Sentinel-class monitor · for AI agents

Proof of what your AI actually did.

Your organisation's agents write files, run commands and reach the network all day. Siphrix gives the people answerable for that — security, compliance, the CISO — the record: every action, captured from outside the agent on every enrolled machine, in a chain where removing or changing an earlier entry breaks it, and hiding that would mean re-sealing every entry after. Coverage gaps are named, evidence exports verify offline, and it never blocks — so it deploys in a day.

WatchesChatGPT · Claude · Gemini
Copilot on the web · coding agents
Proofverifies offline
Storesmetadata only · on the machine
and in your console
Blocksnothing — by design
How a line of the record reads — an illustration

Nothing shown here happened. Observing, not interfering — nothing blocked, everything on record.

Evidence mapped to ISO/IEC 42001, SOC 2, the EU AI Act & GDPR Source-available — verify, don't trust EU-hosted · dedicated instance per customer Metadata only — never prompts or file contents Signed, offline-verifiable reports
The difference

Observability shows you a claim. Siphrix gives you evidence.

Tracing tools ask the agent to report on itself. When an agent is compromised — prompt injection, a hijacked tool call, or simply a bug — the trace describing its behaviour is written by the very code that misbehaved. A self-reported trace is a claim. Siphrix records from outside the agent, where the action is about to happen.

Recorded from outside

Siphrix hooks the agent's harness, so the record never depends on the agent being honest, correct or uncompromised. It sees the action — not the agent's account of it.

A chain, not a log

Every entry carries a SHA-256 over its own fields and the hash before it. Remove or change an earlier entry and the chain breaks there; hiding it would mean re-sealing every entry after it. One click re-walks the chain and names the entry. The newest entries have nothing after them to break, so Verify also gives you a head hash to keep: compared later, it shows whether any of them went missing.

Proof someone else can check

Send an auditor a signed, expiring link. They open it with no account and see the attestation — never your files, never your commands. Revoke every link instantly.

One record, every surface

Terminal, VS Code and browser on every enrolled machine report into the same record. Coding agents, ChatGPT, Claude and Gemini — one place that knows what all of them did.

The auditor's language

The report arranges your record against four frameworks — ISO/IEC 42001, SOC 2, the EU AI Act and GDPR — and names the control each entry answers, from ISO/IEC 42001 A.6.2.8, recording of event logs, to GDPR Art. 17, erasure. It names, just as plainly, the four GDPR articles it does not answer: 5(1)(b) and 30 are evidenced by documents you keep as controller, 33 has no breach register here, and 15 — a subject access export — writes no entry of its own. Nothing is marked satisfied; that judgement is the auditor's. Evidence you can file, not a screenshot.

It never blocks

An observer must not break the thing it observes. Nothing is stopped by default — which is why Siphrix goes in during a sprint, not a procurement cycle.

The blind spot

Your AI already acts in your name. Nobody is watching.

Every tool your teams connect can touch files, reach the internet and move money. Siphrix is the page your security team checks afterwards — and the alarm that fires before they have to.

It deletes files

One misread instruction and a folder is gone — and without a record, you can't say which agent did it, or when, or why.

Severity: critical

It leaks data

A pasted secret, an uploaded document, a message to the wrong place. Siphrix knows the shape of a leak, and the warning is in your console within minutes.

Severity: high

It spends money

Payments, subscriptions, purchases — agents can do all of it. Every attempt becomes an entry; the dangerous ones rise to the top.

Severity: critical
What your organisation gets

Three teams. One record. Each gets the answer they are paid to have.

Without a record, every one of these questions ends in a meeting nobody enjoys. With one, each ends in a page someone opens.

Compliance

“Who put what into the AI?”

  • Personal data going into an AI — national-insurance numbers, cards, payroll rows — flagged by category, never by content, in your console within minutes.
  • A confidential file handed to Copilot raises a critical alert with the person, the machine and the time.
  • Once your Microsoft 365 connection is configured, one click answers who else can open that file — grants, groups, sharing links.
  • A monthly report, cryptographically signed, that an auditor can verify without ever calling us.

IT & Security

“What runs where — and is the policy real?”

  • Every laptop on one page: the person at the keyboard, what runs, when it last reported.
  • Rollouts you can watch — deploy from Intune or your RMM, then watch the fleet update itself.
  • Proof the allow-list actually holds on the endpoint — including the local models a DNS filter can never see.
  • Sign-in through your identity provider; joiners and leavers handled by your directory, sessions cut as soon as your directory reports the leaver.

Finance & Legal

“Is what we pay what we use?”

  • Contracted vs consumed, per AI provider — what you signed against what the record shows actually flowed, priced from your own agreement.
  • Legal holds that freeze deletion for the length of a dispute — and are themselves on the record.
  • The right to leave, engineered in: an expired contract still reads and exports everything; deletion is total and demonstrable.
How it works

Connect once. The record writes itself.

01

Link

Your IT deploys Siphrix like any other fleet software. Each machine enrols with one connection code from your console — its browsers, editors and coding agents all report through that one connection. Siphrix runs beside your tools, never in front of them.

02

Record

Files touched, commands run, sites reached, data shared — each becomes one clean, timestamped entry, sealed to the entry before it. Metadata only — never your prompts or file contents. Commands and file paths are recorded, with secrets masked.

03

Alert

A file handed to a chat site, a destructive command, a payment — anything dangerous-looking is flagged by severity, with the reason in plain language, within minutes of happening.

An illustration — nothing shown here happened. The seals are real SHA-256s computed in your browser, but over a simplified entry. In the product, each entry's seal covers its recorded fields and the seal before it, and the console's Verify re-walks the chain in order and names the first entry whose seal no longer matches.

“An observer must never break the thing it observes. Siphrix watches everything — and touches nothing.”
— Sentinel design rule · held since v1
The record

Everything a record should be.

Complete

Every decision from every connected surface — browsers, editors, agents on each machine. One timeline, exportable.

Ranked by severity

Critical first, low last. Secret-shaped pastes, destructive commands, data egress — flagged when they reach your console, within minutes of happening.

Readable

Plain language on the surface, verdicts and reason codes underneath — for the day you need to know exactly what happened.

Loud where you live

One webhook forwards warnings to Slack, Teams or your SIEM. Mute noisy rules; bursts escalate on their own.

Private by construction

Runs on your machine. Metadata only — action, app, verdict, time, and the command or file path involved, with secrets masked. Never file contents, never message text.

Never in the way

Siphrix records and warns; it does not stop the action, so it cannot break anyone's work. There is no blocking mode to buy today — prevention is a future tier, not a switch in this console.

Signed at the source

Every machine signs its entries with a key that never leaves it. An auditor verifies the export on their own computer, offline — siphrix verify-evidence — without trusting us or you.

Honest about coverage

siphrix coverage names what this machine runs that nothing records. A named gap beats a clean-looking console that silently omits a surface.

Built for providers

Run security for thirty companies? One Clients screen, health numbers only, worst first. Their entries never cross to you — reading a record takes that client's own sign-in.

Region-pinned, if promised

An account pinned to the EU is served by the EU instance and refused — explicitly, naming both sides — anywhere else. A residency label that moves no data is a lie; this one refuses instead.

Questions

Fair questions, straight answers.

Do I need to be technical?

No. Siphrix senses your surfaces on its own. Recording is simply on or off per machine: Off means that computer stops recording, and nothing from an Off period arrives later. What deserves a warning is written as rules in plain words — “warn me when a file is uploaded to a chat site”. The technical detail exists underneath for those who want it, and stays out of the way for those who don't.

What happens when something risky is spotted?

It lands in your Warnings within minutes, ranked by severity, with the reason in plain language. Forward it to Slack, Teams or a SIEM if you like. The action itself is not stopped — you stay in charge.

Can it actually block things?

No — not today, and on purpose. Siphrix is the record and the alarm: it writes down what happened and warns the people who should know, and the action itself goes ahead. Nothing in the console turns a warning into a hard stop. Prevention is a future tier; when it exists it will be a decision written once for the account, in Rules, not a setting on somebody's laptop.

Will it slow down or break my tools?

No. The record is written beside your tools, not in front of them. Even if Siphrix itself fails, your workflow continues untouched — that is a design rule, not a promise.

Where does my data go?

To your organisation's console, and from there only to a webhook, SIEM or email you set up. Each enrolled machine keeps its log as metadata — the action, the app, the verdict, the time, and the command or file path involved, with secrets masked — and reports those entries to your console. Your prompts and file contents never leave the machine.

Couldn't you — or we — just edit the log?

That is the question an audit product must answer or admit it is a diary. Every entry is hash-chained to the one before it, so removing or editing an earlier entry breaks the chain at that entry, and hiding the break would mean re-sealing every entry after it. The newest entries have nothing after them to break: for those, keep the head hash Verify shows and compare it later. And separately: every machine signs its entries with a key that never leaves it — not to us, not to the console. Export an evidence pack and siphrix verify-evidence re-checks every signature on your own computer, offline, with Siphrix switched off. A signed entry that was edited fails. An entry no machine signed is reported as unsigned, and --require-signed fails the check on it — so an invented entry cannot pass as signed. For everything your machines signed, we could not forge your record if we wanted to, and that is the point.

What's free, and what do you actually charge for?

The licence changed at 2.0.0, so here is the whole truth, in order. Versions 1.8.9 and earlier are MIT. Forever. That is everything already published — the PyPI releases up to 1.8.9, the browser extension 0.8.x, the VS Code extension 0.12.x — and it is irrevocable: nothing we do from here relicenses a byte of it. This answer used to promise the whole product under MIT; that promise still binds every version it was made about, and the repository keeps the old claim on record — marked superseded, never deleted — because an audit product that rewrote its own history would deserve none of your trust.

From 2.0.0, Siphrix is source-available under the Business Source License 1.1. You can still read every line — the engine, the bridges, the console — which is the same reason the evidence bundle verifies offline. Production use requires a commercial license. Write to hello@siphrix.com: a person answers and an invoice follows, not a checkout page. And BUSL is a timed licence, not a permanent one — every version becomes MIT four years after its release.

We're a provider — can we watch all our clients at once?

Yes, with their consent and within a hard boundary. Each client creates a one-time code in their own console; you redeem it and they appear on your Clients screen — health numbers only, worst first. You see how much happened, what is waiting, where the gaps are. You never see their entries, rules or keys: reading a record still takes that client's own sign-in, and either side can end the link at any moment.

Our records must stay in the EU. Can you promise that?

We can refuse, which is stronger than promising. An account pinned to a region is served only by that region's instance — a valid sign-in presented to the wrong region gets an explicit refusal naming both sides, not a quiet redirect. And the pin is one-way: moving later means export, delete, re-enrol, because a label change that moves no data would be a lie.

Put your AI on the record.

Every agent your organisation runs, on one tamper-evident record your auditor can verify — deployed in a day, not a quarter. Tell us what you run; a person answers.

Prefer email? hello@siphrix.com · ChatGPT · Claude · Gemini · coding agents