Regulatory evidence you can prove
The regulations do not just ask you to keep records. They ask you to keep records that stay believable years later, held where you control them. AlgoVoi produces tamper evident, offline verifiable evidence for EU AI Act, MiCA and DORA record keeping, signed under post quantum keys and kept inside your own perimeter.
The obligation nobody writes down
A record store the operator can write to is a record store the operator can rewrite. When an authority reads your 2026 records in 2032, the question is not whether the rows exist. It is why anyone should accept they are what your systems produced at the time, after years of administrator write access. Ordinary application logs and database audit tables do not answer that. Cryptographic evidence does, without asking anyone to trust you.
What the estate produces
Tamper evident audit log
Any business event becomes a content addressed, Falcon-1024 signed entry linked to the one before it. No entry can be altered, inserted, removed or back dated without breaking verification at exactly that point.
Trusted timestamps
RFC 3161 timestamps bind each record to an independent authority's clock, with an air gapped fallback that makes no external call. Time is not your server's assertion.
Write once retention
Records are held write once with retention schedules, and a legal or e discovery hold overrides routine disposal so a record inside a statutory window cannot be swept away.
Offline verifiable packs
A recipient verifies the signed chains, the public key and a standalone verifier with two public libraries, no AlgoVoi software, no service, no network.
Mapped to the obligations
Each provision maps to a specific artefact. Article numbers are the operative record keeping provisions, verified against the primary texts.
| Provision | What it asks for | Artefact |
|---|---|---|
| EU AI Act Art. 12 and 19 | Automatic event logging over the system lifetime, kept and available to authorities | Tamper evident audit log |
| MiCA Art. 68(9) | Records of all crypto asset services, activities, orders and transactions, five to seven years | Audit log plus write once retention |
| DORA Art. 17(2) and CDR (EU) 2024/1774 Art. 12 | Record ICT incidents, protect log information against tampering and deletion, reliable time source | Signed chain plus RFC 3161 timestamps |
| AMLR Art. 77 | Retain records for the statutory period, available to competent authorities | Write once retention plus evidence packs |
Kept in your own perimeter
A statutory retention window is no place for a commercial dependency. The estate is self hosted and air gap capable: records are produced where the activity happens, retained under your own policy, and signed under keys you hold. Nothing is generated in someone else's account and nothing phones home.
What this is not
It is not compliance and it is not legal advice. The estate produces tamper evident records that support your obligations. It does not make anyone compliant, and obligations vary by entity type and jurisdiction. Confirm your position with counsel.
What is in the estate
Regulatory evidence is produced by the Verifiable Compliance Suite, one self-hosted estate on a single perpetual licence ($5,000), installed from one encrypted deliverable with no PyPI at runtime:
- Compliance Command Center — evidence console and one-posture dashboard, IQ/OQ/PQ self-validation, SCIM and TOTP.
- Records Vault with .epi export, Recovery Vault, and the Verifiable Archive engine (S3, KMS, PKCS#11, Vault custody).
- Verifiable Audit Log, Sanctions Monitor, Travel Rule, and Retention.
- Compliance Gate policy engine and Crypto-Agility, all on the Substrate 2 core (Falcon-1024, ML-DSA-65, ML-KEM-1024).
Frequently asked questions
What is regulatory evidence in this context?
It is tamper-evident, independently verifiable records that support a statutory or regulatory obligation: signed, hash-chained, RFC-3161 timestamped, and verifiable offline against a published public key. AlgoVoi produces it with the self-hosted Verifiable Compliance Suite, so the evidence lives in your own perimeter and an authority can check it without contacting the vendor.
Which regulations does the evidence support?
HIPAA audit-control and integrity duties, GDPR right-to-erasure and integrity, eIDAS qualified timestamps, 21 CFR Part 11 validation, EU AI Act Articles 12/19/26 record-keeping, and MiCA Article 68(9) and DORA logging. Your counsel certifies compliance; the estate provides the evidence certification rests on.
Is it self-hosted and air-gap capable?
Yes. The estate installs and runs entirely on your own infrastructure, including fully air-gapped networks, from a single encrypted deliverable under a Falcon-1024 licence, with no cloud service, no phone-home, and no PyPI at runtime.
How is the evidence verified independently?
Each record recomputes from its own canonical bytes: canonicalise under RFC 8785 (JCS), hash with SHA-256, and check the post-quantum signature against the published public key. No AlgoVoi account, software, or network call is in the verification path, so an auditor confirms integrity on an offline machine.
Last updated: 3 August 2026.