Open source (Apache-2.0)· Live three-sector demonstrator· github.com/epic28-ltd/raucle

Agents that act at machine speed need records that hold still.

Raucle is monitoring and audit infrastructure for AI agents operating at scale in regulated environments. Every agent action becomes a cryptographically signed receipt. Every policy is machine-checked. Every proof can be re-verified by anyone, independently, offline.

0sorries in the Lean proofs
5cross-language ports, byte-identical receipts
69µsmedian gate decision
FIPS 204post-quantum signatures, shipped

The gap between what agents do
and what anyone can prove

Enterprises are deploying agents faster than they can govern them. Gartner counts 80% of new enterprise applications embedding at least one agent, while only 31% of organisations have one in production. The 49-point gap is not a capability problem. It is an assurance problem: governance, compliance and audit teams cannot yet prove what an autonomous system did, to a regulator, with evidence that cannot be argued with.

Regulation has already moved. EU AI Act Article 12 requires automatic logging for high-risk systems. DORA Article 12 requires tamper-evident reconstruction of decisions in finance. Both ask deployers for evidence, not assurances. That is the problem Raucle was built to solve, and it is why the timing is now.

Five capabilities, one open substrate

01

Receipts

Every agent action, allowed or denied, is written as a signed, content-addressed receipt: which agent, which tool, which arguments, under which policy, when.

02

Audit chains

Receipts link into tamper-evident hash chains with signed checkpoints. Change one character anywhere in the past and verification breaks from that point on.

03

Policy gate

A machine-speed enforcement point. Agents pass every tool call through it; policy is evaluated in microseconds, and the decision itself is receipted.

04

Trust registry

Every agent has a cryptographic identity with its own keys, held in a signed registry with real revocation. Non-human identity you can enumerate and audit.

05

Proofs

Policy safety properties are proved, not just tested: Lean-mechanised soundness theorems with zero sorries, plus Z3 verification of policy invariants in CI.

Privacy-preserving by construction. Layer 1 selective disclosure is shipped: a verifier can confirm a receipt's conformance without seeing raw arguments. Layer 2, zero-knowledge argument privacy, is scoped and on the roadmap. The design principle is that sensitive-sector AI needs evidence that does not leak the sensitive part.

Security claims you can re-verify,
not trust

Most security vendors ask you to believe their product enforces policy. Raucle hands you the proof, machine-checked by the Lean 4 proof assistant, and invites you to run the checker yourself. There are no sorry placeholders anywhere in the proof files, a claim the repository greps clean on.

Gate soundness

If the gate says ALLOW, every one of its six checks genuinely passed: signature, trusted key, validity window, tool match, argument constraints. There is no code path to ALLOW that skips a check. The machine refuses to let the gate be unsound.

Attenuation soundness

When an agent delegates to a sub-agent, the child's capabilities can only tighten and its lifetime can only shorten. The child is provably never more powerful than the parent, in every possible handoff.

Proof composition

When a proven policy meets a gate decision, both guarantees hold at once. The two safety nets are genuinely stacked, and the theorem states plainly which external assumption it carries.

Building AI capabilities is only half the battle. For Britain and the world to benefit from these models we must be able to use them securely and predictably.

The UK's own framing of the assurance gap, from its sovereign AI investment thesis. Raucle is what that sentence looks like as software.

Evidence that outlives the vendor

Raucle is self-hosted, open source, and verifiable without contacting anyone. Receipts are checked with open reference implementations in five languages that produce byte-identical results, proven in CI on every commit. Signatures are post-quantum: every evidence surface, receipts, checkpoints, registry entries and capability tokens, carries hybrid Ed25519 plus ML-DSA-65 (FIPS 204) signatures, so audit evidence stays verifiable for the decades a government or bank needs it to, including after a quantum adversary arrives.

The trust primitive is open forever. The commercial layer, hosted operations, sector policy packs, compliance mappings, sits on top. A country or institution can adopt the substrate and never be dependent on the company that first built it. That is the point.

A live public demonstrator,
and a clear 18-month plan

Three regulated-sector scenarios, banking, government and healthcare, run continuously at demo.raucle.com. Try the demo, read the proofs, run the conformance vectors. If you are building the assurance layer for AI, we should talk.

Talk to the founder Try the live demo