Skip to content
SpanForge Platform by SpanForge

You can’t govern what
you can’t see.

SpanForge is the compliance and governance platform for agentic AI systems. Structured RFC-0001 events, HMAC-signed audit chains, PII redaction, and regulatory evidence packages — provable compliance before auditors or incidents find the problem first.

See it in action.

Three scenarios. Three ways SpanForge generates compliance evidence that your dashboards miss. Switch between tabs to explore — consent records, audit chain verification, and PII redaction events.

These are representative examples. Real output varies by agent configuration and playbook definitions.

SpanForge — Production Monitor
agent_id loan-approval-v2
status MONITORING
baseline established 2026-03-01
decisions 1,247 today
drift_score 0.02 (normal)
ALERT [14:32:07] — Consent boundary violation
data.credit_history accessed outside declared purpose
action ESCALATED to compliance@org
playbook GDPR-002 triggered
agent PAUSED pending human review
// SpanForge caught it before the regulator did.
Capabilities

Everything production AI needs.

01

Structured compliance events

Every LLM call, tool invocation, decision, and guardrail check is recorded as a typed RFC-0001 event — a structured envelope with required fields, audit metadata, and schema-validated payloads.

02

HMAC-SHA256 audit chains

Every emitted event is cryptographically signed with HMAC-SHA256 and chained to its predecessor via prev_id. Verifying the chain proves the event stream has not been modified, reordered, or truncated.

03

PII redaction before export

First-class PII detection and redaction via the llm.redact.* namespace. Sensitivity levels, custom redaction policies, and field-level re-identification risk — before any event reaches a backend.

04

Regulatory framework mapping

ComplianceMappingEngine maps events to obligations under EU AI Act, GDPR, SOC 2, ISO 42001, and NIST AI RMF. HMAC-signed evidence packages are generated on demand for auditors and regulators.

05

Schema governance

Consumer registry, deprecation tracking, and schema migration tooling. Block or warn on disallowed event types, declare schema dependencies, and ensure every consumer is compatible before you ship.

06

Export to any backend

OTLP, Webhook, JSONL, Datadog, Grafana Loki, and Cloud export backends. EventStream multiplexer with Apache Kafka support for streaming compliance pipelines.

Integration

Up and running in an afternoon.

01

Instrument

pip install spanforge and emit RFC-0001 events from every LLM call, tool invocation, and decision point. Zero required dependencies.

02

Sign

Every event carries an HMAC-SHA256 signature chained to the previous — tamper-evident audit trail by design, not by configuration.

03

Validate

Run spanforge validate in CI. Catch non-compliant events, schema violations, and broken audit chains at build time — not post-incident.

04

Prove

ComplianceMappingEngine generates HMAC-signed evidence packages mapped to EU AI Act, GDPR, SOC 2, ISO 42001, and NIST AI RMF.

Who it’s for

Built for regulated, high-stakes AI.

Financial services

Credit decisions, fraud detection, customer communication agents, AML monitoring.

Healthcare

Clinical decision support, triage routing, patient-facing assistants, prior authorisation agents.

Legal & compliance

Contract analysis, regulatory monitoring, compliance automation, document review agents.

Operations & Automation

Procurement automation, HR decision support, internal knowledge agents, IT service automation.

SpanForge Platform

Know what your AI is doing. Always.

SpanForge is the compliance and governance platform for agentic AI systems. Instrument, sign, validate, and prove compliance from day one.

Get started with the SDK →Read the standard →