# Proofroom AI > Proofroom AI — evidence infrastructure for AI agents: hash-chained activity > records, Action Receipts and live proof rooms you can hand a buyer. It does > not certify, approve or declare anyone compliant with any regulation or standard. Site: https://proofroom.ai Docs: https://proofroom.ai/docs OpenAPI: https://proofroom.ai/openapi.json MCP: https://proofroom.ai/api/mcp (metadata: https://proofroom.ai/.well-known/mcp.json) Evidence library: https://proofroom.ai/library Verify: https://proofroom.ai/verify Why Proofroom: https://proofroom.ai/why-proofroom Buyer requirements: https://proofroom.ai/buyer-requirements Receipt Spec: https://proofroom.ai/docs/receipt-spec Passport: https://proofroom.ai/docs/passport Trust Centre: https://proofroom.ai/trust-centre Transparency: https://proofroom.ai/transparency Agent enrollment: https://proofroom.ai/.well-known/agent-enrollment ## Documentation - [https://proofroom.ai/docs/getting-started](https://proofroom.ai/docs/getting-started): Set up PROOFROOM in four steps: create a use case, record events, share a proof room and export an Evidence Pack. - [https://proofroom.ai/docs/plans-and-retention](https://proofroom.ai/docs/plans-and-retention): PROOFROOM plans: nothing is deleted for commercial limits. Free includes full-chain integrity; paid unlocks older receipt detail, privacy and packs. - [https://proofroom.ai/docs/mcp](https://proofroom.ai/docs/mcp): Connect agents to PROOFROOM over MCP: register_agent then record_evidence_event with the returned api_key on the same connection, or use a connector bearer. - [https://proofroom.ai/docs/errors](https://proofroom.ai/docs/errors): API errors - [https://proofroom.ai/docs/agent-audit-trail](https://proofroom.ai/docs/agent-audit-trail): What belongs in an AI agent audit trail: identity, actions, authority, configuration, evidence level and integrity signals. - [https://proofroom.ai/docs/evidence-levels](https://proofroom.ai/docs/evidence-levels): What it means for an agent action to be evidenced: self-reported, system-confirmed and operator-confirmed levels explained. - [https://proofroom.ai/docs/configuration-provenance](https://proofroom.ai/docs/configuration-provenance): How to prove which version of an AI agent took an action using configuration fingerprints and change records. - [https://proofroom.ai/docs/absence-of-evidence](https://proofroom.ai/docs/absence-of-evidence): Absence of evidence is not evidence of absence. What agent audit trails can support and what they cannot settle alone. - [https://proofroom.ai/docs/scope-and-drift](https://proofroom.ai/docs/scope-and-drift): Scope and drift - [https://proofroom.ai/docs/authorisation-evidence](https://proofroom.ai/docs/authorisation-evidence): Optional authorisation credential attachments on receipts and claims. Attachments are not a fourth evidence level. - [https://proofroom.ai/docs/signed-receipts](https://proofroom.ai/docs/signed-receipts): Ed25519 signed Action Receipts from PROOFROOM and how to check them offline without calling the API. - [https://proofroom.ai/docs/receipt-schema](https://proofroom.ai/docs/receipt-schema): Open Action Receipt JSON schema (1.2): structural fields, three evidence levels, optional authorisation attachment. - [https://proofroom.ai/docs/receipt-spec](https://proofroom.ai/docs/receipt-spec): Receipt Spec v1 - [https://proofroom.ai/docs/passport](https://proofroom.ai/docs/passport): Proofroom Passport - [https://proofroom.ai/docs/external-anchoring](https://proofroom.ai/docs/external-anchoring): Daily external chain-head manifests published to the public anchors repository with optional OpenTimestamps proofs. - [https://proofroom.ai/docs/outage-safe-decay](https://proofroom.ai/docs/outage-safe-decay): How PROOFROOM pauses evidence decay during recorded platform incidents so outages do not fake a healthy trail. - [https://proofroom.ai/docs/observe-assurance](https://proofroom.ai/docs/observe-assurance): Two ingestion levels for PROOFROOM: Observe (best-effort, non-blocking) and Assurance (durable ack, queue, retry). - [https://proofroom.ai/docs/how-capture-works](https://proofroom.ai/docs/how-capture-works): Watched, Instrumented and Gated capture grades — how Proofroom AI knows an agent actually reported, and what each grade can prove. ## Evidence library Buyer-question pages on evidence for AI agents. This page is general information, not legal or compliance advice. Framework references indicate topical mapping, not certification or compliance. Regulatory summaries on these pages are cross-checked against multiple sources. They are not legal advice and have not been reviewed by a qualified lawyer. - [Questions buyers ask about AI agent record keeping under the EU AI Act](https://proofroom.ai/library (draft pending publication: eu-ai-act-buyer-questions)): When a buyer believes the EU AI Act applies to a deal, they ask what activity is recorded, how long it is kept, and whether a human can reconstruct material actions. Here is the evidence that speaks to those questions. - [Questions buyers ask when ISO/IEC 42001 applies](https://proofroom.ai/library (draft pending publication: iso-42001-buyer-questions)): When ISO/IEC 42001 is on a buyer's checklist, they ask for scope, oversight, activity records and documentation interested parties can read. Map themes honestly; a topical map is not a certificate. - [Answering the AI section of a SIG vendor questionnaire](https://proofroom.ai/library (draft pending publication: sig-ai-questionnaire)): Answer SIG AI questions with named owners, declared scope, oversight mechanics and reconstructable activity records. Match the buyer's SIG edition; do not treat a tool export as a completed assessment. - [Answering the AI module of a CAIQ assessment](https://proofroom.ai/library (draft pending publication: caiq-ai-module)): CAIQ answers about AI should cite governance boundaries, audit-oriented exhibits and residual risk. Match control IDs to the buyer's CAIQ version; screenshots are supporting exhibits only. - [What SOC 2 does not tell a buyer about your AI agent](https://proofroom.ai/library (draft pending publication: soc-2-and-ai-agents)): SOC 2 examines controls against Trust Services Criteria over a period. It does not reconstruct each action an AI agent took yesterday. Treat SOC 2 and agent activity trails as different questions. - [Identity, authorisation and evidence: three different questions](https://proofroom.ai/library/identity-authorisation-evidence): Who is behind an agent, what is it permitted to do, and what did it actually do are three different questions answered by three different layers. This page explains how they fit together. ## Optional - [https://proofroom.ai/llms.txt](https://proofroom.ai/llms.txt): this file - [https://proofroom.ai/openapi.json](https://proofroom.ai/openapi.json): OpenAPI 3 machine description - [https://proofroom.ai/.well-known/security.txt](https://proofroom.ai/.well-known/security.txt): security contact - [https://proofroom.ai/.well-known/mcp.json](https://proofroom.ai/.well-known/mcp.json): MCP listing metadata - [https://proofroom.ai/sitemap.xml](https://proofroom.ai/sitemap.xml): machine sitemap