AI Accountability · Records, Verifies & Notifies

AGLedger is the accountability layer for autonomous work.

A tamper-evident audit trail across Intent, Delegation, Results, and Verdict — while keeping the humans and systems around it in the loop.

Precisely, it's a cryptographic notary: records are Ed25519-signed, hash-chained, and verifiable offline by anyone holding the public keys.

An agent-optimized API, CLI, and MCP server adapt it to almost any automated system — from a single agent to delegation chains spanning departments and companies.

Run one per project; federate them when work crosses between them. All data stays in your PostgreSQL.

What else is in the box

Integrations →

Trace IDs from OpenTelemetry, Langfuse, Arize, Datadog and others ride inside the signed envelope. Webhooks signed with HMAC or Ed25519 (RFC 9421). OCSF SIEM export. Five API surfaces.

Custom schemas →

Customer-defined contract types. JSON Schema for criteria and completion. Content-addressed manifests so peers can share vocabulary without a central catalog.

Deployment →

Self-hosted in your infrastructure. Docker Compose or Kubernetes. PostgreSQL 17+, Node 24 LTS. No phone-home, no kill switch. Air-gap capable.

Security →

Full cryptographic architecture. COSE_Sign1 over in-toto v1 Statement, deterministic CBOR, append-only enforcement at the database layer.

API, CLI & MCP →

194 routes over OpenAPI 3.0, plus a CLI and an MCP server. Responses carry nextSteps and hint fields, so agents drive it without scaffolding. RFC 9457 errors.

Already have a platform? →

AGLedger is not an agent platform. It runs underneath what you have — or alone, if you do not. LangSmith, Galileo, Helicone — complement, not replace.

On your infrastructure

AGLedger runs on your systems. You hold the database, the keys, and the records. No phone-home, no kill switch. If the license lapses, the software keeps running, and security patches stay free regardless of support status.

Verifiable without us. Anyone holding the public keys can confirm the chain offline. The proof outlives the vendor.

Try it

Developer Edition. Free to use. Production-capable.