inferXby CyberSecAI Request a licence
Court-grade evidence · Runs in your cloud

The evidence layer that turns AI agent records into court-grade evidence.

An AI agent read a medical record, moved money, deleted a file, or was refused. Somewhere there is a log. inferX turns that log into evidence a court can use: independently re-verified, sorted into the facts a legal finding needs, graded by how far it can be trusted, and re-sealed so the work itself is provable.

Published as an IETF Internet-Draft, 3 October 2026.
The Typed-Evidence Record: a legally-operative, trust-graded record format for machine-generated evidence.
Companion to
The format is open for anyone to implement; the method that produces it is licensed.
CyberSecAI Ltd, London

The AI cybersecurity company. Authors of the Agent Audit Trail standard and AgentPass.

Patent pending GB2623300.7

Reproducible legal-accountability typing and trust-grading of machine-generated evidence.

Two open IETF drafts

Agent Audit Trail for the record, Typed-Evidence Record for the evidence. Anyone can implement either format.

15legally operative
categories
A·B·Cevidence grades
by attestation
4signed export formats
verified today
0bytes leave
your cloud
1:1byte-identical
reproduction
What it is

Three layers. inferX is the middle one.

Recording what an agent did, proving what the record establishes, and taking it to court are three different jobs. inferX does the second. It sits on top of the record standard and underneath legal practice, and it does not pretend to be either.

Layer 1 · the record

Agent Audit Trail

Open standard · IETF Internet-Draft

Signed, hash-chained, offline-verifiable records of what an AI agent did: who acted, on what, under which authority, with which model, with or without a human. Proves a record was not altered. Does not say what it legally means. aat-standard.org

Layer 2 · the evidence

inferX

Evidence technology · CyberSecAI · licensed

Re-verifies every record, renders it as a plain legal narrative, sorts it into the fifteen facts a finding turns on, grades the source A, B or C, flags anything uncertain, and re-seals the result as a new signed record. Produces the evidence pack in the Typed-Evidence Record format. Does not interpret law.

Layer 3 · the court

Legal method

Your counsel · your methodology

Admissibility, chain of custody, expert evidence, presentation. inferX output is designed as the input to that work: every fact carries its source hash, its grade and its reproducibility proof, so the legal layer starts from verified material rather than a screenshot.

The ledger records it. inferX sorts and proves it. Counsel takes it to court.

What it does

Eight things, in a fixed order, every time.

The order matters. Nothing is sorted until it has been verified, nothing is graded until it has been sorted, and nothing leaves the pipeline unsealed. The same input produces byte-identical output, which is what lets the result be challenged and defended.

What "typing" means, in plain English. A raw record says something like marketing_bot, SELECT, public.customers, REFUSED, L1, needs L2. Typing sorts each piece of that into the labelled slot a lawyer needs: who acted, on whose data, what they did, to what, who received it, which model and version, under what authority, whether it was allowed, whether a human stepped in, and when. Think of a court clerk filling in a fixed form from a witness statement, except the form never changes, the filling-in is automatic, and it comes out identical every time it is run.
01 · VERIFY

Re-derive every integrity claim

Recompute each record's hash from its content, verify the signature against the published key, test the chain link to the record before it. Nothing is taken on trust from the producer. An unknown signing scheme is reported as inconclusive, never as tampering.

02 · TYPE

Sort each record into the fifteen facts a finding needs

Each record is rendered as a plain sentence and sorted into a fixed, versioned set of slots: who, whose, what, to what, to whom, which model, under what authority, allowed or refused, human or not, when. These are the slots a legal finding turns on.

actorprincipalactobjectrecipientmodel identitymodel versionpromptoutputdata classificationauthority basisauthorisation outcomecompetence levelhuman interventiontemporal validity
03 · GRADE

Grade the source by attestation

Every record is graded A, B or C by how far it can be independently trusted: whether the model is pinned and attested, whether the record is signed and anchored, or whether it is an unattested log, export or screenshot.

04 · QUALIFY

Flag what is uncertain

Each extracted fact carries a confidence margin. Facts near the decision boundary are flagged fragile for human review. Reproducibility risk is quantified on the page, not hidden behind a single pass mark.

05 · RECORD ABSENCE

Treat a missing fact as a fact

"No human approval on record" is itself a typed, signed fact. The categories a record does not satisfy are listed, so the gaps in an organisation's evidence are as visible as the evidence.

06 · RE-SEAL

Make the typing itself evidence

Every typing is wrapped as a new signed, hash-chained record carrying the tool version, the model fingerprint and the source record's hash. The extraction can be verified offline, by anyone, with the public key in the pack.

07 · ANSWER

Expert Witness, grounded and signed

Questions are answered only from the signed record. Every factual sentence cites a record. If the answer is not in the record, the witness says so. Each answer is signed with the hash of the facts it saw. Runs locally; nothing leaves the machine.

08 · EXPORT

Produce the evidence pack

Source records, verification report, typed and graded facts, the re-sealed chain, the public key, the Expert Witness transcript and a method appendix, as a PDF and as machine-readable JSON. Re-verifiable without us.

Why you need it

A tamper-evident log is legible. It is not yet evidence.

Signed logs prove a record was not altered. They do not say who acted, on whose behalf, under what authority, with which model, or whether a human was involved. Those are the questions a court, a regulator or an insurer asks, and they have to be answered from the record, reproducibly.

01

Most AI evidence today is Grade C

Logs, exports and screenshots with no signature and no model pin. They assert provenance; they cannot prove it. inferX makes that visible, and shows the exact upgrade path: record to the standard and you are at B; pin and attest the model and you are at A.

02

Regulators ask for facts, not dashboards

EU AI Act record-keeping and human-oversight duties, financial-services accountability regimes, data-protection authorities and courts all want the same things: who, what, on whose data, under what authority, when, and was a human in the loop. Those are the fifteen categories.

03

Reproducible beats persuasive

An expert who says "I read the logs" is a witness. A method that produces the same typed output byte for byte on every run, from a pinned tool and a fingerprinted model, is a procedure the other side can repeat. That is the difference between testimony and evidence.

04

The gaps matter as much as the facts

The most consequential finding is often an absence: no human approval, no authority basis, no recipient recorded. inferX records absence as a fact, so an organisation sees its exposure before a claimant does.

05

Verification must not need the producer

Evidence whose claims can only be checked by the party that made them is not evidence. Every pack re-verifies with a public key and nothing else. Not our servers, not your servers, not anyone's goodwill.

Court-grade evidence format

What comes out: one pack, three guarantees.

Every pack says what was verified, what each record establishes, and how far it can be trusted. Verified, typed, graded. The layout is identical from case to case so differences in a pack are differences in evidence, not in formatting.

1 · Source integrity report

Record by record

Hash reproduced or not, signature valid or not, chain intact or not, and under which scheme. Per layer when a bundle mixes producers. HMAC-sealed sources are reported honestly as integrity-only.

2 · Typed facts

Fifteen categories, scored

For each record: the legal narrative, the extracted facts with confidence and robustness, the categories not present, the grade and the reason for it, and the full source hashes and provenance carried through verbatim.

3 · Re-sealed chain

The typing, signed

The chain of typing records with tool version, model fingerprint and source hashes, the public key to verify it, and the Expert Witness transcript with each answer signed against the facts it was shown.

VERIFIEDTAMPEREDINCONCLUSIVE · unknown schemeINTEGRITY ONLY · HMACUNATTESTED · raw text
A

Reproducible

Signed record, open-weight model pinned by digest, inference configuration present, hardware attestation where available. The decision can be reproduced and compared, not just re-read.

B

Verifiable

Signed and anchored record. The model is hosted or closed, so the act cannot be reproduced, but the record is independently verifiable by a third party.

C

Asserted

No signature, no model pin. A raw log, an export, a screenshot, pasted text. inferX still types it, so the reader sees what it claims, but it needs corroboration.

What the format is not. inferX types records into legal categories and proves the typing. It does not interpret law, judge admissibility, assess weight or replace a lawyer. Reproducible does not mean correct. Those judgements belong to the legal layer, which this format is built to feed.

What we cover

Any signed record. The whole agent stack.

inferX reads records produced to the standard and the exports of the systems that implement it, and it degrades gracefully: raw text is accepted and typed, honestly graded C.

Sources verified today

  • Agent Audit Trail records from any conformant recorder, including the open aat-mcp recorder.
  • AgentPass Evidence ledger exports, the production WORM ledger with KMS or HSM signing.
  • AgentPass stack exports mixing four producers in one bundle: in-database enforcement, inference enforcement, policy enforcement and hardware human approval.
  • Evidence packs with Merkle anchoring and RFC 3161 timestamps.
  • Raw text: a pasted transcript, a log line, the words off a screenshot. One record per block, Grade C.

Acts the schema was built for

  • Inference over personal or special-category data: which model, which build, which prompt, which output, under what basis.
  • Payments and transfers: amount, counterparty, authority document, approval level, human receipt.
  • Data access, erasure and export: the resource, the classification, the lawful basis or its absence, the recipient.
  • Tool calls and refusals through the Model Context Protocol and agent frameworks, including denied calls recorded rather than dropped.
  • Physical and destructive commands: a valve, a pump, a production deploy, with the human approval that gated it, or the documented absence of one.
How to implement

Deploying court-grade evidence in your enterprise.

Five steps, all inside your own cloud. Nothing is added to the agent's request path and nothing leaves your boundary. You end up with facts your legal counsel can use under their own methodology.

1 · GatewayAgentPass or Trust Gateway in front of agents and sensors
2 · Evidence Ledgersigned, chained, write-once, in your cloud
3 · ExportinferX-compatible evidence file
4 · inferXverify · sort · grade · seal
5 · Court-ready appraisalto your legal counsel
STEP 1 · DEPLOY A GATEWAY

Put a gateway in front of your agents

AgentPass for AI agents and tool calls, or the Trust Gateway for sensors and industrial systems. Every action an agent takes, and every refusal, becomes a signed record with the agent's identity, its trust level and whether a human approved it. Your agents and tools do not change.

STEP 2 · DEPLOY THE EVIDENCE LEDGER

One sealing authority, write-once

The AgentPass Evidence ledger runs in your cloud as the single place records are sealed: hashed, signed with your KMS or HSM key, chained in order, stored write-once. It is the court-grade evidence ledger. Its exports are inferX-compatible by design.

STEP 3 · EXPORT

One signed file per matter

Export the records that relate to a question, an incident, an audit or a claim. One file, with the public keys inside it, that anyone can verify without access to your systems.

STEP 4 · INGEST INTO INFERX

Verify, sort, grade, seal

inferX runs in your cloud too. It re-verifies every record, sorts each one into the facts a legal finding needs, grades how far each can be trusted, flags anything uncertain, and seals the result so the work itself is provable.

STEP 5 · HAND TO COUNSEL

A court-ready appraisal, not a log dump

The pack goes to your legal counsel, who apply their own methodology to admissibility, procedure and presentation. They start from verified facts with a known provenance and grade, which is what lets them support the case rather than reconstruct it.

Runs in your cloud

Software you run. Not a service that sees your data.

Gateway, ledger and inferX are all delivered as software and run inside your own environment. "Nothing left the building" is a provable statement, not a promise.

Your cloud, your rackAWS, Azure, GCP, a sovereign cloud or on-premises hardware.
No egressNo telemetry, no model calls out, no dependency on CyberSecAI at run time.
Your keysThe ledger seals with your KMS or HSM key. Verification needs only the public key.
DeterministicFixed execution, pinned tool and model versions, byte-identical reproduction.
Attested where availableOn confidential-compute hardware inferX runs in an attested environment and the attestation goes in the pack.
Air-gap readyEvaluation and production deployments with no internet path at all.
Licence & contact

Request a licence.

inferX is licensed to organisations that need defensible evidence of what their AI agents did: regulated enterprises, critical infrastructure operators, law firms and forensic practices, and the platforms that serve them. Evaluation deployments are available.

Tell us three things

  • What your agents do and where the records live today.
  • Who will consume the packs: counsel, auditor, regulator, insurer.
  • Where it must run: cloud, on-premises, sovereign, air-gapped.

We reply with a scoped evaluation, the deployment container, and a commercial proposal. Standard terms cover a per-deployment licence with support and model updates; enterprise and partner terms are available.

contact@agentsign.dev →

What a licence includes

  • The inferX container for your environment, with the current typing model and schema version pinned and fingerprinted.
  • The AgentPass and MCP plugin for automatic ingestion from AgentPass Evidence and conformant recorders.
  • Evidence pack export in PDF and JSON, re-verifiable with the published key.
  • Schema and model updates under version control, so packs produced today remain interpretable.
  • Support from the people who wrote the standard.

For legal practices and methodology partners we offer co-branded packs and a hand-off designed around your procedure.

Drafts & IP

Two open drafts. One licensed method.

We publish the formats at the IETF so that evidence outlives any vendor, including us. The Typed-Evidence Record is the flagship: it defines what inferX produces. The Agent Audit Trail is what it consumes. We license the method in between.

FLAGSHIP DRAFT · EVIDENCE FORMAT

Typed-Evidence Record

draft-sharif-typed-evidence-record, IETF Internet-Draft, revision 00 published 3 October 2026. The format of what inferX produces: the fifteen legally operative categories, the trust grade, the verification verdict and the re-sealed record, so any party can read, verify and build on a pack without inferX.

RECORD FORMAT · COMPANION

Agent Audit Trail

draft-sharif-agent-audit-trail, an IETF Internet-Draft series by Raza Sharif, CyberSecAI Ltd, with independent implementations. The record layer inferX consumes. Home: aat-standard.org.

PATENT

GB2623300.7 · patent pending

Method and system for reproducible legal-accountability typing and trust-grading of machine-generated evidence. CyberSecAI Ltd. Further applications across the AgentPass evidence stack are filed in the United Kingdom with international filings in progress.

TRADE MARKS

CyberSecAI™

CyberSecAI™ is a trade mark of CyberSecAI Ltd (UK application 00004362551, classes 9 and 42). AgentPass and inferX are product names of CyberSecAI Ltd. The LATS schema, corpus and method are © 2026 CyberSecAI Ltd and are licensable.

Questions

Straight answers.

Does inferX decide whether evidence is admissible?

No. It verifies, types, grades and seals. Admissibility, weight and procedure are for counsel and the court. The pack is built to make that work faster and harder to challenge, not to replace it.

Does any data leave our environment?

No. inferX runs in your cloud or on your hardware with no outbound dependency. The typing model ships inside the container. The Expert Witness runs on a local model. Nothing is sent to CyberSecAI or anyone else.

Can the other side verify a pack without you or us?

Yes. Every pack carries the public keys and enough structure to recompute every hash, verify every signature and walk every chain with standard cryptographic tooling. The open aat-mcp verifier does it in one command.

What if our records are only HMAC-sealed, or only logs?

They still go through. HMAC-sealed records are reported as integrity-only: hash and chain reproduced, non-repudiation not available without the shared secret. Plain logs are typed and graded C. The pack makes the upgrade path obvious, and recording to the standard is the first step up.

Is the typing deterministic? Can it be reproduced later?

Yes. Fixed compute configuration, pinned tool version, fingerprinted model, no sampling. The same record produces byte-identical typed output on every run, and the pack records the fingerprints that let a later run be compared.

Which jurisdictions and regimes does the schema serve?

The fifteen categories are jurisdiction-neutral: attribution, provenance and authority are what every regime asks about. They map directly onto EU AI Act record-keeping and human-oversight duties, data-protection accountability, and financial-services accountability regimes. Jurisdiction-specific interpretation is the legal layer's job.

Is there a command-line client?

The platform and the AgentPass and MCP plugin are available to licensees today. A command-line client that talks to a licensee's own inferX deployment is on the roadmap.