AI interaction audit custody — built for OSFI E-23. Guard surfaces what your employees are doing with AI. Core proves it.
Sentinel Core Overview v3.0 — Technical Briefing — April 2026
Every federally regulated financial institution must produce runtime evidence of AI model lifecycle governance — not a policy document, not a risk framework. Evidence.
Every AI interaction captured the moment it happens.
Unalterable after the fact. Cryptographically chained, Merkle-anchored, externally timestamped.
On demand by an examiner, auditor, or board — no OAIS involvement required.
Every programmatic AI API call. Supports Anthropic, OpenAI, Azure OpenAI, Gemini, Bedrock. No network changes. No CA installation. No admin rights.
Every web-based AI interaction — ChatGPT, Claude.ai, Gemini, Copilot. Deployed via Intune or Chrome Enterprise Policy. No code change. No user action.
Together: a single verifiable audit record covering both your systems and your employees — including shadow AI.
Core is a standalone SDK wrapper. No browser extension. No IT deployment. One integration — full AI audit custody.
Wraps your existing AI client — Anthropic, OpenAI, Azure OpenAI, Gemini, Bedrock. Every prompt, response, and token count captured at execution.
HMAC-hashed, Ed25519-signed, Merkle-anchored, RFC 3161 timestamped. Immutable. Independently verifiable. No trust in OAIS required.
Track which models your systems use, token spend across providers. Optimize model selection, detect drift — all from captured interaction data.
Who needs Core alone? Teams running AI in production pipelines, agents, or backend systems — where there is no browser to monitor.
| User | Role | Department | Status | Actions | |
|---|---|---|---|---|---|
| No users configured — click + Add User to get started | |||||
| User | Rule Pattern | Reason | Expires | Actions |
|---|---|---|---|---|
| No active exemptions | ||||
In managed environments, administrators push the extension silently via Intune or Chrome Enterprise Policy — users never need to authenticate manually. AI provider access can be blocked entirely unless Guard is active.
Chrome & Edge. Deployed via Intune or Chrome Enterprise Policy. Captures AI tools adopted without IT approval.
OSFI examiner requests AI interaction evidence
Records, Merkle proofs, TSA tokens packaged
verify_chain.py — no OAIS dependency
Sectigo RFC 3161 timestamps confirmed
VERIFIED — independently, permanently
| Surface | Status | Coverage |
|---|---|---|
| Programmatic AI API calls | LIVE | Python systems, agents, pipelines — Anthropic, OpenAI, Azure OpenAI, Gemini, Bedrock |
| Browser-based AI tools | LIVE | All web-based AI in Chrome/Edge — including shadow AI |
| M365 Copilot (Purview) | Q2 2026 | Purview audit logs via Graph API. Word, Excel, Teams, Outlook, PowerPoint. ~2 weeks to deploy. |
| VS Code Extension | Q2 2026 | GitHub Copilot, Cursor, Codeium — AI code suggestions |
| Additional SDK Wrappers | ROADMAP | Node.js, Java, .NET |
Your content is hashed using a secret that lives in your infrastructure. OAIS never holds this key, never transmits it, and cannot retrieve it. This applies to both Core and Guard — regardless of which product you deploy.
Business continuity: Third-party escrow. Full export within 30 days of any cessation event. RFC 3161 tokens verify independently and permanently.
info@oais.ai | OAIS.ai | Ontario, Canada
All options share the same data sovereignty model — your content never leaves your environment.
For teams running AI in production pipelines, agents, or backend systems.
Cover every AI interaction surface — programmatic and browser-based — in one audit chain.
Browser AI control is your primary concern — block, flag, or escalate at the browser level.
Data sovereignty across all options — your HMAC key stays in your infrastructure. O.A.I.S. receives only irreversible hashes.