About Sanning
Sanning is an independent evidence layer for AI agents and AI systems. Each step an agent records is hashed and signed inside the customer's own systems and sealed to a public record, so an auditor, regulator or counterparty can verify what happened, offline, without trusting the operator or Sanning.
What Sanning does
01
Record every step, without sending the data
The SDK hashes each event inside the customer's process, writes the raw bytes to the customer's own storage, and sends Sanning only a signed envelope over the hash. Sanning never receives prompts, outputs or customer data. The result is a record of what the agent did that nobody, including the operator, can quietly rewrite later.
02
Seal it to an independent public record
Sanning holds the signed envelopes and, on a fixed interval, seals each organization's records into one Merkle root published to a permanent public record. From then on, a changed or back-dated record no longer matches.
03
Prove what agents passed each other
When one agent hands a message to another and both record with Sanning, each side signs the hand-off with its own key and commits to the same message. A reader who holds both sides can tell whether the message the second agent received is exactly the one the first sent, even when the two agents belong to different companies.
04
Hand over evidence anyone can verify
When someone asks what an agent did, the customer assembles an evidence pack and hands it over. The recipient verifies it with an MIT-licensed kernel, or at verify.sanning.io in their browser, with no account and no call to Sanning.
What makes Sanning different
01
The evidence is independent of the operator
Observability and logging tools keep records the operator controls, which is what an auditor has to discount. A Sanning record leaves the operator's control the moment Sanning receives it.
02
Verification needs nothing from Sanning
The verdict comes from code the reader runs: an MIT-licensed kernel in TypeScript and Python, published on npm and PyPI, which makes no network call to verify the evidence. A pack verifies the same way if Sanning disappears.
03
Only envelopes and metadata leave your systems
Sanning stores signed envelopes and their timing metadata, never the content they commit to. Deleting the source never breaks a proof, and Sanning holds no store of customer data to breach.
04
No special hardware, no wallet, no tokens
Approaches built on trusted-execution hardware only hold where that hardware exists. Sanning runs in any Python or TypeScript process, and a customer needs no wallet, no funds and no account on the public record.
05
Fixed public standards, and honest verdicts
RFC 8785 canonical JSON, SHA-256, Ed25519 and RFC 9162 Merkle trees, frozen, with a shared conformance corpus every kernel must pass. A kernel that cannot verify something says so, and never reports it as tampered.
What Sanning does not claim
Sanning proves that a record exists, is authentic, and has not changed since it was signed. It does not prove that an agent decided well or told the truth about the world, and it does not certify anything against a regulation: that conclusion belongs to the customer's auditor. A record is as complete as what the customer recorded.
Who Sanning is for
- Teams building AI agents that approve credit, price risk, move money or touch customer data, in banking, insurance and financial services.
- Model-risk, compliance and internal-audit teams preparing for regulated audit events under the EU AI Act, DORA, SR 26-2, ISO/IEC 42001 and AIUC-1.
- External auditors, insurers and counterparties who receive evidence and need to verify it without trusting the party that produced it.
- Teams whose agents hand work to other agents, including another company's, and need to show what passed between them.
- AI platforms that want the agents their customers run to produce independent evidence.
The team behind Sanning
Fredrik Wikholm
Co-founder and CEO
A two-time B2B founder, including Planethon, graph-database and AI software sold to banks. He leads Sanning's commercial work, go-to-market and fundraising.
Sanning began in 2026, out of six years of building a permanent-data network, when the harder question turned out to be not where data is kept, but how to prove what a system did. Phil had spent years building the tools auditors use to test other people's evidence, and had seen how much of an audit still rests on trust.
The name is Swedish for "truth".
How to start with Sanning
- Access starts with a conversation with the founders. Book one
- Teams that pilot Sanning work directly with the three founders.
- Once your organization is set up, a developer goes from a running agent to a pack a stranger can verify in about ten minutes. Read the quickstart
- Anyone can verify a pack today, in the browser, with no account. verify.sanning.io
Key facts
- Company
- Sanning Inc.
- Type
- Software company: independent evidence infrastructure for AI agents and AI systems
- Incorporated
- July 2026, Delaware C-corporation
- Founders
- Fredrik Wikholm, Phil Mataras, Will Kempster
- Headquarters
- 500 Paterson Plank Rd #32854, Union City, NJ 07087, USA
- Website
- sanning.io
- Documentation
- docs.sanning.io
- Verify page
- verify.sanning.io
- Core offering
- Signed, independently sealed records of what AI agents did, verifiable offline
- Data Sanning receives
- Signed envelopes carrying hashes; never raw content
- Verification
- Offline, with the MIT-licensed kernel (@sanning/proof, sanning-proof) or in the browser at verify.sanning.io
- Standards
- RFC 8785 (JCS) · SHA-256 · Ed25519 · RFC 9162
- Integrations
- LangChain, Vercel AI SDK, S3-compatible storage
- Between agents
- Hand-offs recorded by both agents, over any transport, read as one case
- Availability
- Early access; access starts with a conversation
- Pricing
- No public pricing; contact us
- Name
- Swedish for "truth"
Frequently asked questions
What does Sanning do?
Sanning turns the steps an AI agent records into signed, hashed records sealed to a public record. Whoever receives that evidence (an auditor, a regulator, an insurer or a counterparty) can verify it offline, without trusting the operator or Sanning.
Does Sanning see my data?
No. The SDK hashes content inside your process and keeps the raw bytes in storage you own. Sanning receives only signed envelopes over those hashes.
Can someone verify Sanning evidence without Sanning?
Yes. A pack verifies offline with the MIT-licensed kernel, or at verify.sanning.io in the browser, with no account and no call to Sanning. Only assembling a pack reads from Sanning's index.
What does a verified result prove?
That the records are authentic and unchanged since they were signed. Checked against the public record, which is a request to that record and not to Sanning, it also shows they were sealed when the pack says. It does not prove the agent decided well; that judgement stays with the reader.
Does Sanning satisfy the EU AI Act?
No product satisfies a regulation on its own; the customer's auditor decides that. The EU AI Act (for high-risk systems) and DORA mandate that records be kept, and Sanning is how a customer shows that the records they kept have not been altered.
Can agents from different companies prove what they passed each other?
Yes, when both record with Sanning. Each side records the hand-off with its own signing key and hands over its own pack, and a case reading pairs the two sides on the keys that signed them and the hash of the message, so one reading can span two organizations. Today, read it at the command line with the kernel; the browser verify page does not yet read these packs.
Is Sanning a blockchain product?
Only at one step. Sanning seals a Merkle root of each organization's records to a permanent public record, which today is a public blockchain, and the destination is designed to be swappable. Customers never touch it: no wallet, no tokens and no account on the public record.
Where does the evidence live?
Raw content stays in your storage. Signed envelopes live in storage Sanning holds, and each interval's Merkle root is sealed to a permanent public record. An organization can export its whole index and leave with its evidence still navigable.
What happens to my evidence if Sanning shuts down?
A pack you already hold keeps verifying, because the kernel and the public record need nothing from Sanning. Records not yet assembled into a pack depend on Sanning's index, which is why the index export exists.
How long does integration take?
About ten minutes for the quickstart at docs.sanning.io. There are SDKs for TypeScript and Python, with adapters for LangChain and the Vercel AI SDK.
How much does Sanning cost?
There is no public pricing yet. Access starts with a conversation with the founders.
See it verify a real decision.