Provable beats trusted.
Every audit log ever presented as evidence has carried an invisible footnote: trust whoever operates the database.
The operator was honest, the disks were secure, nobody with admin rights had a bad quarter. Nothing in the log itself could say so. We think a document of record should not need the footnote. A wax seal is not a promise; it is a mechanism. Break it and the breaking shows.
Sigilbase exists to build that mechanism for records, and it holds itself to one test.
If you stopped trusting us entirely, tomorrow, your evidence should not care.
Who holds the pen?
Sigilbase is built like a registry, not a feed, and the difference is who holds the pen.
-
In your database
Your admins can rewrite it. Nothing shows the change. This is where most audit trails live, and it is why auditors are handed screenshots and CSV exports and asked to trust them.
An assertion.
-
In your app, hash-chained
Better: tampering is detectable. But you still hold the keys and the checkpoints, so the party being audited still holds the pen, and a logging tool proves events were received, not that history is intact.
Detectable, but still yours.
-
In Sigilbase
The record is held by a third party, anchored outside our reach, and verifiable by anyone with an open-source tool. Nobody has to take anyone's word, including ours.
Evidence.
How we hold ourselves to it
-
Retention is forever
A registry that discards entries is not one. No plan expires history, ages it out, or charges to keep it.
-
Ingestion never stops
History should not have gaps where an invoice went unpaid. Billing can restrict a dashboard; it never stops the record.
-
The verifier is open
Proof you cannot check yourself is just a claim with better typography. The verifier is open source, self-contained, and ships in every bundle.
-
We log ourselves
Our own operations are recorded in the same sealed ledger we sell, because a rule we exempt ourselves from is not a rule.
Who is building this
Sigilbase is built by Laurence Walpole, a payments and infrastructure engineer at a UK SME lender, where he holds hands-on PCI DSS (SAQ-D) compliance responsibility. It began as the tool he wished existed on the producing side of a decade of audit evidence: records that could be proven rather than vouched for.
It is designed, built, and run by one person, deliberately small, on the view that evidence infrastructure should be boring, permanent, and checkable by strangers.
The company, as a record
| Entity | Sigilbase Ltd |
|---|---|
| Registered | England and Wales, no. 17332548 |
| Office | 66 Paul Street, London EC2A 4NA |
| Founded | July 2026 |
| Made in | the United Kingdom |
Start recording provable history
Chained, sealed, independently verifiable audit logs, from the first event. Free while Sigilbase is in beta.
Questions first? Write to hello@sigilbase.io.
Read how the verifier works, what we claim about security, or the documentation.