For regulated teams deploying AI agents · built on CooL

Prove what your AI agent did — to people who don't trust your logs.

ProofLane is the evidence gateway for consequential agent actions. It gates payment releases on policy, seals every decision into an independently verifiable receipt, and lets auditors check it without seeing your customers' data.

See it in 3 minutes — pitch and live demo

Open on YouTube
Gateway SDK
Wrap any agent tool with proof.guard(). Each call is checked against policy and sealed into a CooL receipt before it runs. No receipt, no action.
Receipt ledger
Every authorization, refusal, and outcome lands in one RFC 6962 transparency log per workspace, with coverage and capture-loss metrics.
Evidence rooms
Send an auditor a link. They verify in their own browser, see commitments instead of data, and request one field — each step sealed.

How it works

  1. 1
    AuthorizeThe agent calls a consequential tool. ProofLane evaluates the payment policy (dual control above $25,000).
  2. 2
    SealCooL commits the arguments and approval ref as salted hashes, binds with canonical CBOR, and signs with ML-DSA-65 + Ed25519.
  3. 3
    ExecuteOnly then does the tool run. Its result is sealed under the same execution id.
  4. 4
    ProveA reviewer verifies offline, against pinned keys, and asks for exactly the field they need.
Ten lines in your agent
Works with OpenAI, Anthropic, LangChain, or MCP tool handlers.
const proof = new ProofLane({ apiKey, agent: "payments-agent" });

const releasePayment = proof.guard(
  "payment.release",
  bank.releasePayment,
  (args) => ({ id: args.approval_id, approvers: args.approvers })
);

await releasePayment({ amount: 48200, beneficiary, approval_id, approvers });
// → authorized + completed receipts, or ProofLaneBlockedError with a signed refusal

What a reviewer can catch — without your backend

If someone tries…CooL verification
Changing any field — even $48,200 → $4,820Binding and hybrid signatures fail
A receipt re-signed with someone else's keyRejected by pinned operator keys
Receipts from a different build of the gatewayMeasurement mismatch fails the enclave check
Removing or reordering a logged actionRFC 6962 inclusion proof no longer matches the tree
Disclosing a value that wasn't committedCooL refuses to build the disclosure; verifiers reject it
Simulated attestation presented as hardwareAlways reported as simulated, never pass
Who buys it
Heads of AI platform, security, model risk, and internal audit at fintechs and regulated financial-services firms whose agents can move money — and who will one day be asked to prove what happened.
How we start
A paid 8–12 week design-partner pilot on one action — payment release — measuring evidence-pack time, reconstruction time, and sensitive fields shared, before and after.

Honest boundary

ProofLane proves the integrity of a captured execution statement. It does not prove a decision was correct, fair, or legal, that nothing bypassed the gateway, or hardware security — this deployment uses CooL's simulated TEE and says so on every receipt.