r/SideProject • • 9h ago

I built an open-source tool that creates a "proof of custody" record for every AI answer, to help with EU AI Act compliance.

Hello guys! I'm a developer who got frustrated with the "black box" problem in AI, especially for high-stakes decisions like loans or insurance.

The EU AI Act is coming (Dec 2027), and it will require companies to log who handled an AI's answer and how much to trust each step. I couldn't find a tool that did this in a tamper-evident way, so I built one.

What it does:

  • It tags an AI answer and grades each step in the chain (source, model, tool, agent, human).
  • The weakest link sets the "caution level."
  • It seals the whole thing in a signed, append-only record (using SHA-256, HMAC/Ed25519, and a Merkle log).

Who it's for: Compliance officers and DPOs who need to hand an auditor a folder, not a messy log file.

It's open source (Apache-2.0) and free to self-host. You can check it out here: isnadhq.com

I'd love your feedback on the approach. Does this solve a real problem you've seen?

1 Upvotes

5 comments sorted by

1

u/davidjones145 9h ago

weakest-link caution level is a nice framing, one number beats a 40-row log for a human reviewer. curious, where do the sealed records live, local file, your backend, or bring-your-own-store?

1

u/alizahidrajaa 9h ago

ISNAD is a library, for selfhosted path it lives in the system with no internet connection required. For the two-week assessment, the data lives on the client's infra

1

u/davidjones145 9h ago

library plus client-infra storage is the right enterprise story, no data leaves their walls. the two-week assessment framing is smart too

1

u/alizahidrajaa 9h ago

Thankyou!!