action_hash
Fingerprints the exact action. Change one character of the payee or the amount and it no longer matches.
The notary for AI agents.
Veristade decides whether each agent action may run, then keeps a proof of why that anyone can check later. Refused by default. Allowed only with proof. Written down either way.
Product in development. Design-partner pilots on infrastructure you control. No hosted service yet. Patent pending.
INSIDE A RECEIPT
The receipt above is complete: a refused wire transfer, in the gate's own field layout. Here is what each field is for.
action_hashFingerprints the exact action. Change one character of the payee or the amount and it no longer matches.
policy_hashFingerprints the policy in force. A later policy can’t be passed off as the one that made this call.
verdict · reasonsRecord the call in plain English. For held actions, requires names what would unlock it, such as one person’s signature.
timestamp_unixRead from the gate’s clock, never taken from the agent that asked.
prev_hash · self_hashOne seals the receipt before it, the other seals this one. Edit any receipt and the chain stops adding up.
A receipt is plain data and SHA-256. Your auditor can verify a whole ledger with a few lines of code, without trusting us or the agent.
WHERE THE TRUST COMES FROM
Veristade accepts facts from three places, and none of them is the agent.
Nothing an agent writes, and nothing a prompt injection writes through it, can become a fact.
The honest edge: the people you trust are still the root of trust. If someone with authority signs a bad plan, Veristade can’t stop it. It labels where each decision’s authority came from, so that signature is provable, never hidden.
SIGNED PLANS
Approval fatigue is how human review fails. Sign forty things a day and you start rubber-stamping, which is worse than no review at all because it looks like review.
With a signed plan, a person authorizes the task once. Every step is checked against that plan. A step that isn’t in it, including one an injected instruction slipped in, matches nothing and is refused.
Set the shape of your team’s agent work.
410signatures, approving every step
10signatures, approving each plan once
400 fewer signatures to rubber-stamp every week, with every step still checked.
WHAT A REFUSAL SOUNDS LIKE
A CISO can read the reason. An engineer can check the proof under it.
WHERE TEAMS PUT IT FIRST
One agent, one policy written with you, and a readout of everything it tried.
STATUS
A security product that overstates itself has already failed its first test.
From internal tests, September 2026: 2,000 randomized requests were checked against a separately written reference model with zero actions allowed without a permit. Not an external audit. We walk design partners through the tests line by line.
COMMON QUESTIONS
No mystery claims. No assumed integrations.
No. A filter tries to recognize dangerous text, and it fails open when it misses. Veristade never needs to recognize it. Text can’t become a fact, so an action without real proof doesn’t run, however convincing the text was.
No, and be wary of anyone who says their product does. Veristade makes sure an action was permitted by your policy and proves it. Writing a good policy is part of every pilot.
A person with real authority signing something they shouldn’t. The people you trust are still the root of trust. Veristade makes that signature provable, not impossible, and labels on every decision where the authority came from.
It doesn’t run. The agent gets a plain-English reason it can act on, and you get a receipt. Actions that need a person are held until someone signs or declines.
As a gateway in front of the tools and systems your agents call, on infrastructure you control. There’s no hosted version yet.
No. It holds no certifications today. We’ll tell you exactly what it does and doesn’t cover for your use case.
DESIGN PARTNERS
One workflow, a policy written with you, and a readout of everything the agent tried: what ran, what didn’t, and why.
Apply for a pilot