Hiveram

The system of record for AI work.

Your AI agents can act. Can you prove why they did?

Plain answers for governance, compliance and quality leads.

Hiveram keeps an independent record of AI work, from authorisation and intent through execution, evidence, failure and closure.

We name the frameworks your auditors use so you can see where the evidence sits. Naming a standard is not a claim of conformance, and Obsta Labs holds no certification against any of them.

Why would we need this?

Answers 1–6

Most teams can now make AI do work. Far fewer can independently demonstrate what happened. When the only history lives inside the tool that performed the action, your evidence depends on the system you are trying to govern.

When an AI system sends a message, changes a record, approves a request or triggers another system, ordinary logs tell you about execution. Governance requires more: who authorised the work, what the AI was trying to do, what data it touched, who could intervene, what evidence it produced, and how the work was closed.

Hiveram keeps that record outside the AI actor. Every piece of work begins with an authorised intent, is claimed by an identified actor, accumulates runs and evidence, records failures and interventions, and is closed independently of the agent that performed it. That gives governance, compliance and quality teams answers to six questions.

What are the six questions?

Answers — this is the list

Different frameworks use different words. The operational questions converge on these six, and every other answer on this page points back to them by number.

  1. Who authorised it? This action, not AI in general.
  2. What data did it use or disclose?
  3. Why did it act? The intent it was working towards.
  4. Where is the evidence? Evidence with provenance and history, not a screenshot reconstructed after the fact.
  5. Who can stop it? Mid-task, and on the record.
  6. What happened when it failed?

What exactly is in the record?

Answers 1, 3, 4, 6

Logs record events. Hiveram records accountable work: the intent, the authority, the actor, the execution, the evidence, the revisions and an independent closure stay connected as one record. Four things ordinary AI logs do not give you:

  1. Intent before execution. The work order says what the agent was authorised to do.
  2. Exclusive execution identity. The claim says which actor had the right to do it.
  3. Independent closure. The actor cannot declare its own work complete.
  4. Failures and interventions in the same record. Every change is written as a new revision and the history is kept.
RecordWO-2274 · revision 64
Intent████████████ title redacted3
Claimed bynot retained in this record1
Executed by█████-wo2274-admission · identity redacted1
Pathopen → in progress → pending verification → done, 2026-09-264
Commit49b21ceaf11b · private repository4
Evidencecommit bound to the work order’s content hash sha256:b5dbf944…4
Closed byoperator-cli · a reviewer, not the executor1, 5

A real record from our own ledger, workledger/WO-2274. Redacted where marked; nothing added. Numbers on the right are the six questions above.

We do not claim that nobody with access to your own infrastructure could alter it. We claim the governance record exists outside the actor from the start of the work.

Our AI vendor keeps logs. Isn’t that enough?

Answers 1, 4

A log inside the vendor’s product is the system grading its own homework. The vendor controls it, you lose it when you change vendors, and it rarely records who authorised an action or what the person approving it saw. Ask any vendor one question: can I show my auditor the full record of what your system did, without you in the room? You need durable access to, and control of, the record that does not depend on continued access to the vendor.

We already run ISO/IEC 42001. Why would we need software for this?

Answers 1, 3, 4

ISO/IEC 42001:2023 is a management-system standard. It asks your organisation to set AI policy, assess impact, assign roles, monitor AI systems through their lifecycle, and keep documented information showing all of that happened. It does not produce that information.

A record of AI activity — who authorised it, its purpose, its execution history and the supporting evidence — can provide the documented information your management system needs. Hiveram keeps that record outside the AI actor. Naming the standard is not a conformance claim; it is a description of where the evidence sits. Source

We follow the NIST AI RMF, or ISO/IEC 23894. Where does this fit?

Answers 2, 4, 5

NIST’s AI Risk Management Framework 1.0 (an update is in progress) has four functions, Govern, Map, Measure and Manage, and calls for documentation, measurement and monitoring across the AI lifecycle. Our design response is to keep that record outside the agent being governed, so Measure and Manage rest on an account that does not depend on the system under measurement. Source

ISO/IEC 23894:2023 gives guidance on managing AI risk inside your existing processes, and like the risk-management practice it builds on, it asks you to record and report what happened. The record is where that lives. Source

Does any law actually require this yet?

Answers 1–6 · Last regulatory review: 2026-10-02

South Korea’s AI Basic Act and its Enforcement Decree took effect on 22 January 2026. The Ministry of Science and ICT has announced a grace period of at least one year during which penalties will generally be deferred while organisations prepare. Under Article 34, a business providing high-impact AI must operate risk management measures, ensure human oversight, and prepare and retain documents that verify those measures; Article 35 asks it to endeavour to assess the impact on fundamental rights in advance. Source

In the European Union the AI Act already applies in stages: most provisions since 2 August 2026, obligations for high-risk systems from 2 December 2027 and, for AI embedded in regulated products, from 2 August 2028. The evidence you need depends on the system and on your role under the Act (European Commission timeline). These laws can also reach suppliers outside their home jurisdictions, depending on where a system is placed on the market, deployed, supplied or used, and on the supplier’s contractual role. We describe these laws as published. We are not your counsel, and this page will change when the dates do.

Does this make us compliant? Do you hold a certification?

Answers 1–6

No to both. Obsta Labs holds no certification against ISO/IEC 42001, ISO/IEC 23894, the NIST AI RMF or any other standard named here, and using our products does not by itself make you conformant to any of them. Certification is your organisation’s achievement, against your management system. Our part is making sure the evidence exists when the auditor asks.

Who can stop an agent?

Answers 1, 5, 6

In Hiveram, closing work requires an identity that is not the agent, so an agent cannot mark its own work done. Which actions need a human signature is your policy; the record shows who signed and when. Hiveram applies the same separation-of-duties principle: execution and closure are different identities.

An agent works under a claim the ledger grants. A person can see every active claim and release it, and the release is on the record. When a run fails, it is recorded against the work it addressed, so a failure is an entry in the record rather than a gap in it.

Does this slow our teams down?

Answers 1, 4

Policy checks happen inline with the work they govern; the alternative is reconstructing evidence after an incident. The record is written as the work happens, through the same steps the agent already takes — claim, work, close — not reconstructed afterwards.

We run our own company on our own products: a fleet of AI agents builds the software, and every piece of work carries a contract, a verification step and a closer who is not the author.

How does Hiveram fit with NeuroRouter and VectorCourt?

Answers 2, 3, 5

Hiveram is the record. Two companion products cover the edges around it, and neither is required to use it.

What leaves your network. With NeuroRouter in front of your model providers, detected credentials, tokens and connection strings are redacted or blocked before a request is forwarded, according to your policy. It runs locally, forwards only to the upstream provider you configure, and does not phone home. It is not a promise to catch every encoded or transformed secret — it removes a hosted credential store from the path.

High-stakes verdicts. For a high-stakes decision, VectorCourt checks before anyone acts whether the question can support the verdict asked of it, and signs what it produces.

Where do our records live?

Answers 4

With you. Hiveram runs locally, on infrastructure you control against your own PostgreSQL, or managed by us if you prefer. Nothing leaves your environment unless you decide it does. It installs with one command; see the install guide, and pricing for plans and the 14-day trial.

Pricing and trial Deploy Ask a question