Tamper-evident records for automated decisions

Prove what your AI decided.

Every approval, refusal, flag or payout your systems make gets a receipt that anyone can check against the XODE blockchain. Not even you can change it afterwards — and that is exactly why your customers, auditors and regulators can believe it.

Your data never leaves your servers Verifiable without an account In production since Oct 2026
Example
SENTINEL RECEIPT
acme-lending · window #1,284
deny
Decision
loan_screen
Reason
dti_over_limit
About
0x41c9…e07a
Policy
0x6dd8…3ba7
Model
risk-gbm-2026-09
Committed
XODE block #5,012,880
✓record → leaf
✓leaf → company root · 3,410 records
✓root → chained commit
✓commit → global root
✓global root → XODE block
The problem

“Our logs say so” is not evidence.

When an automated system decides something about a person, the only record of it usually sits in a database controlled by the party being questioned. That is fine until someone disagrees.

A customer disputes a decision.

They insist they qualified for the reward, the refund, the loan. Your log says otherwise — but your log is the only witness, and you own it.

An auditor asks what the model did.

Which policy was live on the 14th? Which model version refused this application? Today the honest answer is “trust our database administrator.”

Regulation wants traceability.

Rules for AI and automated decisions increasingly require automatic, retained logs of what a system decided and why. Logs you can quietly edit carry little weight.

How it works

Four steps. Your data stays home in all of them.

01

Hash on your servers

Our client turns each decision into a canonical record and hashes it where it was made. Only the 32-byte hash is sent.

Your infrastructure
02

Sentinel commits

Every few minutes your hashes become one Merkle root, chained to your previous one, then folded with every other customer's into a single global root.

Sentinel service
03

Anchored on XODE

The global root is written to the XODE blockchain in one signed transaction. From that block on, no one can change what it commits to.

Public blockchain
04

Anyone verifies

Your customer, an auditor or a regulator checks a receipt in a browser or with one Python file — against the chain, not against us.

Anywhere, no account
What you get

Evidence that holds up when someone pushes back.

Cannot be rewritten

Change one character of a committed record — the verdict, the reason, the timestamp — and its receipt fails. Including for us.

Provably complete

Each window commits to its exact record count. Hand an auditor a window bundle and they can confirm nothing was withheld or slipped in.

An unbroken history

Every window links to the one before it. Deleting or rewriting a past window breaks every link after it — visible to anyone holding a later receipt.

Private by construction

We only ever receive hashes. Personal identifiers are pseudonymised with a key only you hold. Nothing about your customers reaches us or the chain.

Which policy, which model

A policy's id is the hash of its own text, and the model is part of the record. “What decided this?” has one answer, fixed at the moment of decision.

No lock-in, even to us

The verifier is one open file using only the Python standard library. If Sentinel disappeared tomorrow, every receipt you hold would still verify.

Use cases

Wherever an automated “no” costs someone money.

Ad & reward settlement

Pay-outs nobody can argue with

ad_reward · deny · cooldown_active

Each granted or refused reward is committed at the moment of decision. When a user insists they watched the ad, both sides look at the same receipt.

Lending & insurance

Explainable refusals

loan_screen · deny · dti_over_limit

Show an applicant, or a supervisor, exactly which policy version and model refused them — and prove it was not edited after the complaint.

Trust & safety

Moderation with a paper trail

moderation · remove · policy_hate_3b

Every takedown carries the rule that triggered it. Appeals start from a fixed record instead of a reconstruction.

AI assistants

Which model said that?

assistant · refuse · medical_advice

Commit each answer's model, system prompt hash and refusal reason. When an answer is challenged, you can show what was actually running.

Marketplaces & fintech

Fraud flags that stand up

risk_flag · hold · velocity_24h

Frozen payouts and blocked accounts are the decisions people fight hardest. Give each one a receipt the merchant can verify on their own.

Compliance

Logs a regulator can trust

window bundle · n=48,210 · #1,284

Retained, automatic, traceable records of what your AI decided — with completeness an examiner can check without access to your systems.

Already in production

Running on real decisions since 4 October 2026.

Sentinel first went live inside XODE omni, committing every ad-reward decision — granted or refused — to the XODE chain every hour. It was built to settle a real dispute: a day when users insisted they had earned rewards the system had refused.

8,800+decisions committed
Hourlyanchors, without a missed window
0.00275XON per anchor, for every customer at once
1 fileto verify any of them, stdlib only
Plain about the limits

What a receipt proves — and what it doesn't.

A trust product that overstates itself is worse than none. Here is exactly where the guarantee ends.

It proves

  • This exact record was committed and has not changed by a single byte since.
  • It existed no later than the finalized XODE block it is anchored in, written there by Sentinel's own anchor account.
  • With a window bundle, that every record from that window was disclosed.
  • That the company's history has no gaps or rewrites up to the latest window you have been shown.

It does not prove

  • That the decision was correct or fair — only what was decided, and under which policy.
  • That the record's own timestamp is accurate — the block gives the upper bound.
  • That a company submitted decisions it chose to hide. The fix is operational: give people their receipt id at the moment of decision, so a missing receipt is itself evidence.
  • Anything about a record during its open window, before it is anchored and finalized.
  • That no windows were cut off the end of a history — only someone holding a later receipt can show that.
Pricing

Start free. Verification is free, forever.

Trial

Wire it in and see a receipt verify.
$0
  • 10,000 records / month
  • Full receipts & bundles
  • Console & API keys
Start trial

Starter

One product, real traffic.
Contact us
  • 1,000,000 records / month
  • Everything in Trial
  • Email support
Talk to us

Growth

Several systems, audit season.
Contact us
  • 20,000,000 records / month
  • Priority support
  • Audit-ready bundle exports
Contact us

Enterprise

Regulated, high volume.
Custom
  • Unmetered records
  • Shorter windows, dedicated anchor
  • Self-hosted option & SLA
Talk to us
Questions

Before you ask.

Is my data put on a blockchain?

No. Your records stay on your servers. We receive only 32-byte hashes, and the chain receives a single root per time window that covers every customer at once. Nothing on chain identifies you, your customers, or how many records you sent.

Can XODE change or delete my records?

Not once a window is anchored. A change to any record changes the root, and the old root is already in a finalized public block. We could in principle anchor a second, different root for the same window — but both would sit on chain, signed by our key, for anyone to find: evidence of misconduct, not a quiet edit. Before anchoring, within the open window, a record is not yet proven — which is why receipts say which state they are in.

What happens if Sentinel shuts down?

Your receipts keep working. Verification needs only the receipt, the open verifier (one Python file or this site's verify page saved to disk) and any public XODE node. There is no Sentinel server in that path.

How do I stop personal data from leaking into records?

Pass identifiers through subject_hash(value, salt), a keyed hash. Without your salt, a record says nothing about who it was about; with it, you can show an auditor. Bulky or sensitive evidence goes in as a hash too.

How fast is a record anchored?

Records are grouped into windows (10 minutes by default) and anchored as soon as each window closes. Enterprise plans can run shorter windows.

Why a blockchain at all, not a signed log?

A signature proves who wrote a log, not that they did not write a different one later and sign that too. A public chain gives an outside clock and a record that nobody — including the signer — can withdraw.

Make your next “no” defensible.

Ten thousand records a month, free. Your first receipt verifies as soon as its window closes.