Prove what your AI decided.
Every approval, refusal, flag or payout your systems make gets a receipt that anyone can check against the XODE blockchain. Not even you can change it afterwards — and that is exactly why your customers, auditors and regulators can believe it.
- Decision
- loan_screen
- Reason
- dti_over_limit
- About
- 0x41c9…e07a
- Policy
- 0x6dd8…3ba7
- Model
- risk-gbm-2026-09
- Committed
- XODE block #5,012,880
“Our logs say so” is not evidence.
When an automated system decides something about a person, the only record of it usually sits in a database controlled by the party being questioned. That is fine until someone disagrees.
They insist they qualified for the reward, the refund, the loan. Your log says otherwise — but your log is the only witness, and you own it.
Which policy was live on the 14th? Which model version refused this application? Today the honest answer is “trust our database administrator.”
Rules for AI and automated decisions increasingly require automatic, retained logs of what a system decided and why. Logs you can quietly edit carry little weight.
Four steps. Your data stays home in all of them.
Hash on your servers
Our client turns each decision into a canonical record and hashes it where it was made. Only the 32-byte hash is sent.
Sentinel commits
Every few minutes your hashes become one Merkle root, chained to your previous one, then folded with every other customer's into a single global root.
Anchored on XODE
The global root is written to the XODE blockchain in one signed transaction. From that block on, no one can change what it commits to.
Anyone verifies
Your customer, an auditor or a regulator checks a receipt in a browser or with one Python file — against the chain, not against us.
Evidence that holds up when someone pushes back.
Cannot be rewritten
Change one character of a committed record — the verdict, the reason, the timestamp — and its receipt fails. Including for us.
Provably complete
Each window commits to its exact record count. Hand an auditor a window bundle and they can confirm nothing was withheld or slipped in.
An unbroken history
Every window links to the one before it. Deleting or rewriting a past window breaks every link after it — visible to anyone holding a later receipt.
Private by construction
We only ever receive hashes. Personal identifiers are pseudonymised with a key only you hold. Nothing about your customers reaches us or the chain.
Which policy, which model
A policy's id is the hash of its own text, and the model is part of the record. “What decided this?” has one answer, fixed at the moment of decision.
No lock-in, even to us
The verifier is one open file using only the Python standard library. If Sentinel disappeared tomorrow, every receipt you hold would still verify.
Wherever an automated “no” costs someone money.
Pay-outs nobody can argue with
Each granted or refused reward is committed at the moment of decision. When a user insists they watched the ad, both sides look at the same receipt.
Explainable refusals
Show an applicant, or a supervisor, exactly which policy version and model refused them — and prove it was not edited after the complaint.
Moderation with a paper trail
Every takedown carries the rule that triggered it. Appeals start from a fixed record instead of a reconstruction.
Which model said that?
Commit each answer's model, system prompt hash and refusal reason. When an answer is challenged, you can show what was actually running.
Fraud flags that stand up
Frozen payouts and blocked accounts are the decisions people fight hardest. Give each one a receipt the merchant can verify on their own.
Logs a regulator can trust
Retained, automatic, traceable records of what your AI decided — with completeness an examiner can check without access to your systems.
Running on real decisions since 4 October 2026.
Sentinel first went live inside XODE omni, committing every ad-reward decision — granted or refused — to the XODE chain every hour. It was built to settle a real dispute: a day when users insisted they had earned rewards the system had refused.
What a receipt proves — and what it doesn't.
A trust product that overstates itself is worse than none. Here is exactly where the guarantee ends.
It proves
- This exact record was committed and has not changed by a single byte since.
- It existed no later than the finalized XODE block it is anchored in, written there by Sentinel's own anchor account.
- With a window bundle, that every record from that window was disclosed.
- That the company's history has no gaps or rewrites up to the latest window you have been shown.
It does not prove
- That the decision was correct or fair — only what was decided, and under which policy.
- That the record's own timestamp is accurate — the block gives the upper bound.
- That a company submitted decisions it chose to hide. The fix is operational: give people their receipt id at the moment of decision, so a missing receipt is itself evidence.
- Anything about a record during its open window, before it is anchored and finalized.
- That no windows were cut off the end of a history — only someone holding a later receipt can show that.
Start free. Verification is free, forever.
Trial
- 10,000 records / month
- Full receipts & bundles
- Console & API keys
Starter
- 1,000,000 records / month
- Everything in Trial
- Email support
Growth
- 20,000,000 records / month
- Priority support
- Audit-ready bundle exports
Enterprise
- Unmetered records
- Shorter windows, dedicated anchor
- Self-hosted option & SLA
Before you ask.
Is my data put on a blockchain?
No. Your records stay on your servers. We receive only 32-byte hashes, and the chain receives a single root per time window that covers every customer at once. Nothing on chain identifies you, your customers, or how many records you sent.
Can XODE change or delete my records?
Not once a window is anchored. A change to any record changes the root, and the old root is already in a finalized public block. We could in principle anchor a second, different root for the same window — but both would sit on chain, signed by our key, for anyone to find: evidence of misconduct, not a quiet edit. Before anchoring, within the open window, a record is not yet proven — which is why receipts say which state they are in.
What happens if Sentinel shuts down?
Your receipts keep working. Verification needs only the receipt, the open verifier (one Python file or this site's verify page saved to disk) and any public XODE node. There is no Sentinel server in that path.
How do I stop personal data from leaking into records?
Pass identifiers through subject_hash(value, salt), a keyed hash. Without your salt, a record says nothing about who it was about; with it, you can show an auditor. Bulky or sensitive evidence goes in as a hash too.
How fast is a record anchored?
Records are grouped into windows (10 minutes by default) and anchored as soon as each window closes. Enterprise plans can run shorter windows.
Why a blockchain at all, not a signed log?
A signature proves who wrote a log, not that they did not write a different one later and sign that too. A public chain gives an outside clock and a record that nobody — including the signer — can withdraw.
Make your next “no” defensible.
Ten thousand records a month, free. Your first receipt verifies as soon as its window closes.