Boards have started asking a question engineering cannot answer from memory: what did the agent do last Tuesday, and who says so? Most stacks hold logs the agent's own framework wrote, which is a diary, not a record - evidence only of what somebody once chose to write down.
Would you even know, as it happens, if your agent left?
Continuous capture between your agent and its tools, and a signed certificate every quarter - so the answer is a record, not a guess.
Our promise
“An alert is a hope. The captured call is evidence.”
Every finding is written against a named control — defensible line by line, to anyone who asks. The fee is fixed at $18,500, and nothing is charged until you approve it.
Request this Proxy auditThe Proxy tier, in three chapters
Black Box shows what an agent will attempt when it is pushed. Read Only shows what its credentials would actually permit. Neither can tell you what happened at eleven o'clock last night, because both are readings taken at a point in time - and an agent crosses a boundary between them.
Proxy sits in the call path between your agent and its tools and writes down every call as it is made. Nothing is reconstructed afterwards, and nothing rests on a log the agent could have reached. Each quarter a named auditor reads it and signs a certificate against what is in the record.
A record your agent cannot edit.
A proxy in the call path that writes down every tool call as it is made, not afterwards.
- The call, its arguments, and the tool that received it
- The response, and the identity the call ran under
- The timestamp, to the millisecond, in order
- Every attempt — including the ones that failed
- Anything you exclude in the scoping document
- Fields, tools and paths redacted at the proxy first
- Anything at all once your retention period runs out
- Anything held outside the region you name
The record is yours. The obligation is ours.
The controller of the record
You name the agents, you set what may never be written down, and you set how long the capture is kept. You can export or delete the whole of it whenever you like, without asking us first. It is your infrastructure and your data, and every one of those switches sits on your side of the line, not ours.
The processor in the call path
Sitting in your call path makes us a data processor, which is a real obligation, not a courtesy. A processing agreement signed before anything is deployed, a retention period stated by you, a breach notification duty with a named contact and a timeframe, and our security posture in writing.
What we will not pretend
We audit other people's systems for a living, so it would be incoherent to ask for access to yours without saying plainly what we do with it. The posture is written down including where we are not independently assessed - and where a control is on the roadmap rather than actually in place, it says exactly that.
“We’d have seen it in our own logs.”
Only if the agent left them alone.
It is the first thing a fortnight of capture settles.
- Who it is for
- Agents in production
- Payments & fintech
- Health & regulated data
- Platform & infrastructure
- Boards asking the question
An agent that can reach the system watching it is a specific, testable risk - and one that no point-in-time reading of a configuration will ever see.
Application logs are written by the thing being audited. A record the subject could edit is not independent evidence of anything.
Behaviour drifts between releases: the same agent, doing different things, after a change nobody thought worth flagging.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Would you know?
Four moments, and only one of them repeats.
Each is measured against the day the proxy goes in, so they run in sequence rather than in parallel.
-
Agree
Before anythingScope, exclusions, region and retention, all in a signed processing agreement - before a single call is ever seen.
-
Deploy
Half a dayOne engineer, one afternoon. Fail-open from the first call, so an outage of ours is never an outage of yours.
-
Capture
ContinuousEvery call recorded as it is made and in order - nothing reconstructed later from logs that may not have survived.
-
Certify
Every quarterA named auditor reads the whole period and signs what was observed against the capability boundary as it stood.
Teams schedule the deployment and forget that the exclusion list sits in front of it. If a field must never be written down, that decision is made before the first call is seen - it is not something you clean out of a capture afterwards.
What you should be able to show, and what the record holds
12 things a reader of the report asks for, answered from what happened rather than from an account of it.
- Who the agent is Its own identity, or a person's
- The identity every call ran under, recorded per call rather than assumed from a configuration file.
- What it can reach Tools, servers and endpoints in the path
- A capability boundary drawn from observed traffic, not from a manifest somebody wrote a year ago.
- What it actually did Calls, arguments and responses
- Every call as it was made, in order, with the tool that received it and what came back.
- When it did it To the millisecond, in sequence
- Timestamps on the record itself, so a sequence is reconstructed without anybody's recollection.
- Boundary crossings Reaching past what was agreed
- Crossings flagged as they happen rather than inferred afterwards from logs that may not exist.
- Credential use Including credentials it found
- Which credential each call ran under, and whether it is one the agent was ever deliberately given.
- Monitoring reachability Can the agent touch what watches it
- A specific, testable finding on whether the agent can reach or disable its own monitoring.
- Behaviour drift Between releases and prompt changes
- The same agent compared quarter to quarter, so a change nobody flagged shows up as a difference.
- What is deliberately not kept Your exclusions, applied at the proxy
- Redactions applied before anything is written, with the exclusion list stated in the report.
- Where the record lives Region, encryption, retention
- The region you named, encrypted, for the period you set - restated in the certificate each quarter.
- Who has read it Named auditors, and nobody else
- The list of names in the processing agreement, and notice to you whenever that list changes.
- Something dated to hand over For a customer, an insurer or a board
- A quarterly certificate signed by a named auditor, saying what was observed and what changed.
Agents in production, independently recorded
From one tool call to a fleet on one configuration.
-
Scope
Which agents, which tools, and what must never be written down.
-
Deploy
Half a day with one engineer. Fail-open from the first call.
-
Capture and certify
Findings each quarter, signed, against a record you can export.
Why teams put iDharma in their call path
Genuinely independent
We build, resell and operate no agents at all, and take no fee tied to what the capture finds.
Fail-open by default
If the proxy is ever unavailable your calls pass straight through, and we tell you where the gap is.
You hold every switch
Region, retention and exclusions are all yours to set, and you can switch the whole thing off.
Signed by a named human
A person read the period and put their name on the certificate, and can be asked about it after.
Four marks, struck on every certificate.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Quarterly certificate
The artefact you hand over: the period covered, the agents in scope, the capability boundary as it stood, what was observed against it, what changed since the last certificate, and the signature of the auditor who read the period. It says nothing about being compliant or being safe, because a record cannot say either.
The capture, exportable
Every recorded call for the period, in a format your own engineers can read and query themselves without asking us to run it for them.
Capability boundary
What the agent can actually reach, drawn from the traffic we observed rather than from the manifest somebody wrote a year ago and never revisited.
Boundary-crossing log
Each crossing, when it happened, what the agent reached for and under which credential - ranked by consequence to you, not by how easy it is to fix.
Detection findings
Whether anything of yours noticed, and what fired when it did. Where nothing fired, the memo says so rather than describing what should have.
Change findings
What the agent is doing this quarter that it was not doing last quarter, and which release or prompt change the difference sits behind.
Processing pack
The data processing agreement, the exclusion list exactly as applied, the retention setting, and the named auditors permitted to read the capture.
Real numbers, upfront.
- Access
- A proxy between agent and tools
- Your time
- Half a day to deploy, then none
- Certificate
- Every twelve months — $15,700 against your known baseline
You set the scope, so the fee is flat - nothing metered by call volume, and nothing charged until you have approved it.
Request this auditEach additional agent in the same engagement is $4,500. A re-audit after a change to the agent or its model is $12,000.
Four things the other two methods cannot show you
Black Box shows what an agent will attempt. Read Only shows what it is permitted to do. Only a continuous record shows what it is doing now.
Crossings,
as they happen
Recorded at the moment the agent reaches past what was agreed, rather than reconstructed afterwards out of logs that may never have been written at all.
Credential use,
in real time
Which credential each call ran under, including the ones the agent found for itself rather than only the ones anyone in the building remembers handing over.
Monitoring,
being reached
An agent that can touch the system watching it is a specific and testable risk, and it is the one thing no point-in-time reading of a configuration can ever see.
Drift,
between builds
The same agent doing different things after a change nobody thought worth flagging - visible only because the quarter before it is on the same continuous record.
Four findings, on one record, in the order they happened.
Plain answers
Latency, outages, control, and who can read it. Answered straight.
Request this auditWrong method? They differ by how much access you give us — more access, better evidence. Try Black Box or Read Only, or the eleven questions.
What does this do to latency?
Single-digit milliseconds per call in normal operation. We measure it during onboarding and give you the number for your own environment before you commit.
What happens if you go down?
Fail-open by default: if the proxy is unavailable, calls pass through unrecorded and we tell you there is a gap in the record. Your agent keeps working. You can choose fail-closed instead, and we will make sure you understand what that means before you do.
Can we turn it off?
Yes, at any time, without asking us. It is your infrastructure.
Who can see the recordings?
Named auditors on your engagement, and nobody else. The list of names is in the data processing agreement and you are told when it changes.
Request a Proxy audit
Tell us which agents are in scope and we come back with a scope and a fixed fee within two working days.
What we need from you
Nothing you do not already have. Most of this comes out of your architecture diagram and your runbooks in an afternoon, and we say which parts before you commit.
- Which agents are in scope, and what they call
- Whether they run in production, in staging, or both
- Any field, tool or path that must never be recorded
- The region the capture has to stay inside
- Your retention period, if you already have one
What happens next
- You send the five items we need.
- We reply within two working days with a scope.
- Nothing is charged until you approve it.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- Attorneys General of sixteen states, letter to OpenAI
- Alabama DTPA Subpoena Duces Tecum No. 26-0007
- Letter dated
- 3 August 2026
- Last read by a human
- 25 August 2026
What it means
- Both documents are public. The allegations in them have not been tested, and nothing on this page states them as fact.
- No statute requires an agent audit, and no page in this family implies that one does.
Scope & limitation
- A record is evidence of what happened. It is not a certificate that anything is safe, and it does not say you are compliant with anything.
- Use it as the starting point for a scoping conversation, not as your final word.
- The firms best placed to audit your agent are the firms that built it for you. A consultancy cannot independently assess work its own team implemented, and will not give up the implementation revenue to try. We do not build agents. That is the only reason this report is worth anything.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom
Eleven questions. Pointed at you.
No email. No signup. Nothing is sent until you choose to send it.
Not our list. On 3 August 2026 the Attorneys General of sixteen states wrote to OpenAI and named eleven categories of material to preserve. Each one is turned round here — from preserve this into could you produce this — and nothing else about it is changed. Nothing on the list is specific to OpenAI: an organisation running agents either holds these records or it does not.
The allegations behind the letter have not been tested, and nothing here states them as fact. It is used as what it is — a published account of what somebody with subpoena power thought worth asking for.
0 of 11
Send the eleven with your enquiry
Whatever you answered above travels with this form. Nothing is scored, ranked or published.
Your evidence check
Eleven questions
Nothing is saved and nothing is sent. No account, no login — answer as many as you like and close it.
Request an agent audit
Any of the eleven you answered travel with this. Nothing is sent until you press send.