AI agents now move money, change entitlements, and reach regulated records. Rujul AI builds the independent evidence layer for those actions. Our first product, ActionGate, records whether the declared basis for each action actually held at the moment of reliance — as a signed, tamper-evident account anyone can verify. It sits off the action path and cannot act. That is precisely why its evidence can be trusted.
Illustration of an ActionGate account — four conditions held, one is known-wrong, one could not be established. Nothing is erased.
The action may execute successfully. The logs may show what happened. But neither answers the question a regulator asks: was the basis this action relied on actually supportable at the moment of reliance? Today that answer is reconstructed after the fact — from evidence scattered across systems, produced by the very platform that took the action.
ActionGate is not on the action path. It receives basis telemetry, never the payload, and it never approves, blocks, or performs anything. At the moment the agent relies on its preconditions, it evaluates each one and preserves the result.
It evaluates whether the declared basis for the action held — every atomic condition — with the same inputs always yielding the same verdict, and no model second-guessing another model. The result is a single, signed, tamper-evident account. When the question comes, the answer already exists.
The declared condition affirmatively held at reliance time.
The evidence contradicts the declaration — a known-wrong basis.
The required evidence could not be obtained — and is not guessed either way.
Most systems collapse these into one "missing information" flag. Keeping them apart — and preserving a contradiction even under uncertainty — is what makes the record audit-grade rather than just another log.
Because Rujul AI evaluates the declared basis and not the business logic, the same method caters to whatever action class you bring it — and extends to every point in an agent's lifecycle where authority or evidence can quietly change hands.
Model-risk and AI-governance expectations are extending toward agentic systems — a forcing function for independent, reconstructable evidence of every consequential action.
The market is racing to build agent firewalls and inline gates. The independent-witness position — evidence an enforcer cannot produce about itself — is open.
Technology-risk, internal-audit and model-risk teams at banks and insurers must answer "was this justified?" today — with tooling that reconstructs after the fact.
Provisional patents covering the governance-evidence method itself — the generic mechanism, not a single action type.
A live vertical slice: an evaluator and an independent verifier, running deterministically on a real agent action, end to end.
Patented invariant · public contract · trade-secret method · customer-confidential instance.
The independent-witness position is structural: an enforcer cannot be its own witness. That is the moat — and it is filed.
If you own the obligation to prove agent actions were justified, we'd like to show you a Rujul AI account on your own action class.