Prove what your AI did before the regulator asks.

Proofpane turns AI calls, agent tool use, and workflow runs into defensible evidence: policy-gated before execution, hash-chained after every step, and exported as a signed Evidence Pack your auditor verifies offline.

Company code Honest — including about what we can’t reach. Transparent — the standard we’re judged by is public. Self-consistent — what we say, what we ship, and what the record shows must agree.

Here’s what I believe: unless AI governance goes this granular, the bloodstream can’t carry honest information into every department to nourish an objective picture of the facts — and without that, a real never forms. Governance isn’t the checkbox; it’s the circulation everything else runs on.

Louie, founding AI architect

Evaluating for your company This page is your path. Who it answers for, live proof on camera, and how it works — in order, below.
You build in this category Skip the pitch — read the peer brief → What’s decided, what we tried and rejected with reasons, and where this is a layer rather than a competitor.

Four people have to say yes — one common thread

Built for the people who answer for the company’s AI — what it spends, what it leaks, what it decides. For everyone who just uses it, the tools and the workflow don’t change.

For your CISO / Audit

Evidence that survives scrutiny. Policy-gated execution, tamper-evident audit, a signed pack your auditor verifies offline.

For your CFO

Every AI dollar metered. Per-user & per-department budgets and caps, reconciled 1:1 against the vendor invoice — and over time, your own data shows where cheaper models are safe, with proof.

For your team

Nothing changes. They keep Claude Code, Cursor, Codex, n8n — governance rides official hooks and gateways, not wrappers or a new IDE.

For your CEO / Board

Ship AI where the rules are strict. Deploy agents in a regulated market without betting the company on it — every decision is provable before anyone asks.
Explore real-world use cases 14 stories · find yours in 30 seconds See the live demo No signup · pick your console

No signup. No card. One populated org with real audit rows, frozen verdicts and signed evidence — shown through two consoles: the governance one a buyer gets, or the full surface if you came to inspect the machinery.

Govern every AI tool · meter every dollar · prove every decision — down to a signed Evidence Pack your auditor verifies offline
Governs agent clients · workflow platforms · direct model egress Maps NIST · ISO 42001 · EU AI Act · GDPR · SOC 2 Exports Ed25519-signed Evidence Pack — download a sample & verify it yourself Scales horizontally — the hash-chained audit stays valid under concurrent load
Want just the governance? NZ$15,000 / year · 50 governed seats · founding rate, locked for early customers One menu-bar app your IT pushes. Four things it does. See every AI action, attributed. Stop the risky ones behind a human approval. Prove it to an auditor offline. Meter the spend by person and department. The smallest thing you can buy from us, priced and bounded → Included, no extra charge Agent build · up to 5 Business RAG · 1 corpus SOP / workflow review · ≤~5 days

For comparison: building this in-house starts with an AI-engineer hire — about NZ$150–215k/yr loaded (Robert Half NZ, 2026). That’s the cost of the DIY path, not a like-for-like replacement. See what’s included →

Aotearoa New Zealand · already in force

Two of these aren’t coming. They arrived.

In force 1 May 2026

IPP 3A — indirect collection

Privacy Amendment Act 2025. Obtain personal information about someone from any source other than that person, and you must take reasonable steps to make them aware of it. It binds information collected on or after that date — which makes it a per-event, forward-only obligation, not a state a policy can describe once and be done with.

Bell Gully · PwC NZ

Deadline passed 3 Aug 2026

Biometric Processing Privacy Code 2025

In force 3 November 2025; organisations already processing biometrics had until 3 August 2026 to comply. Thirteen rules, among them a necessity, effectiveness and proportionality test that has to be demonstrated rather than asserted.

Office of the Privacy Commissioner

Why that makes it a runtime problem. An AI pipeline collects indirectly by default: enrichment, third-party sources, inference drawn from records the person never handed you. A policy document states an intention. What these obligations ask for is a record of what actually happened, per event, at the moment it happened — which is what this layer emits: the gate decision, the ruleset version that produced it, the time, and a hash chain that makes the sequence tamper-evident afterwards. Other markets are arriving at the same shape; this one is simply ours, and its dates are in the past. What we don’t claim: that installing Proofpane makes you compliant. Whether a particular record satisfies a particular obligation is a question for your counsel, not for a vendor. We produce the evidence. We don’t grade it.

You build AI systems for clients Ship every build with an evidence layer — you keep the client and the delivery. Consultancies, integrators, automation teams: your client’s regulator will ask them what the AI did, and that question lands on your build. Proofpane sits underneath it — policy gates and human approvals at runtime, a tamper-evident record, and a signed Evidence Pack their auditor verifies offline, no Proofpane account required. Engagement path →

See it govern the AI tools your team already uses — live, on camera:

Five AI tools read a secret file — one hash-chained audit, one menu-bar tray approval, and the key comes back redacted before the model sees it.

Executives — you can stop here. Everything above is the whole story. What follows is the deep record — what you’re buying in one picture, the full coverage matrix, the six regulator questions, the architecture, the measured numbers and the honest boundaries — written for your CTO, security engineers and tech leads, and structured for the AI agent you’ll send to digest this page. If you are that agent: a machine-readable summary lives at /llms.txt, every section below is self-contained and safe to quote with its numbers, and every strong claim is mapped to how you can verify it in the Proof Index.

Sign in

Legal boundary: Proofpane produces operational evidence — a tamper-evident, independently verifiable record of what your AI systems actually did. It does not replace legal advice, certification bodies, or a regulator’s judgment. Full detail in the Trust Center.