Proof · Built to be validated
Don't take our word for it. Check it.
SydClaw is evidence-grade AI for firms whose output gets challenged — expert witnesses, tax advisers, credit committees. Plenty of AI vendors say every action is logged and your data stays local. Below are four things you can check for yourself, each shown on a clearly-labelled sample so no client's data appears on this page.
Check 1
Trace a figure to the line it came from
Every figure in an answer is checked against the documents and results the AI was given, and marked where it stands.
- Traced: the figure appears in a source. You see the document and the line, with the figure highlighted.
- From your message: you supplied it. It is never presented as evidence.
- Not in the sources: it was calculated or came from general knowledge. A correct total is still marked this way — that is the number to check before you rely on it.
The check is exact matching in code, not the model's opinion of itself. It folds formatting (“$1,200.00” matches “1200”) but never rounds. The receipt under the answer can be copied into a working paper or file note.
The marks above were produced by the product's own checker, run on this sample. Hover or tab to a figure; open the receipt to see the full list.
Check 2
Replay the run, step by step
Any answer can be replayed as an ordered timeline: each tool it used, how long it took, how it ended, and who approved or refused it.
- Steps that change something — saving, sending, writing to a system — can require a named person's approval before they run.
- The replay shows who decided, and when. A refused step is shown as refused, not quietly dropped.
- Inputs and outputs are visible only to the person whose conversation it was; others see the steps and receipts.
Replay
14 Apr 2026, 10:42:03 am → 14 Apr 2026, 10:49:51 am · 5 steps
Check 3
A log that shows if it has been edited
Each AI action is written to an append-only audit log in which every entry is chained to the one before it.
Each entry stores a SHA-256 hash computed over its contents — its id, time, organisation, user, event type, action and details — and the previous entry's hash. The database refuses edits and deletions of audit rows; the one exception is the retention period your organisation sets, and each retention purge is itself recorded, with the entry the chain resumes from. If a row were changed anyway, by someone with privileged access, its hash would no longer match, and every later link would break.
What the verifier checks
- Every entry's hash, recomputed from its stored contents, matches the hash stored with it.
- Every entry's “previous hash” is the hash of the entry immediately before it in sequence — so a deleted or inserted row shows as a gap.
- The newest entry matches a signed record of the chain's head kept outside the database — so rows cut off the end are caught too.
To be precise about what this is: tamper-evident, not tamper-proof. It does not stop someone with full database access from altering a row; it makes the alteration detectable. By default, if every audit store is unavailable at once, the action goes ahead and the gap is logged as critical. Deploys that need strict compliance are set to stop the action instead.
the next entry carries this hash
the next entry carries this hash
Hashes shortened for display; each is a full SHA-256 digest.
Check 4
See where your data is processed
Every deploy publishes a residency report: each service that can carry client content, where it runs, and whether that is onshore.
- Onshore, offshore or not configured — judged from the deploy's configuration, such as endpoint hosts and regions.
- In Australian-residency mode, an offshore service that would carry client content is refused or switched off rather than used quietly. Infrastructure that can't be refused call by call is reported instead.
- The report says ready only when nothing is offshore.
We don't claim every part of every deploy runs in Australia today — the sample above shows what the report says when something doesn't. Commercial deploys run in Australian-residency mode, and each deploy's report shows exactly where its data goes. Every deploy publishes this report; ask for it.
Rows abridged. A real report lists every processor that can carry client content, judged from the deploy's configuration — never from a secret.
Take this to any vendor
Ask any AI vendor for these four things
Show me where a figure in this answer came from — the document, the page, the line.
If they can only show you a list of documents, nobody checked the number.
Replay one run for me: every tool it used, who approved what, and when.
“Every action is logged” means little if you can’t read the log in order.
How would you know if your audit log had been edited? Run that check for me.
A log that can be changed quietly is a record of what someone wanted it to say.
List every service that processes our data for our deploy, and where each one runs.
“Hosted in Australia” often means the database. Ask about the model, the search index and the job queue too.
See it on your own work
A six-week pilot runs one workflow for one team, and ends with a written evaluation against answers you already know.