Evidence is only useful if it can be trusted
We hold ourselves to the standard we ask of agents: say what happens, show it, and let others check. Here's how records are protected and what we keep.
How evidence is signed and verified
- 1
Record
An action is written as a structured record: what happened, for which customer, when, and what authorised it.
- 2
Sign
The record is signed. Any later change to it, however small, means the signature no longer matches.
- 3
Chain
Each record includes a reference to the one before it. Removing or reordering records breaks the chain.
- 4
Verify
A bank can check signatures and the chain itself, without relying on the vendor's word or on ours.
We'll publish the technical details of our signing scheme and a verification guide for bank teams. Ask us for the current draft.
What we store, and what we don't
We keep what's needed to prove what happened, and as little else as possible.
We store
- Action records: action type, time, the customer reference you choose, and the authoriser
- Signatures and chain references for each record
- Coverage counts per period
- Who in your team and your customers' teams can access which packs
We don't store
- Your model weights, prompts or system instructions
- Full conversation transcripts, unless you choose to attach them
- Card numbers, passwords or authentication secrets
- Data about one bank's customers in another bank's pack
Where we are today
- Certifications
- We're an early-stage company and don't hold SOC 2 or ISO 27001 certification yet. When we start an audit, we'll say so here.
- Hosting and data location
- We'll publish our hosting regions and subprocessors here before the first customer goes live.
- Reporting an issue
- Found a security problem? Email hello@shoirly.com with “Security report” in the subject. We'll reply within two working days.
Want the detail for your security review?
Book a call and we'll walk your team through signing, verification and data handling.