The decision record for autonomous systems. A council deliberates. The judgment is sealed with SHA-256. The human decision is Ed25519-signed, bound to that exact hash, and chained into a ledger anyone can verify.
Autonomous systems make consequential calls. Afterwards, someone always asks the same questions: what was decided, on what reasoning, who approved it, and has the record changed since. StoneAI answers all four with cryptography, not screenshots.
Model seats vote on your request. The majority judgment becomes a decree, sealed with a SHA-256 content hash.
A reviewer approves or denies. The decision is Ed25519-signed and bound to the exact content it approves.
StoneAI notifies you by webhook. It holds no credentials to your systems and executes nothing in them. The action stays yours.
Think of a notary. A notary does not run your business. A notary leaves a record of what was agreed and when that is very hard to dispute later. StoneAI is that notary for AI decisions.
Precise, checkable specifics — not adjectives. Every figure below is counted from the current codebase, and the service reports its own health in public at /status. No fake uptime.
No single model presides. Each configured model seat casts a judgment, and the majority carries. Multi-model by design.
The winning judgment is the one most seats voted for. Confidence is the mean of the winning seats.
A split vote is broken by a fixed rule. The same votes always yield the same verdict.
If every seat fails, the council returns hold. It never guesses a verdict it did not reach.
Status — Council deliberation: Live. Today the live council draws on one independent model provider. Three or more independent seats: Roadmap.
Every judgment becomes a decree: reasoned, sealed with a SHA-256 content hash, and inert. It carries no credentials, no tokens, and no capability to act. Change one byte and the hash no longer matches.
Example data — for illustration.
A reviewer marks the decree approve or deny. That decision is Ed25519-signed over a SHA-256 digest of tenant, decree, approver, scope, content hash, nonce, expiry, and verdict — and it verifies only if the content hash matches the decree. Each nonce is unique to its decree. A decree can be decided once, while pending; a second attempt is refused. Then StoneAI notifies your systems, and your systems act.
Every ledger entry is SHA-256 over its tenant, event, payload, and the hash before it. A per-tenant lock prevents forks. Postgres rules block UPDATE and DELETE. Alter one entry and every hash after it breaks.
Example data — for illustration.
Anyone can verify a decision at /proof/:tenantId/:decreeId — no login. It checks the signature, the decree binding, the ledger entry hash, and the verdict.
Once an hour, each tenant's ledger is rolled into a Merkle root and submitted to OpenTimestamps, on a best-effort basis.
Postgres FORCE row-level security on decrees, approvals, the audit ledger, and billing tables. Tenants can be suspended and API keys revoked.
/status reports real process data in public. No uptime percentage we have not measured. No certifications we do not hold — today, that is none.
Every plan, including Trial, gets the same engine: the council, SHA-256 decrees, Ed25519-signed decisions, the hash-chained audit ledger, and public receipts. Plans differ only in volume. Pay by card or crypto.