The day you have to answer for it.
Every firm that handles client files will be asked, sooner or later, what the AI did with them. Most cannot answer, because nothing on the machine was recording at the level where the answer lives. Attest is a boundary your compliance officer can read, a sealed record of what the AI did, and one page a month that says what the record holds.
Deployed and run by ProjxAI, compiled for your firm. Never a public download, which is what makes it safe to run. Pricing per machine per month, quoted after a boundary conversation.
The boundary as a plain file, the sealed ledger, a monthly attestation per machine, and an independent verifier that checks the record without our software.
The Recorder and the Ledger are built and tested; the resident Watcher is the next phase. We say what is built, not what is planned.
What it is
Every endpoint security product asks one question: is this software malicious? An AI agent is not malicious. It is authorised, paid for, runs as the signed in user, holds that user’s credentials, and acts on instructions that arrived as text, sometimes from a web page it was asked to summarise. Nothing in the security stack was designed for that, and none of it can answer the question a partner is actually asked: what did the AI do here, and can you prove it.
Attest records that answer. The machine is configured so the evidence exists (Windows ships with most of it switched off). Every AI attributable action is written to a ledger where each entry is sealed over the one before, so alteration, removal or back dating is not merely detected but located. A separate verifier, with no dependency on our code, checks the record and exits with a result. Your client’s auditor does not have to believe us; they can check.
This is for you if
- You are a partner or principal in a practice that holds client files
- AI tools are already in use, or a staff member is about to bring one in
- You would rather have the record before the question than after it
Not for you if
- You want a security product; this is an accountability record and works beside your security tooling
- Nobody in the firm is willing to own the boundary file
- You need the live Watcher today; it is the next phase and we will tell you when it ships
How it runs
- 1 · 1 conversation
Boundary
Which paths AI may read, which hosts it may reach, what must never happen without someone being told. Written as a file your compliance officer can read and argue with.
- 2 · install
Record
The machine configured to keep the evidence, recording switched on and verified to have stayed on, the ledger started with a sealed genesis entry.
- 3 · monthly
Attest
One page per machine: what the AI touched, what the boundary was, what crossed it, and a verification hash.
- 4 · any time
Verify
The standalone verifier checks the ledger and the attestation without our software present. Removing Attest leaves the record behind.
In writing, before we start
Three sentences that hold on every engagement. They are the method, written as promises.
The measure, the budget cap and the point at which we stop are set in the written scope before anything is billed. Nothing moves the goalposts afterwards.
Everything we build runs in your accounts and is yours: code, configuration, documentation and measurements. We hand over; there is no dependency on us.
If the pilot does not hit the measure we agreed first, we keep working at no further cost until it does, or we stop and say so in writing. You will not be sold the next step by the first one.
Questions it answers
- What did the AI read, and on whose instruction?
- Did anything leave the machine, and to where?
- Was the recording on the whole time?
- Has anyone altered the record since?
What it deliberately is not
- A public download with a shared update channel to attack
- A dashboard to watch on a good day
- A replacement for your security tooling
- A claim about the Watcher before the Watcher exists
What you receive
Where does your practice stand today?
Seven questions a partner can answer in a minute. The reading appears at once; nobody asks for your email.
A reading of where a practice stands the day it is asked what its AI did. It is not advice and nothing you enter leaves your browser.
- 01Do staff use AI assistants (ChatGPT, Copilot, Claude or similar) on machines that hold client files?
- 02Has any AI tool been given access to email, documents or a practice system, even for a trial?
- 03Is there a written statement of what AI may and may not read or send?
- 04If asked today what an AI did with a client’s file last month, could you produce a record?
- 05Are process command lines, script activity and per process network connections being logged on those machines?
- 06Do your engagement letters or client terms say anything about AI use?
- 07Has a client, insurer or regulator already asked you about AI use?
Questions
Why not a public product?
A signed, privileged agent on strangers’ machines paints a target on the update channel. Compiled per client and deployed by us there is no shared signing identity worth stealing and no channel worth attacking, and the boundary is tuned to the firm rather than to a lowest common denominator.
Does it slow the machine or watch staff?
It records what AI processes do, attributed to the agent, within the boundary the firm declared. It is not a monitoring tool for people, and the boundary file says exactly what is recorded.
What does the attestation look like?
One page. What the AI touched, what the boundary was, what crossed it and whether the record is intact, with a hash your auditor can check against the ledger.
When will you be asked?
Tell us what your firm holds and which AI tools are in the building. The boundary conversation is the first hour, at no charge.