VITNAcompliance evidence layerSign in
[ studio brief, positioning ]

Evidence, not just
observability.

AI agents now produce regulated data flows. VITNA gives your agents pre-flight compliance checks they call before they act, each producing a signed, tamper-evident record of the decision, plus audit-grade event logs tagged with the regulatory frame at ingest. Mapped to 13 jurisdictions and 28 regimes.

VITNA produces Ed25519-signed evidence records that anyone can verify offline with a published public key and an open-source verifier, with no need to trust VITNA's servers. It is a cooperative guardrail with heuristic detection, and those limits are documented publicly. Its purpose is not prevention. It is independently verifiable proof that an AI agent's actions were checked and allowed.

How the three categories of agent safety tooling compare, and where each falls short: AI Agent Safety and Compliance Tools: A 2026 Comparison.

[ the problem your existing tools don't solve ]

Two stacks, one missing answer.

The buyer's actual problem

AI agents now produce regulated data flows. A retrieval-augmented chatbot touches a Quebec resident's record. A coding assistant logs an Aadhaar. The buyer's question isn't "can I see what my agent did?" or "am I compliant?". It is both at once: "what just happened, and was it legal?"

Why this doesn't split cleanly along existing tool lines

Observability tools (Datadog, Sentry, Splunk) capture what happened. Compliance tools (Drata, Vanta) document policies + run audits. Neither answers "is this agent action legal in real time?" The buyer has to wire two stacks together and write their own glue, usually after a regulator asks.

Why VITNA is built differently

VITNA captures every event AND tags it with the regulatory frame (DPDP / GDPR / PIPL / etc.) AT INGEST. The DPIA, ROPA, breach classifier, and cross-border registries all run against the live event stream. The dashboard and the compliance reports are the same surface, drawn from the same database.

[ how vitna differs from datadog + drata ]

Side-by-side.

CapabilityVITNADatadog / SentryDrata / Vanta
Real-time agent event feed
VITNA emits SIEM-grade events (CEF / LEEF).
no
Multi-jurisdiction PII detection
Aadhaar Verhoeff, PAN, UPI, SIN, CPF, NRIC, RRN, NIN, BVN, IBAN, VAT, My Number, China ID.
13 jurisdictionsGenericno
Per-jurisdiction breach classifier
DPDP §8, GDPR Art 33, CPRA §1798.82, LGPD Art 48, PDPA §26B, US-FED sectoral.
6+ jurisdictionsnoGeneric
EU AI Act classifier (Reg 2024/1689)
Risk tiers + effective dates + penalties + obligations.
nono
Pre-flight consent enforcement
Agents call /api/consent/check BEFORE processing, not after.
nono
Independently verifiable evidence export
Export signed pre-flight records as a package an auditor verifies offline with our published Ed25519 key: proves it was issued by VITNA and unaltered since export (not that the records are factually true).
nono
DPIA generator (live + snapshot)
Generated from live processing record; weekly snapshot for audit history.
noTemplate
DPDP §16 / APPI Art 28 / PIPL Art 38 cross-border registries
Country-level lookup with sectoral caveats.
nono
MCP server (agents call compliance tools)
@costrinity/vitna-compliance-mcp, 21 tools.
nono
Indigenous data sovereignty (OCAP / CARE / UNDRIP)
COSTRINITY is Indigenous-owned. Real position, not marketing.
Authenticnono
Cryptocurrency-native payments (Solana Pay)
Lower fees, no card-network forex markup, India + EM friendly.
Card-onlyCard-only
[ the built thing, verifiable ]

Numbers you can verify.

143
production API routes
28
compliance regimes
13
jurisdictions hand-coded
22
identifier validators
9
Indian sectoral regulators
16
US state privacy laws

Verify any number: /api/compliance/global-status, /api/.well-known/openapi, and /api/health/security are public + machine-readable.

[ positioning pillars ]

Four things that make us different.

Operator-first, not enterprise-first

Most compliance tools are sold to CISOs of 500-person companies. VITNA is built for the solo founder shipping an AI agent who needs DPIA + breach + cross-border notice in 5 minutes, not a 6-week audit kickoff.

Honest pre-audit readiness

We don't claim SOC 2 / ISO 27001 / HIPAA attestations we don't have. We DO publish detailed pre-audit readiness scorecards mapping every control to evidence. Procurement teams get the truthful answer they can verify.

Indigenous-owned, with real position

COSTRINITY operates from Treaty 4 territory (Regina, Saskatchewan). We support OCAP™ + CARE Principles + UNDRIP Article 31 because we live them, not because they're marketable.

Crypto-native + local-first

Solana Pay billing skips card networks. storage_mode=local means events stay on the operator's device. VITNA stores nothing server-side. Data sovereignty as a default, not a checkbox.

[ new in 2026 ]

VITNA for agents, called by agents

The @costrinity/vitna-compliance-mcp package exposes 20 VITNA compliance tools as MCP. Your AI agent can ask, mid-task: "Is this transfer DPDP §16 OK? Is this incident reportable? Is this AI use case high-risk under the AI Act?" and get the answer before it acts.

compliance as runtime decision support, not yearly DPIA
[ start here ]

Try VITNA in three steps.

1

Read the surface

Hit /docs or pull the OpenAPI spec for the 143-route catalogue.

2

Sign up

Free tier on /upgrade. PayPal or Solana Pay. No card walls on the free tier.

3

Wire up MCP

Add @costrinity/vitna-compliance-mcp to your agent. Your LLM can now call VITNA.

Start free →