Verifiable evidence base

The notary for the AI era.

Activity across identity, SaaS, cloud, dev and AI — automatically kept as tamper-evident records that anyone can independently verify.

Acme/All projects

Connections

Sources → one tamper-evident record → outputs.

Sources

Domain diagnosticsAutomatic monthly vulnerability diagnostics for your domains3 connectedManage
IdentityRecords logins and access-permission changes4 connectedManage
SaaS & business toolsRecords actions and sharing in business tools6 connectedManage
Development & deploymentRecords code changes and deploymentsNot connectedConnect
Cloud & IaCDiagnoses and records cloud settings and infrastructure changes5 connectedManage
Cloud audit logsRecords cloud management operation logs3 connectedManage
Databases & DWHRecords database access and privileged operationsNot connectedConnect
Security & devicesRecords device posture and threat detectionsNot connectedConnect
NetworkRecords network access and block logsNot connectedConnect
AI execution recordsSeal agent and model runs as tamper-evident evidence — supporting ISO 42001 / EU AI Act1 connectedManage
Your app & SDKsRecords your own app's activity via SDK or inbound URL1 connectedManage

One tamper-evident record

Read-only, independently verifiable

1,439Sealed this monthOpen Recorder

Outputs

GRC integrationsAutomatically send evidence to Vanta, Drata and Secureframe2 connectedManage
Verification packs & auditor sharingShare evidence packs your auditor can verify independentlyActiveOpen
The Cost of Inaction

By the time it makes the news, it is already a financial event.

What happened to companies that deprioritized security. Every case below is a documented fact, not a cautionary tale.

Real-World Breach Cases

Code Spaces2014

Continuity

Stopped in 12h

12 hours from breach to bankruptcy

The root AWS account had no MFA, so stolen credentials alone gave full access. After ransom was refused, the attacker deleted every instance, bucket, and snapshot. The company had no path to recovery and shut down the same day. Skipping MFA at cloud setup erased the entire business.

Cause

No MFA on the root AWS account

Yahoo! (US)2013–2014

Accounts impacted

3B+

Weak hashing erased ~$350M in acquisition value

Two breaches in 2013 and 2014 went undisclosed until 2016. MD5-hashed passwords were trivially crackable, enabling continuous exploitation. All 3 billion accounts were ultimately affected. Yahoo's Verizon acquisition price was cut by $350M over the hidden incident.

Cause

Legacy MD5 hashing and delayed disclosure

British Airways2018

Customers affected

~500K

22 lines of code that shook a global brand

Magecart inserted 22 lines of skimmer code into a third-party JavaScript loaded on the checkout page. Every card detail entered was forwarded to attackers in real time for nearly two weeks. About 500K customers were affected and the initial GDPR fine proposal reached £183M.

Cause

Third-party JavaScript injection (Magecart)

Equifax2017

Records exposed

148M

An unpatched vulnerability exposed 148M people

A critical Apache Struts patch (CVE-2017-5638) sat unapplied for two months. Attackers exploited it, remained undetected for 76 days, and exfiltrated 148M records including SSNs and birth dates. Total settlement and fine costs exceeded $575M. The CEO and CIO resigned.

Cause

CVE-2017-5638 left unpatched for 2 months

Target2013

Cards stolen

40M

An HVAC vendor's credentials breached 40M cards

Credentials stolen from an HVAC vendor provided a foothold inside Target's corporate network. Poor network segmentation let malware spread to 4,000+ POS terminals during Christmas season. 40M payment cards and 70M personal records were stolen, triggering CEO and CIO resignations.

Cause

Vendor network not isolated from POS systems

SolarWinds2020

Orgs compromised

18,000+

A trusted software update became a nation-state weapon

Attackers inserted the SUNBURST backdoor into a legitimate monitoring software update. Over 18,000 organizations installed it — including the US Treasury and State Departments. The intrusion went undetected for ~9 months and redefined supply-chain attacks as a top-tier threat.

Cause

Build system compromise and malicious code injection

Change Healthcare2024

Total loss

~$3B+

One missing MFA setting halted US healthcare for weeks

One internal account lacked MFA on a critical system. A single stolen password was enough for ransomware operators to access the core. US pharmacies and hospitals stopped processing prescriptions and payments for weeks. Total losses to UnitedHealth Group exceeded $3B.

Cause

MFA missing on a critical access account

CrowdStrike2024

Machines crashed

8.5M

A security vendor's own update caused history's largest IT outage

A faulty content update — not malware — crashed 8.5M Windows machines globally. Airports, banks, hospitals, and broadcasters halted simultaneously. Fortune 500 firms alone lost $5.4B+. A trusted security vendor proved a single bad update can outscale any cyberattack.

Cause

Unvetted content update pushed to production

Bybit2025

Stolen

~$1.4B

Phishing seized the keys behind a multi-sig wallet

Phishing and access exploitation let attackers seize the signing environment of a multi-signature wallet. The multi-sig protocol itself was intact, but the human layer managing the keys was compromised. ~$1.4B in Ethereum was stolen — the largest single crypto theft in history.

Cause

Phishing compromise of multi-sig key managers

Recorder

Everything that happens, in a record no one can rewrite.

Events from every connected source are appended to one ledger, each fingerprinted — open any record and verify it independently.

  • One tamper-evident record
  • Append-only & sealed
  • Verifiable without trusting us

Recorder

Sealed this month 1,439Last capture 3mPublic anchorpending

Search by target or referenceType: AllAll timeStatus: AllSaved viewsCSV
TimeTypeRecordStatus
just nowAIGenerated a summaryPending
1m agoIdentityEnabled MFA
2m agoCloudRecorded a config change
3m agoSaaSCreated a share link
4m agoAIAgent approved a task
5m agoCode activityMerged a PR
6m agoIdentityGranted access
7m agoDiagnosticsMissing security header
8m agoIaCRan a deploy
9m agoAIGenerated a summary
10m agoIdentityEnabled MFA
11m agoCloudRecorded a config change
12m agoSaaSCreated a share link
13m agoAIAgent approved a task
14m agoCode activityMerged a PR
15m agoIdentityGranted access

Login from a new device

Identity · 2m

Sealed

Provenance

SourceIdentity
Actorj.rivera@acme.com
Captured2026-08-15 04:12:38Z

Integrity

4e9a…1c2f
a7f3…9b0d
c015…77e4

Chain consistent · 0 mismatches

Verification

Recompute fingerprintMatch
Canonical form (JCS)Match
Inclusion in epochMatch
Link to adjacent recordMatch
SPHIOR Recorder

The audit areas SPHIOR handles — kept as tamper-proof facts.

Your security scan results, your infrastructure changes, your own AI's activity — whatever reaches SPHIOR is kept as a record that can't be rewritten. Not even SPHIOR, which built it, can change it afterward.

SPHIOR

Vulnerabilities and misconfigurations found

CC7 · Vulnerability management

Every month we actually scan your site and cloud environment and record the weaknesses and misconfigurations we find, with severity and impact. What was found, when, and how it was fixed stays in a form that can't be rewritten later.

Cloud configuration change diffs

CC8 · Change management

We record when and how your cloud and infrastructure settings changed, as diffs. The contents themselves stay with you — only the fact that something changed becomes the record.

TLS encryption and exposed login surfaces

CC6 · Logical access (technical)

We record whether traffic is properly encrypted (TLS, certificates) and how your externally exposed authentication and login surfaces look. Your internal identity systems and company-wide MFA are out of scope.

Your AI and agents' executions

ISO 42001 / EU AI Act

We record what your in-house AI and AI agents did — which model, when, and what decision. The prompts and answers themselves stay with you; only the fact that a run happened is kept as a tamper-proof record.

Records from any tool or SaaS

Connected via webhook

Even in areas SPHIOR doesn't scan, send events from any internal tool or SaaS and they become the same tamper-proof records. Onboarding and offboarding, vendor reviews, access reviews — keep the evidence you care about in one place.

DAST Architecture

Deep, authenticated audits, architected for absolute security.

Safely and comprehensively diagnose vulnerabilities deep within your system, beyond the login screen. Through secure session handoffs via our dedicated browser extension and isolated scanning environments, we completely eliminate the risk of production impact and data leakage.

STL 01

Secure Integration via Extension

Use the SPHIOR Chrome extension to securely synchronize auth credentials or session tokens from your local environment. No plaintext passwords stored on our servers.

STL 02

Encrypted Session Vault

Received sessions are heavily encrypted and managed strictly within a secure vault. They are loaded into memory only during the scan to maintain safe access.

STL 03

State-Aware Dynamic Scanning

Not just a crawler, but an engine that understands application state. We deeply and accurately trace post-login processes involving complex transitions and API calls.

STL 04

Fully Isolated Audit Environment

Scans execute on isolated, ephemeral microVMs for each customer. Physical data boundaries ensure that your audit data never leaks to other environments.

Ref · SPHIOR-RECORDER

Sealed Evidence Record

SPHIOR Recorder
  • Tamper-evident hash chain
  • Public / qualified timestamp
  • Independently verifiable
ContinuousAnchored

Ref · SPHIOR-AIGOV

AI Execution Record

AI Governance
  • ISO 42001 / EU AI Act aligned
  • Hash-only — no prompts or outputs
  • Tamper-evident & verifiable
Per executionTamper-evident

Ref · SPHIOR-AUDIT

Monthly Security Evidence

SOC 2 / ISO 27001
  • External assessment performed
  • Findings prioritized & tracked
  • Sealed for auditor reference
MonthlyAudit-support
Governance & Evidence

Once recorded, your evidence can't be rewritten, not even by SPHIOR.

SPHIOR doesn't just report your security posture — it seals it. Findings, infrastructure-as-code changes, and AI executions are recorded in a tamper-evident, independently verifiable form, so you and your auditor can prove exactly what happened and when — without having to trust us.

  • Tamper-evident & independently verifiable

    Every record is sealed with public and qualified timestamps. Your auditor verifies it with open tools — no need to trust SPHIOR.

  • AI Governance evidence — ISO 42001 / EU AI Act

    Record your AI and AI-agent executions as tamper-evident evidence for ISO 42001, the EU AI Act and SOC 2. Only hashes and metadata are stored — never your prompts or outputs.

  • Supporting evidence for SOC 2 / ISO 27001

    Monthly external assessment records, scope and remediation — sealed and packaged for auditor reference.

Pricing

Your tamper-evident evidence base. Add security diagnosis when you need it.

2 months free

Free

Start recording, free forever

Connect your services and record tamper-evident audit evidence. Prove what happened — even before you need an audit.

$0

$0 billed annually

  • Tamper-evident Recorder — connect & record
  • 2 connections · 1 project
  • 90-day retention
  • Manual verification pack download
  • Self-serve verification

Team

The floor to pass a real audit

Everything to hand verifiable evidence to an auditor: a full year of retention, verification packs, control mapping and read-only auditor access.

$99/mo

$990 billed annually

  • 1-year retention (covers Type II periods)
  • 10 connections · 3 projects · advanced sources
  • Verification packs (API + bulk)
  • Control mapping (SOC 2 / ISO)
  • Read-only auditor sharing

Business

Run audits every year

The standard for teams under continuous audit: multi-year retention, full control mapping, GRC push and a branded auditor portal.

$499/mo

$4,990 billed annually

  • 3-year retention
  • Unlimited connections · 20 projects
  • Full control mapping + compliance trends
  • GRC push (Vanta / Drata / Secureframe)
  • Auditor portal & full evidence export

Enterprise

Scale, long retention, assurance

For large organizations: 7-year retention, multiple audit firms, SLA and priority support — fully self-serve.

Contact us
  • 7-year retention
  • Unlimited projects & connections
  • Multiple auditor firms
  • AI governance included (unlimited)
  • SLA & priority support
  • Everything in Business

Add-ons

Security Diagnosis

Monthly authenticated DAST, vulnerability and code scanning per domain. Add it to any plan.

$199per domain / mo
  • Authenticated DAST — dynamic testing past login
  • Vulnerability scanning per domain, every month
  • Code diagnosis (SAST & SCA) for connected repositories
  • Findings folded into your evidence base & monthly report

AI Governance

Record AI and agent executions as tamper-evident evidence (ISO 42001 / EU AI Act).

Freeto start
  • Tamper-evident record of AI & agent executions
  • Evidence aligned to ISO 42001 / EU AI Act
  • Only a hash leaves your environment — never the content
  • Flat pricing: $99 (100k/mo), $199 (1M/mo), $499 unlimited — never metered per event
  • Free: view up to 10k/mo. Events from 10k–100k are still recorded and appear retroactively when you upgrade; recording pauses above 100k/mo.
  • Included with Enterprise

Ready to Secure Your Digital Future?

Start Free

✓ No credit card required