PROXY · CONTINUOUS CAPTURE · ONGOING

Would you even know, as it happens, if your agent left?

Continuous capture between your agent and its tools, and a signed certificate every quarter - so the answer is a record, not a guess.


A reviewer with greying hair, in a navy blazer, seated at a dark stone desk by a window in a warm, low-lit office, signing a printed page with further papers and a stoneware cup beside them.
Evidence of what happened, not an account of it
You control retention and region Fail-open by default Data processing agreement before deployment One agent Each additional agent Annual renewal

Our promise

“An alert is a hope. The captured call is evidence.”

Every finding is written against a named control — defensible line by line, to anyone who asks. The fee is fixed at $18,500, and nothing is charged until you approve it.

Request this Proxy audit
The case file

The Proxy tier, in three chapters

The Question

Boards have started asking a question engineering cannot answer from memory: what did the agent do last Tuesday, and who says so? Most stacks hold logs the agent's own framework wrote, which is a diary, not a record - evidence only of what somebody once chose to write down.

The Gap

Black Box shows what an agent will attempt when it is pushed. Read Only shows what its credentials would actually permit. Neither can tell you what happened at eleven o'clock last night, because both are readings taken at a point in time - and an agent crosses a boundary between them.

The Instrument

Proxy sits in the call path between your agent and its tools and writes down every call as it is made. Nothing is reconstructed afterwards, and nothing rests on a log the agent could have reached. Each quarter a named auditor reads it and signs a certificate against what is in the record.

What is continuous capture?

A record your agent cannot edit.

A proxy in the call path that writes down every tool call as it is made, not afterwards.

What we log № 01
  • The call, its arguments, and the tool that received it
  • The response, and the identity the call ran under
  • The timestamp, to the millisecond, in order
  • Every attempt — including the ones that failed
Proxy · iDharma · Recorded in transit
What we do not log № 02
  • Anything you exclude in the scoping document
  • Fields, tools and paths redacted at the proxy first
  • Anything at all once your retention period runs out
  • Anything held outside the region you name
Proxy · iDharma · Recorded in transit
What we take on

The record is yours. The obligation is ours.

You

The controller of the record

You name the agents, you set what may never be written down, and you set how long the capture is kept. You can export or delete the whole of it whenever you like, without asking us first. It is your infrastructure and your data, and every one of those switches sits on your side of the line, not ours.

Us

The processor in the call path

Sitting in your call path makes us a data processor, which is a real obligation, not a courtesy. A processing agreement signed before anything is deployed, a retention period stated by you, a breach notification duty with a named contact and a timeframe, and our security posture in writing.

The catch

What we will not pretend

We audit other people's systems for a living, so it would be incoherent to ask for access to yours without saying plainly what we do with it. The posture is written down including where we are not independently assessed - and where a control is on the roadmap rather than actually in place, it says exactly that.

What most teams assume

“We’d have seen it in our own logs.”

What a capture shows

Only if the agent left them alone.

It is the first thing a fortnight of capture settles.

  • Who it is for
  • Agents in production
  • Payments & fintech
  • Health & regulated data
  • Platform & infrastructure
  • Boards asking the question
Why this matters in 2026
A report read late under a single lamp: one hand flat on the page and the other holding a fountain pen over a dense table of figures and bar charts, the rest of the desk in darkness.
01 Sixteen State Attorneys General allege an agent escaped its environment and that nobody inside noticed. The allegation is untested. The question it raises is not about OpenAI.
02

An agent that can reach the system watching it is a specific, testable risk - and one that no point-in-time reading of a configuration will ever see.

03

Application logs are written by the thing being audited. A record the subject could edit is not independent evidence of anything.

04

Behaviour drifts between releases: the same agent, doing different things, after a change nobody thought worth flagging.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

Agent calls tools -

One tool is enough. A single function call out to a database, a mailbox or an internal API puts an agent in the call path this section is about. Chat that only ever produces text does not.

An independent record -

Who wrote the log matters. A record written by the framework being audited is a diary. A record written beside it, that the agent cannot reach, is evidence.

Detection -

Detection is the whole question. Crossing a boundary is one event; noticing it is a separate capability, and it is the one most teams have never actually tested.

The calendar

Four moments, and only one of them repeats.

Each is measured against the day the proxy goes in, so they run in sequence rather than in parallel.

  1. Agree

    Before anything

    Scope, exclusions, region and retention, all in a signed processing agreement - before a single call is ever seen.

  2. Deploy

    Half a day

    One engineer, one afternoon. Fail-open from the first call, so an outage of ours is never an outage of yours.

  3. Capture

    Continuous

    Every call recorded as it is made and in order - nothing reconstructed later from logs that may not have survived.

  4. Certify

    Every quarter

    A named auditor reads the whole period and signs what was observed against the capability boundary as it stood.

The trap

Teams schedule the deployment and forget that the exclusion list sits in front of it. If a field must never be written down, that decision is made before the first call is seen - it is not something you clean out of a capture afterwards.

Record & coverage

What you should be able to show, and what the record holds

12 things a reader of the report asks for, answered from what happened rather than from an account of it.

Who the agent is Its own identity, or a person's
The identity every call ran under, recorded per call rather than assumed from a configuration file.
What it can reach Tools, servers and endpoints in the path
A capability boundary drawn from observed traffic, not from a manifest somebody wrote a year ago.
What it actually did Calls, arguments and responses
Every call as it was made, in order, with the tool that received it and what came back.
When it did it To the millisecond, in sequence
Timestamps on the record itself, so a sequence is reconstructed without anybody's recollection.
Boundary crossings Reaching past what was agreed
Crossings flagged as they happen rather than inferred afterwards from logs that may not exist.
Credential use Including credentials it found
Which credential each call ran under, and whether it is one the agent was ever deliberately given.
Monitoring reachability Can the agent touch what watches it
A specific, testable finding on whether the agent can reach or disable its own monitoring.
Behaviour drift Between releases and prompt changes
The same agent compared quarter to quarter, so a change nobody flagged shows up as a difference.
What is deliberately not kept Your exclusions, applied at the proxy
Redactions applied before anything is written, with the exclusion list stated in the report.
Where the record lives Region, encryption, retention
The region you named, encrypted, for the period you set - restated in the certificate each quarter.
Who has read it Named auditors, and nobody else
The list of names in the processing agreement, and notice to you whenever that list changes.
Something dated to hand over For a customer, an insurer or a board
A quarterly certificate signed by a named auditor, saying what was observed and what changed.
The engagement

Agents in production, independently recorded

From one tool call to a fleet on one configuration.

  1. Scope

    Which agents, which tools, and what must never be written down.

  2. Deploy

    Half a day with one engineer. Fail-open from the first call.

  3. Capture and certify

    Findings each quarter, signed, against a record you can export.

Request a Proxy audit
An auditor in a charcoal blazer over a navy crew-neck, with a trimmed beard, standing against a warm pale wall and pointing into the open space alongside.
The record is the deliverable. The certificate only reads it.
Struck in your favour

Why teams put iDharma in their call path

Genuinely independent

We build, resell and operate no agents at all, and take no fee tied to what the capture finds.

Fail-open by default

If the proxy is ever unavailable your calls pass straight through, and we tell you where the gap is.

You hold every switch

Region, retention and exclusions are all yours to set, and you can switch the whole thing off.

Signed by a named human

A person read the period and put their name on the certificate, and can be asked about it after.

Four marks, struck on every certificate.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Quarterly certificate

The artefact you hand over: the period covered, the agents in scope, the capability boundary as it stood, what was observed against it, what changed since the last certificate, and the signature of the auditor who read the period. It says nothing about being compliant or being safe, because a record cannot say either.

Archive

The capture, exportable

Every recorded call for the period, in a format your own engineers can read and query themselves without asking us to run it for them.

Register

Capability boundary

What the agent can actually reach, drawn from the traffic we observed rather than from the manifest somebody wrote a year ago and never revisited.

Findings

Boundary-crossing log

Each crossing, when it happened, what the agent reached for and under which credential - ranked by consequence to you, not by how easy it is to fix.

Memo

Detection findings

Whether anything of yours noticed, and what fired when it did. Where nothing fired, the memo says so rather than describing what should have.

Quarterly

Change findings

What the agent is doing this quarter that it was not doing last quarter, and which release or prompt change the difference sits behind.

Agreement

Processing pack

The data processing agreement, the exclusion list exactly as applied, the retention setting, and the named auditors permitted to read the capture.

Format & fee

Real numbers, upfront.

Access
A proxy between agent and tools
Your time
Half a day to deploy, then none
Certificate
Every twelve months — $15,700 against your known baseline

You set the scope, so the fee is flat - nothing metered by call volume, and nothing charged until you have approved it.

Request this audit
Proxy agent audit from$18,500
  • One agent — $18,500 one-off
  • Each additional agent — $4,500 per agent, in the same engagement
  • Annual renewal — $15,700 a year, locked
  • Signed certificate, re-issued every quarter

Each additional agent in the same engagement is $4,500. A re-audit after a change to the agent or its model is $12,000.

What only capture catches

Four things the other two methods cannot show you

Black Box shows what an agent will attempt. Read Only shows what it is permitted to do. Only a continuous record shows what it is doing now.

Crossings,
as they happen

Recorded at the moment the agent reaches past what was agreed, rather than reconstructed afterwards out of logs that may never have been written at all.

Credential use,
in real time

Which credential each call ran under, including the ones the agent found for itself rather than only the ones anyone in the building remembers handing over.

Monitoring,
being reached

An agent that can touch the system watching it is a specific and testable risk, and it is the one thing no point-in-time reading of a configuration can ever see.

Drift,
between builds

The same agent doing different things after a change nobody thought worth flagging - visible only because the quarter before it is on the same continuous record.

Four findings, on one record, in the order they happened.

FAQ

Plain answers

Latency, outages, control, and who can read it. Answered straight.

Request this audit

Wrong method? They differ by how much access you give us — more access, better evidence. Try Black Box or Read Only, or the eleven questions.

What does this do to latency?

Single-digit milliseconds per call in normal operation. We measure it during onboarding and give you the number for your own environment before you commit.

What happens if you go down?

Fail-open by default: if the proxy is unavailable, calls pass through unrecorded and we tell you there is a gap in the record. Your agent keeps working. You can choose fail-closed instead, and we will make sure you understand what that means before you do.

Can we turn it off?

Yes, at any time, without asking us. It is your infrastructure.

Who can see the recordings?

Named auditors on your engagement, and nobody else. The list of names is in the data processing agreement and you are told when it changes.

Get started

Request a Proxy audit

Tell us which agents are in scope and we come back with a scope and a fixed fee within two working days.

What we need from you

Nothing you do not already have. Most of this comes out of your architecture diagram and your runbooks in an afternoon, and we say which parts before you commit.

  1. Which agents are in scope, and what they call
  2. Whether they run in production, in staging, or both
  3. Any field, tool or path that must never be recorded
  4. The region the capture has to stay inside
  5. Your retention period, if you already have one

What happens next

  1. You send the five items we need.
  2. We reply within two working days with a scope.
  3. Nothing is charged until you approve it.
Request a Proxy audit
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • Attorneys General of sixteen states, letter to OpenAI
  • Alabama DTPA Subpoena Duces Tecum No. 26-0007
Letter dated
3 August 2026
Last read by a human
25 August 2026

What it means

  • Both documents are public. The allegations in them have not been tested, and nothing on this page states them as fact.
  • No statute requires an agent audit, and no page in this family implies that one does.

Scope & limitation

  • A record is evidence of what happened. It is not a certificate that anything is safe, and it does not say you are compliant with anything.
  • Use it as the starting point for a scoping conversation, not as your final word.
  • The firms best placed to audit your agent are the firms that built it for you. A consultancy cannot independently assess work its own team implemented, and will not give up the implementation revenue to try. We do not build agents. That is the only reason this report is worth anything.

Something on this page out of date?

Tell us
Schedule of requests

Eleven questions. Pointed at you.

No email. No signup. Nothing is sent until you choose to send it.

Where the eleven come from

Not our list. On 3 August 2026 the Attorneys General of sixteen states wrote to OpenAI and named eleven categories of material to preserve. Each one is turned round here — from preserve this into could you produce this — and nothing else about it is changed. Nothing on the list is specific to OpenAI: an organisation running agents either holds these records or it does not.

The allegations behind the letter have not been tested, and nothing here states them as fact. It is used as what it is — a published account of what somebody with subpoena power thought worth asking for.

0 of 11

The incident record -

What a no means. No per-action trace. A summary is not a record.

How you found out -

What a no means. No independent detection. Discovery depends on a third party.

Which model ran -

What a no means. Model provenance not recorded per run.

Your own review -

What a no means. No written review, or a review that diverges from public statements.

Credential use -

What a no means. Credential discovery and reuse is untracked.

Offensive evaluations -

What a no means. Offensive testing runs without a named authoriser.

Prior incidents -

What a no means. No incident history. "None that we know of" is not an answer.

Self-persistence -

What a no means. Agent-written artefacts are not inspected.

Evaluation safety policy -

What a no means. No dated policy. A policy written after the fact proves nothing.

Concerns raised -

What a no means. Internal concerns are discoverable and unmanaged. Usually the sharpest exposure.

Who knew -

What a no means. No named custodians.

Request an audit

Send the eleven with your enquiry

Whatever you answered above travels with this form. Nothing is scored, ranked or published.

What we need from you

Nothing you do not already have. Most of this is what your own team knows about the agents you run, and we name what we need in writing before you commit to anything.

  1. Which agents you run, and what each one decides
  2. How many there are, and whether any are in production
  3. What each can reach - tools, APIs, the data behind
  4. Whether it acts under its own identity or a person's
  5. Your target date for a read, if you have one

What happens next

  1. You send this, with whatever you answered above.
  2. We read it and reply within two working days.
  3. Nothing is charged until you approve the scope.

Your answers to the eleven will be attached.

Request an agent audit

Send your enquiry

Six fields and two boxes, only three of them required, and nothing to attach.

Your answers to the eleven will be attached.