AI-Safe Operations Governance Platform

Every incident, governed.
Every action,
cryptographically witnessed.

Acta is the tamper-evident audit layer for organisations that cannot afford to lose trust — in their operations or their AI systems.

Start 90-day free pilot → View live dashboard
CHAIN VERIFIED
HMAC-SHA256 cryptographic chain — active All incident records signed and linked. Zero tampering detected.
Events
42ms
Verify
0
Errors
Compliance framework coverage

One platform.
Two distinct missions.

The same cryptographic infrastructure serves both compliance-sensitive regulated industries and engineering teams governing AI in production.

🏛
Model A

Compliance Evidence
& Incident Learning

Turn operational incidents, response history, and corrective actions into audit-ready, tamper-evident records. Built for the moment an accreditation auditor asks: "Prove this was not altered."

JCI Hospitals Bangladesh Bank MFS SOC 2 Orgs Regulated SaaS
Cryptographic chain on every incident event — tamper-evidence at DB tier
JCI, SOC 2, and BB MFS evidence reports from verified chain data
Postmortem quality gate — readiness-evaluated before publication
12-artifact evidence pack with security, overclaim, and wording gates
🤖
Model B

AI-Safe Operations
Governance

AI can propose operational actions. Only governed, approved, auditable actions can execute. Built for the moment an auditor asks: "Show me exactly what your AI did, when, and who approved it."

AI-first Fintechs SRE / Platform Teams EU AI Act Regulated AI Ops
Policy-as-code: approval rules enforced at the database tier
AI actions enter candidate layer — no direct execution authority
Every AI command registered, dispatched, and cryptographically audited
Governance snapshot: who approved what, when, under which policy

From incident to auditor-ready evidence
in one governed pipeline.

01
Incident enters the event gateway
Manual, webhook, or AI-generated incidents enter through the ops gateway. Candidates are created — no direct execution yet.
ops_event → ops_adapter
02
Policy evaluation & governance gate
Every command is evaluated against the active policy version. Sensitive actions require approval before crossing the protected execution boundary.
ops_governance → approval gate
03
Cryptographic chain — every event signed
Each incident event is signed with HMAC-SHA256, linked to the previous event's hash, and stored in an append-only ledger. Tampering with any record breaks the chain and is detected immediately.
ops_audit Layer 2 — HMAC-SHA256
04
Postmortem — evidence-linked learning
After resolution, a postmortem with 7-check readiness gate must pass before publication. Evidence links, timeline snapshots, action items, and learning taxonomy are all attached.
ops_postmortem → SHA-256 sealed revision
05
Auditor-ready evidence report
Compliance reports are generated from verified chain data only. JCI, SOC 2, and Bangladesh Bank MFS frameworks. 12-artifact evidence pack with honest disclosures — no overclaiming.
ops_audit Layer 5 — Evidence Production

Enterprise-grade from day one.

Cryptographic Audit Chain
HMAC-SHA256 chain on every incident event. Any modification of a committed record produces a hash mismatch detected on next verification. Enforced at the database trigger tier — application code cannot bypass it.
Layer 1-3 of 5-layer audit posture
📋
Compliance Reports
JCI (MOI.11, QPS.7.1, QPS.7.2, GLD.4), SOC 2 (CC6.1, CC7.2, CC7.3), and Bangladesh Bank MFS (§4.3, §5.2) compliance reports generated from verified chain data. Not from assumptions — from proof.
Layer 5 — Evidence Production
📎
Evidence-Linked Postmortems
Draft to sealed publication with 7-check readiness gate. Evidence links, timeline snapshots, action items, learning taxonomy. SHA-256 revision sealing. Post-publish mutation blocked at DB tier.
ops_postmortem — 8M.14
🏛
Policy-as-Code Governance
Approval requirements enforced at the database tier, not by code review. Deterministic policy evaluator. Approval-gated execution. Every governance decision immutably logged.
ops_governance — 8M.12
📊
Operational Health Intelligence
Composite health score with risk flags, freshness indicators, and confidence scoring across incident, SLA, governance, provider safety, and evidence integrity dimensions.
ops_metrics — 8M.13
🔍
Operator Activity Audit
Every privileged admin action — governance approvals, postmortem publications, evidence exports — logged in an append-only ledger with risk classification. The boundary integrity panel shows zero protected mutations, always.
ops_admin_audit — 8M.15

Defence-in-depth.
Each layer independently verifiable.

L5
Evidence Production
JCI, SOC 2, BB MFS reports from verified chain data. 12-artifact evidence pack.
✓ Active
L4
External Immutable Mirror
Chain hashes streamed to S3/WORM storage. Independent of database environment.
Enterprise
L3
Continuous Chain Verification
Scheduled verification. Tamper detection. Staleness alerting. Verification log.
✓ Active
L2
Cryptographic Chain
HMAC-SHA256. Each record signs prev_hash + content. Vault-encrypted key.
✓ Verified
L1
Append-Only Foundation
DB triggers prevent UPDATE/DELETE on all audit tables. Cannot be bypassed by application code.
✓ Active

The only operations governance platform built for BB MFS compliance from day one.

Bangladesh Bank MFS §4.3 and §5.2 compliance templates are fully implemented. Incident audit trails and evidence reports ready for BB MFS examiners — not as an afterthought, as a core feature.

90
Day free pilot for BB MFS regulated organisations
2wk
From signing pilot agreement to live evidence reports
§4.3
Incident reporting template — fully implemented
§5.2
Audit trail requirement — fully implemented
Bangladesh Bank MFS §4.3 — Incident Reporting
Cryptographically signed incident records with tamper-evidence, complete event timeline, and verifiable audit trail for BB MFS examination.
template: active · chain: verified
Bangladesh Bank MFS §5.2 — Audit Trail
Append-only audit ledger with operator accountability, governance decision history, and evidence pack downloadable for examiner handoff.
template: active · reports: ready
JCI Hospital Accreditation
MOI.11, QPS.7.1, QPS.7.2, GLD.4 compliance evidence. Incident completeness, tamper evidence, governance compliance, and response time analysis in one report.
template: active · chain: verified

Start with a pilot.
Scale when you're ready.

All plans include chain verification, postmortems, and health intelligence No hidden limits on core governance
90-Day Pilot
Free
Signed engagement agreement required
500 incidents/month
5 operators
BB MFS framework
Chain verification
Postmortems
Health intelligence
Direct founder support
API access
Start free pilot →
Starter
$500
per month · billed monthly
500 incidents/month
5 operators
BB MFS framework
Chain verification
Postmortems
Health intelligence
API access
JCI / SOC 2 frameworks
Get started →
Enterprise
$5,000+
per month · custom terms
Unlimited incidents
Unlimited operators
All frameworks + custom
External mirror (Layer 4)
Ed25519 asymmetric signing
Dedicated SLA 24/7
Custom framework templates
Annual contract
Contact us →
Bangladesh Bank MFS regulated organisations: 90-day free pilot + go-live in 2 weeks.  ·  All pilots include direct access to the founder.

Governance before autonomy.
Trust before AI execution.

Start your 90-day free pilot today. No Stripe required. Sign a pilot agreement and go live in two weeks.

Pilot engagement agreement only. No credit card. Cancel anytime.

JCI Hospitals Bangladesh Bank MFS SOC 2 Orgs AI Governance Teams