About
Veritio is an open-source evidence layer for audit trails.
Application logs were never built to answer "who did this, under whose review, and how dangerous was it?" They rotate, they get rewritten, and they belong to whoever holds the database.
Veritio records application events, agent sessions, code changes, and deployments as hash-linked records instead. Every record carries an origin — user, service, or AI agent — a deterministic risk score from an open policy, and a SHA-256 hash that locks it into a per-tenant sequence. Edit one byte, delete a record, or reorder history, and verification fails at exactly the position where history diverged.
The verifier ships inside the open packages, so an auditor does not have to trust your database, your admins, or us. SDKs cover TypeScript, Python, and Go with the same field names across all three.
Self-hosting the open-source stack is free and always will be. Veritio Cloud adds hosted ingest, region choice (EU, US, or APAC), signed export bundles, and team roles.
Veritio provides evidence support for reviews and investigations. It does not make an organization automatically compliant with GDPR, SOC 2, or any other framework — that is decided by auditors against a framework, not by tooling.
