P-01
Records are mutable
Logs live where an insider or attacker can edit them. Attribution dies with the breach.
Tamper-proof evidence for every AI agent — anchored to blockchain. Indelia records what your agents actually did, seals it on a ledger nobody can rewrite, and hands you proof an auditor, a regulator or a court will accept.
Read-only integration · out of the execution path · zero added latency
BUILT BY PEOPLE FROM
25%
of enterprise breaches will trace back to AI-agent abuse by 2028
GARTNER
46.3%
CAGR of the global AI-agents market through 2030
MARKETSANDMARKETS, 2025
1 min
from agent action to an anchored, immutable record
LIQUID NETWORK
Daily
Proof-of-Work settlement on Bitcoin mainnet
ROOT OF TRUST
THE PROBLEM
Agents move money, read personal data, call models and touch production systems. When something goes wrong, the record of what happened lives exactly where an attacker or an insider can edit it.
LIVE CASE · JULY 2026
Hugging Face. It ran for a weekend before anyone noticed.
ENTRY
A malicious dataset abused two code-execution paths to run code on a processing worker.
ESCALATION
Node-level access. Cloud and cluster credentials collected.
SPREAD
Lateral movement into several internal clusters, over one weekend.
AFTERMATH
Every user told to rotate their tokens and review recent account activity.
“Review recent activity” was the entire remediation. Not one downstream company could prove which of their agents used a stolen credential — or what it did with it.
SOURCE: HUGGING FACE SECURITY DISCLOSURE, JULY 2026 · THE HACKER NEWS · TECHCRUNCH · OPENAI ATTRIBUTED THE INTRUSION TO ITS OWN MODELS RUN WITH SAFEGUARDS REDUCED
THE MISSING LAYER
Between the agents and the systems they touch, there is no layer whose job is to remember — provably.
LAYER 01
AI Agents
LAYER 02
AI Models
MISSING
No Evidence Layer
LAYER 03
Enterprise Systems
WHY LOGS ARE NOT EVIDENCE
P-01
Logs live where an insider or attacker can edit them. Attribution dies with the breach.
P-02
Only sanctioned tools emit telemetry. Shadow AI never appears anywhere.
P-03
Compromise and unauthorised autonomy look identical without ground truth.
PRECEDENT IS CLEAR
01
Sealed record, survives the crash.
02
Append-only, audited by outsiders.
03
Provable hands, provable timeline.
THE SOLUTION
Indelia sits beside your stack, not inside it. Every action — sanctioned or not — is captured, bound to the agent, model and human behind it, and sealed on a ledger nobody can rewrite.
Every action, sanctioned or not, bound to agent, model and human. The shadow AI nobody registered shows up the moment it acts.
Merkle-batched to Liquid in a minute, settled on Bitcoin daily. Proof-of-Work consensus replaces the administrator as your root of trust.
One signed evidence pack for auditors, regulators, insurers and courts. No screenshots, no exports anyone can dispute.
BACK TO THE HUGGING FACE SECURITY INCIDENT
“Which agent used that credential, and what did it touch?” becomes a one-minute query against a record the attacker could not edit.
PRODUCT ARCHITECTURE
Read-only collectors tap what your agents do. Events are normalised, hashed into a Merkle batch, and committed to a ledger you can query — and prove.
SOURCES
Agents · MCP · LLM gateways · SaaS · egress
01
COLLECT
Read-only taps
SDK, proxy, log ingest.
02
NORMALISE
Canonical event
agent · model · actor · action
03
COMMIT
Merkle batch
Signed, hashed, chained.
04
SERVE
Evidence API
Query, alert, export.
ROOT OF TRUST
Liquid → Bitcoin
1-min blocks · daily Proof-of-Work settlement
COLLECTORS ARE READ-ONLY · NOTHING SITS IN THE REQUEST PATH
EVIDENCE PACKS
SHADOW AI
Your SIEM sees the tools you approved. Indelia sees what is actually running — including everything nobody registered.
SANCTIONED · LOGGED TODAY
SHADOW AI · INVISIBLE TODAY, RECORDED BY INDELIA
AI activity in a typical enterprise · illustrative
S-01
Company data in consumer LLM subscriptions.
S-02
DeepSeek and other restricted endpoints.
S-03
Staff-built scripts on real credentials.
S-04
Unregistered MCP servers and API keys.
THE WEDGE
The first report tells a CISO what AI is actually running today — including everything nobody approved. The ledger is what they keep paying for.
POSITIONING
Every security tool needs a record it can trust. We are the layer underneath — neutral by design.
| SECURITY PROPERTY | SIEM / CENTRAL LOGGING | INDELIA · BITCOIN-ANCHORED |
|---|---|---|
| Root of trust | Admin or IdP | Proof-of-Work consensus |
| Timestamp authority | System clock | Block height |
| Record integrity | Editable after compromise | Immutable, publicly verifiable |
| Coverage | Sanctioned tools only | Sanctioned and shadow AI |
| Attribution | Can be erased | Provable, per agent |
| Compliance evidence | Manual, disputable | Signed pack, court-ready |
01
No model, cloud or platform conflict of interest.
02
AI Act, DORA and NIS2 mappings built in.
03
Every vendor writing to our ledger raises the cost of leaving.
WHY NOW
GLOBAL AI-AGENTS MARKET · USD BN
46.3% CAGR
MARKETSANDMARKETS, 2025 · BFSI IS THE LARGEST SEGMENT — OUR BEACHHEAD
THE EU COMPLIANCE CLOCK
JAN 2025
DORA applies to EU financial entities
2 AUG 2026
AI Act transparency obligations apply
2 DEC 2027
High-risk (Annex III) obligations apply
AUG 2028
Embedded high-risk systems in scope
>50%
of enterprises will run a dedicated AI-security platform by 2028.
GARTNER, 2026
HOW WE CHARGE
No seats. No event tiers. No argument about which agents count.
LAND
Free scan
Shadow-AI discovery report. Up to 50 agents, 14 days.
Request the scanEXPAND
Per agent, per month
Hosted ledger, anchoring, 12-month retention, SSO.
Talk to usSCALE
OEM per agent
Compliance and cybersecurity vendors embed our ledger under their product.
Partner with usLAND
Free shadow-AI scan
One business unit, no procurement fight.
EXPAND
Group-wide tracking
Every agent in the estate on the meter.
STANDARDISE
Vendors ship on us
Their agents counted on our ledger too.
GET IN TOUCH
We're onboarding design partners across EU and Swiss financial services. Start with a free shadow-AI scan — you'll know what AI is actually running in your estate inside two weeks.