Signed, tamper-evident, verifiable by anyone.
A cryptographic record of every AI agent run — mapped to the controls, policies, and frameworks your organization already uses. Send your auditors and enterprise buyers a verifiable link instead of screenshots and PDFs.
Every agent. Every framework. Every model.
The ones you build, the ones you buy, and everything in between — including:
Start with the governance question you need to answer. Map the obligation, choose the checks, record the run, then hand over a verifier-readable artifact.
Primust does not replace your policy engine, detector stack, dashboard, or enforcement layer. It binds what they did into evidence another party can verify later.
At the top level: turn governance requirements into runtime checks, then issue evidence that survives outside the original system.
The artifact can leave your system and still answer the review question later: what happened, what was proven, and what stayed outside the proof.
Agent runtimes move faster than their review paths. After primust init, a Python startup hook records governed sessions while they happen and auto-activates in the path before the governed session starts — wrapping whichever supported framework you've imported (OpenAI Agents, LangGraph, CrewAI, LlamaIndex, DSPy, Haystack, LiteLLM, MCP, Bedrock, Strands, Google ADK, MSAF, Pydantic AI, Semantic Kernel, AG2, OTel). Every tool call, every policy gate, every blocked attempt lands in the VPEC — with no change to supported agent code.
Install Primust before the session: when an agent edits files, runs commands, or opens a PR, the VPEC records what it touched, which policies gated the change, and exactly what was blocked. Without the hook, the git commit is only a diff.
primust-hook is a Go binary. Per-invocation. Zero permanent state on developer machines. IT-deployable. Same governance applies whether the agent is running locally or in CI.
This is not disclaimer language. It is the boundary that makes the evidence credible.
Start with the hosted verifier or go directly to the sandbox. The product decision should come after you have seen the artifact and its limits clearly.