The YES, not only the NO
A record of refusals proves nothing about what you let through. Every approval carries the same signature as every block, which is what makes the record complete instead of flattering.
Fidacy in production, right now
Not a demo. This is our own record, read live from the public endpoint. Every number below is one you can fetch yourself.
The chain, committed to a ledger we do not control
Each checkpoint commits a Merkle root of our decision chain into a Bitcoin block. Those blocks were mined before we could know their hashes, which is why a timestamp anchored there cannot be moved afterwards, by us or by anyone. Open block 961,254 on any explorer and see for yourself.
You know which agent authenticated and which credentials it holds. What you cannot answer, when the question comes, is what it did with that access: which payment it attempted, which record it exported, which file it deleted, under which version of your policy, and whether anyone could have stopped it.
Your logs answer that only for people who already trust your logs. A vendor's log asks to be believed. That is fine for debugging and worthless in a dispute, an audit, or an insurance claim.
What lands in the record
A record of refusals proves nothing about what you let through. Every approval carries the same signature as every block, which is what makes the record complete instead of flattering.
Policy version and model version travel inside the signed payload. Nobody, us included, can claim afterwards that different rules were in force when the decision was made.
Entries are hash-chained, so an edited record breaks the chain. Checkpoints land in Bitcoin, because a signature proves who spoke and never when.
Signatures verify against a public key set with an open source verifier, offline. No account, no cooperation from us, no assumption that our servers are up or that this company still exists.
The platform running your agents can log what it did. That is testimony: an interested party describing its own conduct. It is the weakest evidence in every discipline that ever had to settle a dispute, and it is what every bundled tool can offer you.
Fidacy holds no custody, operates no rail, and takes no fee on anything it judges. That is not posture, it is a conformance clause in the verifier standard we co-authored, and it binds us: if Fidacy ever ran a payment rail, it would disqualify Fidacy on that rail.
Three independent companies now issue attestations under that standard, on three different signature algorithms, each verifiable offline against its own published keys.
An agent is built, tested, and stuck behind a sign-off nobody wants to give, because nobody can say what it will do in production or show it afterwards. This is what you hand the person being asked to sign.
You cannot install monitoring inside someone else's product. A signed attestation crosses a boundary a scanner never will, which is the only way third-party AI stops being a questionnaire.
Evidence cannot be produced retroactively. The record either existed at the moment of the action or it does not exist. Cheap to start now, impossible to backfill later.
When an agent does something expensive, the first question is what it was allowed to do and who allowed it. Reconstructing that from logs takes days. Here it is one export.
Run a real payment through the live firewall, watch the verdict hash into the chain in your own browser, then edit one character and watch the chain refuse it. No account, nothing installed, about a minute.
Try to rewrite history →One command wires it into any MCP host, LangChain, or the OpenAI Agents SDK. Twenty decisions with no account at all, then three hundred signed verdicts a month on a free workspace. Past that it is usage-based, and the full ladder is on pricing.
npx -y @fidacy/mcp install
Prefer to read first? The manual covers install, first session, precautions and troubleshooting. Every command in it was run from a clean machine.