Audit VaultEvery step signed. Every decision explainable.
Tamper-evident HMAC-SHA256 trace. Downloadable decision receipts. Offline verification with one CLI command — auditors never call home.
Eight step types. One request. One signed trace.
Every stage of a request is an explicit step.
Download a receipt. Verify offline.
{"trace_id": "trace_01HQ5V8K3P7Z2MJR9","decision": "BLOCK","key_id": "vsk_prod_04","tool": "postgres.query","score": 8,"triggered_checks": [{"id": "CHK-002","detail": "DELETE not in allowed_operations [SELECT]"}],"modifications_applied": [],"request_hash": "sha256:3b2d…91a","signed_at": "2026-04-15T09:41:22Z","signature": "hmac-sha256:a7b9c2…4f8e"}
↓ Download receipt$ verosek-verify-receipt receipt.jsonreading receipt.json ...signature: hmac-sha256:a7b9c2...4f8esigned at: 2026-04-15T09:41:22Zrequest_hash match: oktriggered_checks well-formed: oksignature verifies: okVALID
Frequently Asked Questions
Logs are written by the system you are auditing, so you have to trust them. Verosek's records are signed and chained, so tampering is provable instead of assumed. It is evidence, not a log.
Yes. You verify against a key only you hold, on your own machine, with no call back to us. If we disappeared tomorrow, your evidence would still stand on its own.
Every record is linked to the others, so changing or removing any one of them breaks verification for the rest. You cannot rewrite history without it showing.
You keep all of it, in an open format, and it keeps verifying forever against your key. There is no lock-in on your evidence.

