A human owns
every decision.

An agent that can approve its own work is not governed, however well it is logged. IntelliChain gives every task a named human owner who is the only one able to approve, deny or send back any part of it. The agent proposes a plan, declares the tools each step will use and executes only what was approved. Every ruling is anchored to a ledger that cannot be rewritten, so oversight is evidence rather than an assurance.

Block Explorer LIVE
0-bit
Record Checksum
0%
Actions Anchored
0
Actor Types Covered
0:1
Ledger Per Project
AWS Activate Startup
Google cloud Startup
Microsoft for Startups Founders
Record // 01

The accountability gap.

Automation moved faster than the ability to answer for it. When an agent changes a record, a device trips a threshold, or a model makes a call, the evidence usually lives in the same database the system controls, so it can be changed, and nobody can tell.

Problem 01

Logs prove nothing

An application log is written by the system it is meant to hold to account, and can be edited by anyone with database access. It is a description of events, not evidence of them.

Problem 02

Nobody owns the decision

When an agent runs unattended, approval is implicit and diffuse. Afterwards there is no way to point to the person who authorised a specific step, or to show what they were shown.

Problem 03

Backdating is invisible

Without an independent time anchor, a record written after the fact looks identical to one written at the time. Reconstructed history and real history are indistinguishable.

Human owner Creates & assigns the task Sole approver
AI agent Plans, executes, records Cannot approve
Verifier sub-agent Checks work against the plan Cannot approve
Human owner Final say before it ships Approves
Record // 02

Authority is ownership.

CAP, the Chain of Accountable Provenance, is the governance model. The person who creates a task owns it, and is the only one who can approve, deny or send back any part of it. There is no global approval tier and no all-powerful administrator who can wave work through.

The agent decomposes the task into a plan, plan-tasks and actions, each action declaring the tools it will use, so the owner approves not just what but how. Every ruling is anchored and bound to the key that signed it. A denied step sends the agent back with the previous version kept on-chain, so the whole negotiation survives.

Record // 03

A ledger they
cannot rewrite.

IntelliChain runs a private, permissioned blockchain. Each customer project is placed in its own isolated group with its own ledger, so no project can read or write another's records, and none of it is public.

  • Isolated per project A separate group and ledger per project. Membership is the boundary, and there is no shared pool of records.
  • Checksums, not your data Only a cryptographic checksum of the record goes on-chain. The content stays in your database, so records can be as rich as you like.
  • Gated end to end Every read and write is authorised on-chain by the contract itself, in tiers. There are deliberately no events, because event payloads would bypass those checks.
  • Chained by parent hash Records form a DAG. Altering any earlier payload breaks verification for everything downstream, so tampering cannot be contained.
Project Isolation Private
network Private permissioned
isolation Group per project
ledger Dedicated per project
on_chain checksum only
visibility group members only
Run your own node in the group and verify independently
Record // 04

Written for the EU AI Act.

The obligations IntelliChain was designed around, and what answers each one.

Article 12

Record keeping

Automatic logging across the system's lifetime, traceable to a degree appropriate to its risk. Each entry is anchored by checksum when it is written and chained by parent hash, so any later alteration breaks verification for everything downstream.

Article 13

Transparency

Output a deployer can interpret and use appropriately. Each action declares the tools it will use before it runs, and the plan the owner approved is anchored alongside the result, so what was authorised and what happened are the same record.

Article 14

Human oversight

A natural person must be able to oversee, intervene and override. CAP makes the task owner the only party who can approve any step, and binds each ruling to the key that signed it. Oversight is a gate the work cannot pass without, not an alert once it has already run.

  • 2 August 2026 — transparency duties People must be told when they are dealing with an AI system, and the Commission's powers over general-purpose models begin.
  • 2 December 2027 — high-risk duties Articles 9, 12, 13 and 14 apply to stand-alone high-risk systems. What they ask for is a history, which means it has to already exist by then.
  • Article 9 — risk management IntelliChain does not score or grade your risk. It holds the evidence your own risk process produces, so the ongoing review the Article requires rests on records that hold up when they are examined.
  • Software cannot make you compliant Compliance is a judgement your counsel makes about your organisation, and it stays theirs. What we provide is the evidence that judgement is built on.
Record // 05

Three domains, one record.

The same anchoring model governs anything that acts on your behalf, whether the actor is a piece of software, a device in the field, or a model making a judgement call.

Domain 01

Digital Systems

Business platforms where records change constantly and an auditor eventually asks who changed what, when, and on whose authority.

  • Anchor every create, update and delete
  • Prove a row is unchanged since it was written
  • Show the signing identity for each entry
Domain 02

IoT Estates

Sensor networks and controllers whose readings drive real decisions, and whose history is worth exactly as much as its integrity.

  • Checksum telemetry at the point of ingest
  • Detect retro-fitted or replayed readings
  • Tie automated actuation back to a rule
Domain 03

AI & Agents

LLM-driven systems that plan and act. The reason IntelliChain exists: work that is genuinely autonomous still needs a human answerable for it.

  • Human-approved plans before execution
  • Declared tools per action
  • Verifier verdicts anchored per stage
Record // 06

How a record gets anchored.

Five steps, all signed by the caller's own key. A caller with no resolvable chain identity is refused , nothing is ever signed on someone else's behalf.

Provision

The project gets a group and its own ledger, deployed by its own owner key.

Authorise

Each user is issued a chain identity and registered on the contract by an existing admin.

Anchor

A cryptographic checksum of the canonical payload is written against a data_id, signed by the acting user.

Verify

Recompute the checksum later and compare. A match proves the record is unaltered.

Disclose

Hand an auditor the hash, transaction, block and signer for one record, without opening the rest.

Record // 07

What it proves,
and what it does not.

Governance software that overstates itself is worse than none, because people rely on a guarantee that was never there. So we are precise about the boundary.

  • It proves tamper-evidence If a record changed after it was written, verification fails. That is genuine, and it is the property most audits actually need.
  • It proves ordering Parent hashes and block numbers fix the sequence of events, so history cannot be re-ordered or backdated without the change showing.
  • It proves which key signed Every write is attributable to the key that authorised it, and the contract refuses writes from keys it does not know.
  • It is not non-repudiation Signing keys are held by the platform, encrypted at rest. The chain shows a record is unaltered; it does not prove a named person personally authorised it. We will not claim otherwise.
  • The API is not the boundary Anyone with node access, the signing key and group membership can transact directly. The real controls are the contract's own checks and key custody, which is where we put them.
  • Mistakes are permanent A wrong hash cannot be superseded. That is deliberate: a sanctioned route to change what a record says is exactly what the ledger exists to prevent.
Packages

Every tier does everything.

No tier withholds part of the record. You choose the level of isolation and the scale you need.

01

Starter

Shared infrastructure with an isolated group and dedicated ledger per project.

£49 per user / month
Hosting
Shared (Multi-Tenant)
Agent identities
10
Records per month
250,000
Most chosen 02

Growth

Dedicated instance and chain for one customer, managed by us.

£249 per user / month
Hosting
Private (Single-Tenant)
Agent identities
100
Records per month
5,000,000
03

Enterprise

Deployed on the customer own infrastructure under licence.

On application
Hosting
Self-Hosted
Agent identities
Unlimited
Records per month
Unlimited
Get started

Hold your systems to the record.

Provision a project, issue chain identities to your team, and start anchoring. The console gives you the ledger, the explorer and the full audit trail.