Glossary / Definition

Signed, Auditable AI: A Definition for Regulated Buyers

Signed, auditable AI is inference where every model call is anchored to a tamper-evident audit chain, and that chain is cryptographically signed. Because the signature covers each linked record, any change made after the fact — an edited output, an inserted call, a deleted one — is detectable. The result is an audit trail that works as evidence, not a log you are simply asked to trust.

The phrase carries two claims that are easy to blur together. Auditable means each inference is recorded — the input, the output, the model version, the timestamp, in a linked sequence. Signed means that sequence is protected by cryptography so its integrity can be checked independently. Auditable without signed gives you a log an administrator can quietly rewrite. Signed makes the log defensible.

How signing makes the record tamper-evident

Each inference record is chained to the one before it, and the chain is covered by a digital signature. That structure means you cannot alter one record in isolation. Change an earlier output, reorder events, or drop a call, and the signature no longer validates and the chain no longer links. The tampering does not stay hidden — it surfaces the moment anyone verifies.

Crucially, verification does not depend on the vendor. Anyone holding the public key and the chain can confirm, on their own, whether the record is intact. That is the difference between an audit trail that is hard to change and one where changes are provable after the fact.

Inference call Linked record ML-DSA signature Independent verify
Post-quantum by design In Hyfstele the signatures use ML-DSA (the NIST-standardized Module-Lattice Digital Signature Algorithm). A post-quantum signature keeps the evidence verifiable against future cryptographic attacks — a record you must retain for years should not rest on a signature scheme a quantum computer could later forge. See post-quantum signed inference for the mechanics.

One of four independently verifiable controls

The signed audit chain does not stand alone. In a Hyfstele deployment it is the fourth of four controls, each verifiable on your own hardware inside your own perimeter — open-weight models, air-gapped:

  1. Weights proven byte-identical to the public artifact, so the model you run is the model you audited.
  2. Dormant / latent capacity enumerated, so unused capability is accounted for rather than assumed away.
  3. No egress — no route to the internet and no name to resolve. Things go in; nothing comes out.
  4. Every inference call anchored to a tamper-evident audit chain signed with post-quantum cryptography (ML-DSA).
Honest posture We do not claim the model is clean, safe, or free of hidden behavior — no one can scan that away. What we claim is narrower and checkable: these four controls are verifiable on your hardware. Your confidence comes from evidence you can reproduce, not from our word.

Why signed evidence is the standard to demand

Most AI vendors offer assurance in the form of assertion: a SOC report, a policy page, a support contact who says the logs are safe. In a regulated environment that inverts the burden. You are the one accountable to an auditor or an inspector, and "the vendor told us" is not a control.

Signed evidence moves the burden back where it belongs. Instead of trusting that the record is intact, you verify it — and if it were altered, you would know. For a regulated buyer this is the practical dividing line: demand the artifact you can check yourself, not the claim you have to believe. This is the same logic behind a tamper-evident audit trail generally, applied to AI inference.

Connection to 21 CFR Part 11

For life-sciences buyers this is not abstract. 21 CFR Part 11 requires secure, computer-generated, time-stamped audit trails that record who did what and when, and that do not obscure previously recorded information. Records must be attributable, and protected against unauthorized alteration through their retention period.

A cryptographically signed inference chain maps onto those expectations directly. It timestamps and links each AI decision, it makes any later alteration detectable rather than silent, and it lets an auditor confirm record integrity without taking the system operator's word for it. The signed chain does not replace your Part 11 controls — it gives the AI portion of your process an evidence trail that meets the same bar. For the fuller mapping, see 21 CFR Part 11 for AI.

What it looks like in practice: MLR review

Hyfstele's MLR use case is an AI assist for pharmaceutical Medical, Legal, and Regulatory promotional review (live at mlr.hyfstele.com). The doctrine is "It flags. You decide." — the assistant runs a Flag → Judge → Prove flow with no LLM inside the flag decision plane. Every flag, and the human judgment on it, lands in the signed audit chain. When a reviewer later asks "why was this claim flagged, and who cleared it," the answer is a signed record, not a reconstruction.

Frequently asked questions

What is signed, auditable AI?

Signed, auditable AI is inference where every model call is anchored to a tamper-evident audit chain, and that chain is cryptographically signed. Because the signature covers each linked record, any after-the-fact alteration, insertion, or deletion is detectable. The audit trail becomes evidence that stands on its own rather than a log you are asked to trust.

How does signing make an AI audit trail tamper-evident?

Each inference record is chained to the one before it and covered by a cryptographic signature. Altering any earlier record breaks the signature and the chain, so tampering is detectable on verification. In Hyfstele the signatures use ML-DSA, a post-quantum digital signature standard, so the evidence stays verifiable against future cryptographic attacks.

Why demand signed evidence instead of a vendor's assertion?

A vendor assertion is a claim you must trust. Signed evidence is a fact you can check on your own hardware. Under 21 CFR Part 11 and GxP the audit trail must be attributable, complete, and protected from alteration. A signed, tamper-evident chain lets an auditor verify integrity independently, without relying on the vendor's word.

How does this relate to 21 CFR Part 11?

Part 11 requires secure, computer-generated, time-stamped audit trails that record operations and do not obscure previously recorded information, plus controls that keep records attributable and tamper-evident. A cryptographically signed inference chain supports these expectations by making any alteration of an AI decision record detectable and independently verifiable.

Does a signed audit chain prove the model has no hidden behavior?

No. A signed audit chain proves the record of what happened is intact and unaltered. It does not claim the model is clean or free of hidden behavior, and Hyfstele does not make that claim. Instead it exposes four controls you can verify on your own hardware — the signed audit chain is one — so your confidence rests on evidence rather than assertion.

See a signed audit chain on your own terms

Hyfstele runs open-weight models inside your perimeter, air-gapped, with four controls you can verify on your hardware. See the MLR assist live, or talk through a deployment.

Open the live demo Email Blake →