SIGNAL·NODUS
Evidence for AI agent deployments

When an AI agent acts on your behalf, can you prove why it was allowed to?

Signal Nodus reconstructs the record of an agent deployment after an incident, a board question, or an examiner's request, and watches the world for the next one.

Request a reviewHow it works

71cities watched
15sentinels
5being built
livebuildingplanned
Proof

We keep this record on ourselves first.

There are no client logos or case studies here yet. What we can show is the method, applied every day to the system that does the work.

Expectations before actions

Every uncertain action is preceded by a written expectation and followed by the outcome. Misses stay on the record.

A human at every door

Nothing is sent, published, bought or deployed without a named person's yes, and the yes is logged.

Evidence over self-report

A device, a log line or a person confirms each result. The system's own report of success is not enough.

Nothing is deleted

Old material moves to slower storage, so anyone can go back and check the work.

The question

Three questions every agent deployment now gets asked.

"What did it expect to happen?"

Without a stated expectation an action can only be judged after the fact. The review recovers the expectation for every action it can and names the ones where none was recorded.

"Who allowed it?"

A policy, a named person, or nothing. The record shows which, action by action, with the hand-off where a human decided.

"What happened, and where did it miss?"

Outcomes sit beside expectations, and every mismatch stays in the record. Examiners trust a record that shows its misses.

Security tools show what was blocked. The review shows why an allowed action was allowed, which is the question a board or an examiner asks.

The record

The incident evidence review.

Two to three weeks, one agent deployment. You provide the logs and two interviews. You get the record, its gaps, and a one-page summary written for the people who asked.

How the review works

timeline        every relevant action, in order, with its source
action record   expected · authorised by · outcome · mismatch, per action
gap list        where no expectation, no authority, or no outcome was recorded
oversight map   where a human could have overridden, and whether one did
mapping         each finding against the logging and human-oversight duties you are asked about
board page      one page, plain language, for the people who asked the question

Every finding cites the log line it came from, so nothing in the pack is an opinion without a source. Regulators ask for automatic, tamper-evident logs and for a person who can override or interrupt an agent. Insurers and boards ask the same in plainer words. The pack answers those requests in the form they take.

The watch

Sentinels that notice incidents from the record, not the news.

The sentinels read incident filings, breach notices, vendor disclosures, and security advisories that name the frameworks agents run on. A few are tripwires on our own servers that only an automated agent would follow. The globe above shows where each one is looking, and it fills in as more are built.

Every sentinel, mapped

filings         material cybersecurity incident disclosures, within days of filing
breach notices  state attorney-general and federal portals
vendors         incident posts from model providers and cloud platforms
advisories      security advisories naming agent frameworks and tool servers
tripwires       canary endpoints on assets we control, tripped only by bots

Every signal is treated as a claim until someone verifies it. The sentinels read public sources and our own servers only.

Trust

Your logs never reach the system that does the reasoning.

A review takes your agent's logs, which are proprietary. Raw data stays in a vault, the models see tokens in place of names, and every byte that leaves is logged and handed back to you with the pack.

The eight controls

A person owns and runs this service. An AI system does the reconstruction under that person's control, with a kill switch, and keeps the same record of its own work.

Request a review