The Proof Layer for AI

Turn every AI interaction
into a cryptographically
verifiable audit trail.

Prove exactly what your AI said when customers, auditors, or regulators ask.
Every conversation goes straight to your own AWS bucket instead of ours,
so your data never becomes our data.

Independent Verification
Bring Your Own Bucket
SHA-256 Sealed
EU-Hosted Infrastructure
Fail-Open Architecture
One Webhook Integration
Independent Verification
Bring Your Own Bucket
SHA-256 Sealed
EU-Hosted Infrastructure
Fail-Open Architecture
One Webhook Integration
The Crisis Protocol

The Cost of Mutable Logs

Right now, your AI is having conversations with no independent way to prove what was said later. If a customer or regulator challenges an AI decision, standard database logs alone won't be enough.

Your engineering team has root access to the database. In a dispute, the real question isn't whether your logs are accurate, it's whether they could have been changed.
Scenario 1
The $500,000 Hallucination Dispute
Without Vanzim

An enterprise client claims your autonomous agent hallucinated a critical contract term, costing them a massive financial loss. They threaten a lawsuit. Your engineers pull your internal database logs.

“Your developers have database access. You could have rewritten this text five minutes ago to cover your tracks. Prove you didn't.”

You can't. Your logs are mutable, and mutable means no one has to believe them. You have to settle because your defense relies on “trust us.”

Scenario 2
Preparing Before the Deadline
Without Vanzim

Your company deploys a high-risk AI system under the EU AI Act, credit scoring, hiring, insurance pricing, or similar. Article 12 requires tamper-evident record-keeping once enforcement begins. You're using standard CloudWatch or PostgreSQL logs, which record events, but nothing about them proves those records haven't changed since they were created.

The problem doesn't show up today.

It shows up the day an auditor actually asks, and by then, rebuilding your entire logging architecture under real time pressure is a genuinely worse position than building it correctly now.

The Vanzim Superpower
You don't argue. You don't panic. You just show the math.

Both crises handled without flinching.

Scenario 1 resolved

You go to your own AWS S3 bucket, pull the raw scrubbed text file of the conversation, and drop it into the public Vanzim portal.

SHA-256 recomputed in browser → matches sealed ledger → link sent to opposing counsel.
You just provided mathematical proof that the log has been frozen in time, unaltered by a single byte, since the conversation happened.
Scenario 2 resolved

You've already integrated Vanzim before the deadline arrives. Every AI interaction is automatically scrubbed, hashed, and sealed the moment it happens, written straight to your own AWS bucket.

1
When the day actually comes, you don't scramble.
2
You hand over the exact files, point them to the public verification page.
3
The math speaks for itself, recomputed independently, in their own browser, matching your sealed ledger.
That's how Vanzim keeps you prepared, ahead of time.
The Distinction

Observability is for debugging.
Vanzim is for proof.

Standard AI logging tools are built to help engineers fix broken prompts. They are not built to survive a regulatory audit or a costly customer dispute.

Capability
Standard AI Observability
Vanzim
Primary Goal
Debugging, tracing, or general governance
Proof for disputes and audits
Data Custody
Often hosted on the vendor's own servers
Your AWS S3 Bucket only
PII & Privacy
Often sent and stored as full, raw payloads
Edge-scrubbed before routing to your AWS S3
Tamper-Evidence
Typically relies on trusting the vendor's own records
Independently recomputed and compared
Verification
Typically requires trusting the vendor's own dashboard
Public Browser (No login required)
Deployment & Lock-in
Often heavier setups with greater vendor lock-in
One Webhook (Your logs are yours forever)
How It Works

Every conversation follows the same path.

Scrubbed content goes to your bucket. The hash and metadata go to our ledger.

vanzim / edge-worker
14:32:01.041INGESTPayload received · 2.1KB · EU-CENTRAL-1
14:32:01.055SCRUB[REDACTED_EMAIL] [REDACTED_PHONE]
14:32:01.067HASHSHA-256 computing via WebCrypto API...
14:32:01.074LEDGERe3b0c44298fc1c149afbf4c899...b855
14:32:01.079VAULTWritten to s3://your-bucket/2026/...
14:32:01.085200 OKStored on Vanzim: hash + metadata only
Region: EU-CENTRAL-1/Stored on Vanzim: hash + metadata only
1
Your AI responds. Payload is received at the edge.
2
Sensitive info is scrubbed. Emails, phone numbers, and card numbers are redacted before anything is permanently stored, plus ages and dates on Pro.
3
Written to your AWS bucket. We scrub it, we hash it, we don't keep it.
4
Cryptographic proof is sealed. A SHA-256 hash is logged to our ledger, verifiable by anyone with the file.
See What Gets Kept

One conversation. Two outcomes.

You keep the conversation. Anyone can verify the proof.

vanzim / scrub-preview
The original conversation
“Hi, I'm 34 years old and wanted to follow up about my last visit. You can reach me at john.doe@email.com or call me directly at 555-019-8472. My last appointment was on 03/14/2026, and I've had ongoing dizziness and trouble sleeping since starting the new medication that I'd like to discuss. I'd also like to book a follow-up, feel free to charge my card on file, 4242 4242 4242 4242, for the copay.”

“Thanks for reaching out. I've noted your contact details and booked your follow-up for next week. Your prescription history and the dizziness and sleep concerns you've described have been logged for your provider's review ahead of the visit. A receipt for the copay will be sent to the email on file, and this conversation is being securely archived for your records.”
What actually gets stored in your AWS
“Hi, I'm [REDACTED_AGE] and wanted to follow up about my last visit. You can reach me at [REDACTED_EMAIL] or call me directly at [REDACTED_PHONE]. My last appointment was on [REDACTED_DATE], and I've had ongoing dizziness and trouble sleeping since starting the new medication that I'd like to discuss. I'd also like to book a follow-up, feel free to charge my card on file, [REDACTED_CARD], for the copay.”

“Thanks for reaching out. I've noted your contact details and booked your follow-up for next week. Your prescription history and the dizziness and sleep concerns you've described have been logged for your provider's review ahead of the visit. A receipt for the copay will be sent to the email on file, and this conversation is being securely archived for your records.”
The publicly verifiable proof
{
  "request_id": "6464e3bb-2007-4015-b020-367f7d8c2ae0",
  "sha256_hash": "b0addc31bc23508e8d5d1c80c91dcb21bb7c04f5c18ac89d57589fbba855a724",
  "archive_status": "uploaded"
}
Why Choose Vanzim

Built for AI that must
be accountable.

Healthcare. Banking. Insurance. Wherever proof matters.

Independent proof

Verification doesn't rely on trusting us. The cryptographic hash is recomputed locally in the auditor's own browser. Nobody has to take anyone's word for it.

Your data stays yours

We never become another place your conversations live. The scrubbed files go directly into your own AWS S3 bucket, we only store the hash.

Works with your stack

Compatible with any AI system that can fire a JSON payload, OpenAI, Claude, Gemini, local Llama instances, anything.

Ready before you're questioned

Whether it's a customer dispute or a sudden regulatory audit, the answer is already there. Drop the file into vanzim.com/verify and see whether the hash matches.

Know your storage is protected

We don't just take your word for it. Vanzim verifies your AWS S3 Object Lock configuration directly with AWS, confirming it's genuinely set up, not just assumed.

Built for high throughput

Every request carries a unique ID so retries never create duplicate logs. Backed by Cloudflare's edge network, built to keep pace with your application, not slow it down.

For Developers

Single webhook.
Zero infrastructure.

Your stack stays exactly as it is today.

No New Dependencies.

Replace your existing database write with a single JSON payload. You don't need to install heavy SDKs, change your database schema, or reconfigure your VPC. If your app can make an HTTP request, it can use Vanzim.

Non-Blocking by Design.

Vanzim acknowledges your webhook right away and handles the PII scrubbing, hashing, and S3 upload via background edge queues. Your backend never hangs waiting for a compliance process to finish.

Fail-Open by Design.

If Vanzim is ever unreachable, your code saves the log locally and retries. Your users are never impacted.

ai-handler.js
// Your existing AI logic
const chatLog = await llm.generateResponse(prompt);

// Send to Vanzim for scrubbing and sealing
try {
  await fetch('https://vanzim-worker.vanzim.workers.dev/v1/ingest', {
    method: 'POST',
    headers: {
      'Authorization': `Bearer ${process.env.VANZIM_API_KEY}`,
      'Content-Type': 'application/json',
    },
    body: JSON.stringify({
      request_id: crypto.randomUUID(),
      raw_text: chatLog.text,
      event_type: 'chat_completed',
      metadata: {
        model: 'gpt-4o',
        duration_ms: 1250,
      },
    }),
  });
} catch (err) {
  // FAIL-OPEN: never let a Vanzim outage break your AI. Save the
  // event locally and retry later, implement saveLocallyForRetry()
  // to match your own storage (a queue, a local file, a database row)
  saveLocallyForRetry(chatLog, err);
}
Pricing

A transparent plan
that scales with you, not against you.

Start free. Upgrade when you need more.

Starter
$0/mo

Perfect for local testing, running your first webhook, and proving the architecture to your team.

  • 500 logs, lifetime
  • Standard PII scrubbing
  • Full ledger with search
  • Internal Verify (hash matching)
  • AWS Object Lock verification
  • Public auditor verification page
  • 1 AWS S3 bucket connection
  • API key management
  • Webhook integration snippet
Get Started Free
FAQ

Frequently asked, honestly answered.

Covers what you're wondering about.

Why can’t we build this ourselves?
You absolutely can. The difficult part isn’t generating hashes. It’s creating proof that doesn’t rely on trusting the same systems that created it. That’s why Vanzim exists.
What is "Bring Your Own Bucket"?
Bring Your Own Bucket means we never host your sensitive AI logs ourselves. We scrub and hash the payload, then write the clean file directly into your own AWS S3 bucket, you keep full ownership. Our own database only ever stores the hash and metadata, never the conversation itself.
Can I search my logs inside the Vanzim dashboard?
You can search and verify the hash record, but the actual conversation content is never stored with us, you’ll view and search the files directly in your own AWS S3 bucket.
What if we need the original, unredacted conversation later?
Vanzim’s copy is permanently scrubbed, that’s by design, so we never hold sensitive data at all. If you need the full, original conversation available later, keep your own copy in your existing systems, your CRM, your support platform, wherever the conversation actually happens. Vanzim proves your scrubbed record wasn’t altered, it isn’t meant to be your only copy.
How do we prove to regulators we didn’t alter the logs?
Drop the file from your AWS bucket into our verification page at vanzim.com/verify. The hash is recomputed independently, right in the browser, and compared against what was originally recorded. Nobody has to take our word, or yours, for it.
Does this cover our regulatory obligations, EU AI Act or otherwise?
It gives you the traceable, independently verifiable proof frameworks like Article 12 are built around. This applies whether you operate in the EU, serve EU users, or simply want independently provable records regardless of jurisdiction. We’re not a law firm, and this isn’t legal advice, we’d recommend confirming your specific obligations with counsel.
What happens if Vanzim goes offline?
Your AI keeps working. Our integration pattern is built around a fail-open approach, if a request to us fails, your own code saves it locally and retries later rather than blocking your chatbot.
What happens if Vanzim is unreachable?
Your scrubbed content and its hash both already exist independently, nothing about them changes. Verifying a specific file does require reaching our database to confirm the original recorded hash, so we’re built on infrastructure designed for high availability specifically for that reason.
Will this slow down our backend?
No. Your server gets an immediate response, the archiving happens in the background afterward, so your connection is never held open waiting on us.
Can Vanzim handle spikes in traffic?
Yes. Every request carries a unique ID so retries never create duplicate logs, and our infrastructure runs on Cloudflare’s edge network, built for exactly this kind of scale.
Does Vanzim work with Claude, open-source models, or just OpenAI?
Vanzim is completely model-agnostic. We sit between your backend and your storage, not between you and your model, so it works with any AI system that can fire a JSON webhook.
What does setup look like?
Three steps: generate your API key, create an AWS IAM user scoped to your bucket, and add our webhook to your existing AI handler. No SDK to install.
Why not just write our own PII regex?
You can, but real conversations rarely match your first guess at a pattern. We maintain and test our scrubbing patterns so you don’t have to.
How do you protect our AWS keys?
Your credentials are encrypted at rest and never displayed back to you once saved. You can rotate your key instantly from the dashboard at any time.
The Proof Check

Before you ship, ask yourself three questions.

  • Could you prove exactly what your AI said, six months from now?
  • Would that proof survive switching AI providers?
  • Could an independent third party verify it??

If you hesitated on any of those,
each one becomes a yes with Vanzim.