Prove what your AI decided.
Years later.
A regulator, a court, or your own board asks why the model declined that claim in 2026. Frontier vendors retired those weights long ago. Decision Records exist so your answer is a replay, not a shrug.
- Reproducibility class assigned at decision time, not at dispute time
- Encrypted, per-tenant evidence bundles with policy-driven capture
- Replay against pinned weights, with engine drift detected and named
- Honest verdicts: identical, equivalent, or divergent, never pretended
/ How it works
From a live decision
to a defensible replay.
Decide
A consequential decision flows through the stack: a claim triaged, a transaction scored, a document judged.
Classify and capture
The record is stamped reproducible, reproducible-until, or not-reproducible, and a policy-selected evidence bundle is encrypted.
Store with intent
Bundles live encrypted per tenant. Retention expiry deletes the bundle but keeps the record: you always know what existed.
Replay on demand
The bundle re-runs against the pinned weights that decided. Engine fingerprints catch drift, and the verdict names it.
/ Capabilities
Everything this layer holds.
Classes, not promises
Reproducible means we hold the weights. Reproducible-until names an expiry. Not-reproducible is the honest default for frontier APIs.
Pinned-weight replay
Replay targets the exact model version that decided, on sovereign hardware, never a router's choice of whatever is current.
Drift detection
Serving-engine fingerprints ride along with every replay. A changed engine caps the verdict at equivalent and says why.
Encryption per tenant
Bundles are sealed with per-tenant derived keys. Capture is policy-driven for consequential decisions, never a blanket dragnet.
Retention with a memory
When retention expires, the evidence bundle is destroyed and the decision record survives, including its reproducibility class.
What we do not claim
No bit-exact determinism theater. Identical requires byte equality plus matching engine and weights; anything less is labeled equivalent.
/ The difference
An audit log says what happened.
A decision record can happen again.
The vendor deprecated the model. The decision can never be re-run.
Weights are pinned on hardware you control. The 2026 decision re-runs in 2029, on the same weights.
You discover a decision is unreproducible when the dispute arrives.
The class is stamped at decision time. You know what you can prove before anyone asks.
Evidence is raw logs of customer data, retained forever, readable by whoever finds them.
Encrypted per-tenant bundles, policy-scoped capture, and expiry that destroys evidence without erasing history.
Replays that differ get quietly rounded to a pass.
Identical, equivalent, and divergent are distinct verdicts, and the reason for anything short of identical is named.
/ The rest of the stack
One layer is a feature. Six is a fabric.

Ready to run on WIT OS?
Talk to the team about a managed deployment, a pilot, or a custom agent. We typically respond within an hour.
