The notary for the AI era.
Activity across identity, SaaS, cloud, dev and AI — automatically kept as tamper-evident records that anyone can independently verify.
Connections
Sources → one tamper-evident record → outputs.
Sources
One tamper-evident record
Read-only, independently verifiable
Outputs
Every audit starts with the same two weeks.
Opening consoles to take screenshots, exporting CSVs and reconciling them by hand, asking around for when a departed employee’s access was actually removed. By the time the evidence is gathered, half the time until the next audit is gone.
“Send us the list of everyone who could access production during the period.”
TodayYou open each console, screenshot the permissions as they are today, and ask around for when each departed employee’s access was removed. The list as it stood on a given past date exists nowhere.
With SPHIORGrants and revocations are recorded as they happen. Name a date and the list as of that date comes out.
“Give us every change during the period — all of them.”
TodayYou export CSVs from each tool and stitch them together by hand. Two weeks later, you still cannot say “this is all of it.”
With SPHIORRecords are chained in sequence, so you can show on the spot that nothing is missing.
“Show us evidence that monitoring ran for the entire period.”
TodayYou screenshot the dashboard showing “healthy” right now and paste it in. That there was no downtime in between, nobody can show.
With SPHIORPeriods where records stopped are themselves recorded. You can show whether there were gaps, exactly as they were.
“Who took this screenshot, and when?”
TodayOnly the person who took it knows. And six months later, at the next audit, the same hundred screenshots get taken all over again.
With SPHIORRecords are sealed at the moment of capture, and the auditor can verify them on their own machine. Nothing needs to be recollected.
What an audit consumes is not thinking time but gathering time. SPHIOR does the gathering every day, in advance — and hands it over in a form that can be checked without trusting whoever gathered it.
Everything that happens, in a record no one can rewrite.
Events from every connected source are appended to one ledger, each fingerprinted — open any record and verify it independently.
- One tamper-evident record
- Append-only & sealed
- Verifiable without trusting us
The pane shows a sample record. Your own records are verified on the same screen, the same way.
Recorder
Sealed this month 1,439Last capture 3mPublic anchorpending
user.session.start
The audit areas SPHIOR handles — kept as tamper-proof facts.
Your security scan results, your infrastructure changes, your own AI's activity — whatever reaches SPHIOR is kept as a record that can't be rewritten. Not even SPHIOR, which built it, can change it afterward.
Vulnerabilities and misconfigurations found
CC7 · Vulnerability management
Every month we actually scan your site and cloud environment and record the weaknesses and misconfigurations we find, with severity and impact. What was found, when, and how it was fixed stays in a form that can't be rewritten later.
Cloud configuration change diffs
CC8 · Change management
We record when and how your cloud and infrastructure settings changed, as diffs. The contents themselves stay with you — only the fact that something changed becomes the record.
TLS encryption and exposed login surfaces
CC6 · Logical access (technical)
We record whether traffic is properly encrypted (TLS, certificates) and how your externally exposed authentication and login surfaces look. Your internal identity systems and company-wide MFA are out of scope.
Your AI and agents' executions
ISO 42001 / EU AI Act
We record what your in-house AI and AI agents did — which model, when, and what decision. The prompts and answers themselves stay with you; only the fact that a run happened is kept as a tamper-proof record.
Records from any tool or SaaS
Connected via webhook
Even in areas SPHIOR doesn't scan, send events from any internal tool or SaaS and they become the same tamper-proof records. Onboarding and offboarding, vendor reviews, access reviews — keep the evidence you care about in one place.
Vulnerabilities and misconfigurations found
CC7 · Vulnerability management
Every month we actually scan your site and cloud environment and record the weaknesses and misconfigurations we find, with severity and impact. What was found, when, and how it was fixed stays in a form that can't be rewritten later.
Cloud configuration change diffs
CC8 · Change management
We record when and how your cloud and infrastructure settings changed, as diffs. The contents themselves stay with you — only the fact that something changed becomes the record.
TLS encryption and exposed login surfaces
CC6 · Logical access (technical)
We record whether traffic is properly encrypted (TLS, certificates) and how your externally exposed authentication and login surfaces look. Your internal identity systems and company-wide MFA are out of scope.
Your AI and agents' executions
ISO 42001 / EU AI Act
We record what your in-house AI and AI agents did — which model, when, and what decision. The prompts and answers themselves stay with you; only the fact that a run happened is kept as a tamper-proof record.
Records from any tool or SaaS
Connected via webhook
Even in areas SPHIOR doesn't scan, send events from any internal tool or SaaS and they become the same tamper-proof records. Onboarding and offboarding, vendor reviews, access reviews — keep the evidence you care about in one place.
Deep, authenticated audits, architected for absolute security.
Safely and comprehensively diagnose vulnerabilities deep within your system, beyond the login screen. Through secure session handoffs via our dedicated browser extension and isolated scanning environments, we completely eliminate the risk of production impact and data leakage.
Secure Integration via Extension
Use the SPHIOR Chrome extension to securely synchronize auth credentials or session tokens from your local environment. No plaintext passwords stored on our servers.
Encrypted Session Vault
Received sessions are heavily encrypted and managed strictly within a secure vault. They are loaded into memory only during the scan to maintain safe access.
State-Aware Dynamic Scanning
Not just a crawler, but an engine that understands application state. We deeply and accurately trace post-login processes involving complex transitions and API calls.
Fully Isolated Audit Environment
Scans execute on isolated, ephemeral microVMs for each customer. Physical data boundaries ensure that your audit data never leaks to other environments.
Ref · SPHIOR-RECORDER
Sealed Evidence Record
- Tamper-evident hash chain
- Public / qualified timestamp
- Independently verifiable
Ref · SPHIOR-AIGOV
AI Execution Record
- ISO 42001 / EU AI Act aligned
- Hash-only — no prompts or outputs
- Tamper-evident & verifiable
Ref · SPHIOR-AUDIT
Monthly Security Evidence
- External assessment performed
- Findings prioritized & tracked
- Sealed for auditor reference
Once recorded, your evidence can't be rewritten, not even by SPHIOR.
SPHIOR doesn't just report your security posture — it seals it. Findings, infrastructure-as-code changes, and AI executions are recorded in a tamper-evident, independently verifiable form, so you and your auditor can prove exactly what happened and when — without having to trust us.
Tamper-evident & independently verifiable
Every record is sealed with public and qualified timestamps. Your auditor verifies it with open tools — no need to trust SPHIOR.
AI Governance evidence — ISO 42001 / EU AI Act
Record your AI and AI-agent executions as tamper-evident evidence for ISO 42001, the EU AI Act and SOC 2. Only hashes and metadata are stored — never your prompts or outputs.
Supporting evidence for SOC 2 / ISO 27001
Monthly external assessment records, scope and remediation — sealed and packaged for auditor reference.
Pricing
Your tamper-evident evidence base. Add security diagnosis when you need it.
Free
Start recording, free forever
Connect your services and record tamper-evident audit evidence. Prove what happened — even before you need an audit.
$0 billed annually
- Tamper-evident Recorder — connect & record
- 2 connections · 1 project
- 90-day retention
- Manual verification pack download
- Self-serve verification
Team
The floor to pass a real audit
Everything to hand verifiable evidence to an auditor: a full year of retention, verification packs, control mapping and read-only auditor access.
$990 billed annually
- 1-year retention (covers Type II periods)
- 10 connections · 3 projects · advanced sources
- Verification packs (API + bulk)
- Control mapping (SOC 2 / ISO)
- Read-only auditor sharing
Business
Run audits every year
The standard for teams under continuous audit: multi-year retention, full control mapping, GRC push and a branded auditor portal.
$4,990 billed annually
- 3-year retention
- Unlimited connections · 20 projects
- Full control mapping + compliance trends
- GRC push (Vanta / Drata / Secureframe)
- Auditor portal & full evidence export
Enterprise
Scale, long retention, assurance
For large organizations: 7-year retention, multiple audit firms, SLA and priority support — fully self-serve.
- 7-year retention
- Unlimited projects & connections
- Multiple auditor firms
- AI governance included (unlimited)
- SLA & priority support
- Everything in Business
Ready to Secure Your Digital Future?
✓ No credit card required
