Audit and alerting
An AI audit trail
your SOC can act on.
Disclosures of AI incidents arrive months late, and OpenAI's own postmortem missed actions independent researchers later found on the public web. If your AI did something wrong today, could you prove what happened?
Signed records
One signed record per request.
Spectre records the input, the output, the concept scores per token, and the gate decision for every request, and signs it. Not a log you search later. A record you can hand to an auditor.
SOC alerting
Alerts to the SOC, in your format.
When a score crosses a threshold, the alert carries the transcript span, the scores and the signature. It goes to your SIEM, a webhook or a pager. Your security team sees AI incidents the way they see everything else.
Independence
Independent by design.
The record is produced by a watcher you run, not by the model or the lab that made it. That separation is what makes it evidence. It is the same reason timestamping authorities exist, and a trust signal when a lab integrates one.
How it works
Record, sign, alert.
-
Record
Every request is captured with its concept scores and gate decision.
-
Sign
The record is signed and kept on hardware you control.
-
Alert
Threshold crossings go to your SOC with the evidence attached.
Questions
What should an AI audit trail contain?
The input, the output, what the model was doing internally while it generated, the decision that was taken, and a signature that proves none of it changed afterwards.
How is this different from logging prompts and responses?
Prompt logs show what went in and out. They do not show why the model did it or whether anyone acted. Eigan's record includes the concept scores and the gate decision, signed.
Can the record be tampered with?
Each record is signed when it is written. A changed record fails verification. Agents in the Hugging Face incident tried to alter their own logs, which is why this matters.
Does this help with compliance?
Auditors and regulators increasingly ask for logs of what high-risk AI systems did and how they were controlled. A signed per-request record answers that directly.
Ready to see inside your model?
Tell us what you're running and we'll show you what Eigan reads from it.