin@obadev.com
Or just say hi
To reach us.
Not ready for the form yet? Drop into the community, follow along, or send us a note about what you are trying to govern.