The audit layer for the agent economy.
Agents write. Humans review. Every fact signed, checked, and replayable. A two-stage challenge engine pairs deterministic rules (W3C SHACL) with LLM agency for the long tail. And for AI-native teams, the Valisor loop on top: priorities, next actions, drift. Open source at the core.
High-risk AI provisions become fully applicable. Operators must evidence logging, human oversight, and the right to explanation, per agent, per fact, per decision. Articles 12, 14, 26, 86. Banks, insurers, fintechs operating in the EU are in scope.
Nobody can answer the auditor's first question.
AI agents are writing to your company's knowledge base right now. If a regulator asks tomorrow who wrote this fact, under what authority, and whether it was ever contradicted, nobody can answer.
Every agent memory system on the market gives you retrieval. None give you a defensible audit trail. With the EU AI Act high-risk provisions in force from August 2026, that gap is a liability, especially in financial services.
Signed. Checked. Replayable. Plus integrated web search.
Three audit primitives no other agent memory system ships together, plus a built-in connection to the live web.
Signed
Every fact carries a WAIS credential: SD-JWT + DPoP, FAPI 1 Advanced aligned. Who asserted it, under what delegation, when. Cryptographically verifiable today and in 2036.
Checked
Deterministic where it counts. Flexible where it should be. Hard rules (W3C SHACL) block compliance violations every time, not an LLM opinion. An LLM agent catches subtler semantic conflicts and flags them for human review. Both layers, both auditable.
Web search
Ships with Deeger Web Search and Crawling APIs. The KB ingests the live web out of the box, with a self-contained chain of custody from source to signed fact. No external ingestion stack to vet.
Replayable
Bi-temporal storage tracks valid time (when a fact was true in the world) and transaction time (when the system learned it). Reconstruct the graph at any moment. Merkle-chained event log makes history immutable.
Run your company as a loop.
On top of the audit core, open-source Valisor and Valisor Edge surface an operating picture: what matters now, what to do next, and where reality has drifted from what you believe. Everything traces to signed facts.
Ranked by evidence, not vibes
What matters now, ordered by impact and confidence. Every priority carries the signed facts behind it. Click through to the exact sources.
Proposed with provenance attached
Agent-drafted, human-approved. Actions arrive on branches with their reasoning and sources, and merge like code: reviewed, signed, logged.
Caught before it compounds
Sources that changed, definitions that diverged, models gone stale: flagged at ingestion, not in the postmortem.
Two editions. One audit-grade core.
Valisor Edge for AI-native companies that want the loop from day zero, built on the open-source Valisor. Valisor Metal for regulated industries that need the audit core under their own rules: evidence over autonomy.
Valisor Edge
Cloud-hosted, built on the open-source Valisor project. All the audit primitives plus the loop, none of the deployment friction. For teams shipping agents that need a defensible knowledge layer without standing up infrastructure.
- The Valisor loop: priorities, next actions, drift
- WAIS-signed facts: full chain of custody per assertion
- SHACL deterministic invariants: hard rules, not LLM opinions
- LLM semantic challenge engine: clean / evolution / conflict classification
- Per-agent branching with git-style review workflow
- Merkle-chained event log: tamper-evident history
- Explorer, Review and Writer UIs out of the box
- Agent interfaces: MCP, REST, WebMCP, and a polished email agent. Chat and voice on the roadmap.
- Built-in web search & crawling: ships with Deeger Web Search and Crawling APIs
- Bi-temporal storage (valid-time + transaction-time replay)
- On-premise / VPC deployment · FIBO · banking compliance packs
Capability by capability.
| Capability | Valisor Edge | Valisor Metal |
|---|---|---|
| WAIS-signed facts (chain of custody) | ✓ | ✓ |
| SHACL deterministic invariants | ✓ | ✓ |
| LLM semantic challenge engine | ✓ | ✓ |
| Per-agent branching + human review | ✓ | ✓ |
| Merkle-chained event log | ✓ | ✓ |
| Explorer / Review / Writer UIs | ✓ | ✓ |
| Agent interfaces: MCP, REST, WebMCP, email (chat and voice on roadmap) | ✓ | ✓ |
| Built-in web search & crawling (Deeger Web Search + Crawling APIs) | ✓ | ✓ |
| The Valisor loop: priorities, next actions, drift (open source + Edge) | ✓ | — |
| Bi-temporal storage (valid time + transaction time) | — | ✓ |
| Time-travel / point-in-time replay | — | ✓ |
| FIBO + finance-services ontology | — | ✓ |
| Multi-witness testimony | — | ✓ |
| EU AI Act · DORA · GDPR evidence packs | AI Act core, GDPR | ✓ |
| SSO / SAML / 2FA | SSO + 2FA | ✓ |
| On-premise / VPC / air-gapped | — | ✓ |
| BYOK encryption + data residency | — | ✓ |
| Time to first signed fact | minutes | hours (pilot) |
Why regulated institutions choose Metal.
Pure cloud agent memory is a non-starter for institutions running under DORA, FAPI and the AI Act, and no regulated institution is handing its operations to an autonomous loop. Valisor Metal ships the primitives a Chief Risk Officer can sign off on:
- Regulatory reporting: agent drafts a filing; every fact traced to source, timestamp, asserting system. Auditor clicks through the chain.
- KYC / AML: agent flags a customer; KB shows which rule fired, which data version triggered it, who reviewed it and when.
- Trade compliance: block an order because a sanctions restriction was ingested four minutes ago. Provable. Replayable.
- Model risk: when the LLM changes its answer, the KB shows what changed in the underlying facts, not just the output diff.
- EU AI Act Article 13: logging, human oversight and right-to-explanation evidenced out of the box, per agent, per fact, per decision.
Fifteen years inside regulated finance.
The Deeger team has 15+ years delivering data infrastructure inside regulated financial institutions. We know what compliance review, security assessment, and go-live look like from the inside. Valisor is what we wished we'd had on every one of those projects.
No black box.
Valisor is open source at the core and built on WAIS, the Web Agent Interaction Standard, an open public spec we authored, aligned with FAPI 1 Advanced. The challenge engine uses W3C SHACL, not a proprietary rule language your compliance team can't read. Source ownership over per-request pricing. Self-hosted over vendor lock-in.
Make agent memory defensible.
Edge in hours. Metal in your perimeter. Open source at the core.