Audit ledger and receipts

    A tamper-evident record of what your organisation asked Ansvar and what came back, which an auditor can verify without access to Ansvar.

    Plan Company. Recording starts on its own.

    Try it

    Using Ansvar, list my audit receipts from 2026-10-01 to 2026-10-07 and verify the receipt for the most recent search.

    More examples:

    Using Ansvar, export the full audit package for our organisation for September 2026 so our auditor can verify it offline.
    Using Ansvar, list my audit receipts from the last seven days, then decrypt the most recent one and show me what the gateway returned.

    What comes back

    Ansvar writes an encrypted receipt for your organisation's calls and links the receipts so that changing one would break the chain. Each day the chain is co-signed and stamped by an independent timestamp authority, and an export carries everything an auditor needs to check it offline.

    For developers, the fields to read:

    • Listing: receipt metadata (timestamps, tool names, query ids), paged with next_cursor
    • One receipt: its encrypted envelope
    • Verification: the chain-hash result and the timestamp authority's signature check (RFC 3161)
    • Decryption: the query, the response and metadata
    • Export: the full bundle (every encrypted envelope plus anchors, timestamps and signatures; verifies offline) or the summary bundle (metadata and anchors only; does not verify offline). With include_plaintext=true an org-admin's full export also carries the decrypted content

    Which plan

    Company. A member reads their own receipts; an org-admin reads the whole organisation's, decrypts receipts and exports the organisation-wide package.

    Tools

    Limits

    • Not every tool's full request and response lands in the ledger. Effective-risk results are not stored at Ansvar, and a signed review decision is recorded as metadata only, so keep the results and tokens you need yourself.
    • A listing needs a date range. Ansvar never picks the window for you.
    • The summary bundle is a view of the record, not evidence. Give an auditor the full bundle.
    • An export larger than the response limit is refused with its size, never cut short. Narrow the dates or the scope.
    • Decryption and the organisation-wide export are refused for anyone who is not an org-admin, and each decryption is itself recorded.