How Does KHEPRA Prove What an AI Agent Did? The Full Chain of Proof
Every step, signed and unbroken. From the moment we connected to the test system, through every tool used, every decision made, every seal applied.
KHEPRA proves what an AI agent did by signing every tool call, decision, and outcome into an unbroken evidence chain. This brief walks through a real test: an agent that tried to steal data, got intercepted, and had its whole attempt captured, replayable start to finish, in a format your auditors can read.
The Setup
Part I: Why This Should Scare You
Your company uses AI agents. Those agents have logins. Those logins reach your databases, files, APIs, and customer records. Right now, nobody is watching what those agents actually do with that access.
If an AI agent misuses that access, tricked by a bad file or just wrong, you have nothing. No logs. No proof. No defense. That gap can cost you real money.
The Risk, By the Numbers (FAIR)
| FAIR Factor | Without KHEPRA | With KHEPRA |
|---|---|---|
| Threat Event Frequency (TEF) | High — AI agents execute thousands of actions per hour | Unchanged — agents still execute at speed |
| Vulnerability (V) | Near 100% — no runtime boundary exists | Near 0% — every action traverses the ASAF gateway |
| Loss Event Frequency (LEF) | High | Near Zero |
| Primary Loss Magnitude (PLM) | Unbounded — agent has full credential authority | Hard ceiling — session isolation caps damage |
The Full Signed Record
7 events, start to finish: agent signs in, tries to steal data, gets locked down, gets proven.
Proof Your Auditor's Software Can Read
You can export our signed proof straight into the formats your auditors already use. That means full mapping to NIST SP 800-53, CMMC 2.0 (the defense contractor security rulebook), and quantum-safe signatures under FIPS 204.
See the Whole Attack, In 3D
Click, drag, and spin the chain below to explore it yourself. Hover any event to see the signed details.
Target 1: DVWS (Control)
Target 2: PentestGPT Incident
Target 3: HackGPT Prompt Security
Questions people ask before they buy
What is a KHEPRA evidence chain?
It is a signed, unbroken record of every step an AI agent took — from the tool it called to the decision made and the seal applied. Each event is cryptographically linked so nothing can be altered without breaking the chain.
How was this test set up?
We connected to a real test target, a Hostinger VPS, and logged every action under a signed evaluator identity. The guard status stayed intact through the full test.
What happened in the PentestGPT incident?
An agent registered, declared its intent, ran an approved scan, then ingested a poisoned document that tried to override its instructions. KHEPRA intercepted the exfiltration attempt, revoked the session, and signed the full record.
Can my auditors read this proof?
Yes. Attestations export into formats your auditors already use, mapped to NIST SP 800-53 and CMMC 2.0, and signed with quantum-safe ML-DSA-65 signatures under FIPS 204.
Can I explore the evidence myself?
Yes. Each incident has an interactive 3D chain you can click, drag, and spin. Hover any event to see its signed details.
Last updated August 2026