Infyrence
Every major agent platform tells you to build your own tamper-evident audit log.
We checked seven. None of them ship one. Policy enforcement has been commoditised; evidence has not. We build the part that is missing, in the open.
The survey
Pre-execution policy enforcement, and whether the audit trail is cryptographically verifiable. Read from shipping documentation. Corrections welcome — the point of publishing it is that you can check it. Read October 2026.
| Platform | Pre-tool policy | Verifiable audit |
|---|---|---|
| AWS Bedrock AgentCore | GA — gateway-bound | No |
| Google ADK / Agent Runtime | GA — per-SDK callback | No |
| Microsoft Foundry | Preview | No |
| Vercel eve | Observe-only hooks | No |
| LangSmith / LangGraph | None | No |
| Cloudflare Agents | Gateway DLP only | No |
| OpenAI AgentKit | Tool guardrails | No |
Every one documents it as something the customer builds — S3 Object Lock, GCS Bucket Lock, Confidential Ledger, “sign your writes with KMS.” An audit log written by the process being audited, which that process can rewrite, is the producer’s own account of itself.
What we build
infy — Apache-2.0, on PyPI. The enforcement path is open because a control plane you cannot read is one you cannot trust.
- Decided before it runs
- Policy is evaluated in-process at the tool call, roughly 50 microseconds. Deny by default, fail closed. A refused call never reaches the network.
- Recorded so it can be checked
- Every decision — allowed, refused, or approved by a named person — is appended to a SHA-256 hash chain. Alter one entry and verification fails.
- On the agents you already run
- Six surfaces without modifying the agent: infy, LangChain, smolagents, OpenHands, Agno, and the Model Context Protocol — the last governs any MCP client talking to any MCP server.
- Where it does not reach
- A self-anchored chain proves nothing was altered; it does not prove an independent party witnessed it. External anchoring is not built yet. Our benchmarks publish the cases where this approach loses.
Writing
Contact
If you are running agents with real authority and cannot currently prove what they did, that is the conversation worth having.
Email [email protected].