⚖️ APP 1.7–1.9 enforcement begins 10 December 2026 135 days, 0 hours remaining.Get in touch →

Product & Features

Every automated decision, recorded automatically

ADM Guard is a drop-in REST API that captures automated decisions the microsecond they execute in production - no manual logging, no policy documents to keep in sync, and privacy-focused controls to reduce personal data capture.

How it works

Three steps to a defensible audit trail

1

Call the API

One HTTPS POST per decision, with a client-generated idempotency key. Safe to retry on any network failure - we guarantee no duplicates and no lost events, no client library required.

2

Decisions record themselves

Every automated decision streams to our Australian ingestion API. New systems and versions auto-register on first sight. PII is rejected at the boundary - it physically cannot be stored.

3

Evidence on demand

Live ADM register, per-person decision trails for access requests, cryptographic verification, and signed PDF evidence reports ready for a regulator or your board.

Features

What's included

Auto-registering ADM system

Every new automated decision system and version registers itself the first time it emits an event - the register can never drift from what's actually running in production.

Tamper-evident audit trail

Per-tenant SHA-256 hash chains, daily Merkle roots anchored to write-once storage, and independent timestamping. Verify at any time that nothing was quietly rewritten.

Zero-PII boundary

No free-text fields. Payloads containing names, emails or phone numbers are rejected at the API boundary by validation controls before they're persisted.

Evidence Reports

Generate signed PDF Compliance Evidence Reports on demand - a live export of your automated decision register, ready for a regulator, auditor, or your board.

Australian residency

All data persists in Azure Australia East. Region-locked by cloud policy - nothing crosses the border.

Idempotent by design

Every write carries an idempotency key. Retry any failed or timed-out call as many times as you need - we'll never create a duplicate, and no decision event is ever silently lost.

Security & architecture

Built to pass your security review in days, not months

Zero-PII by architecture

No free-text fields. No names, emails or phone numbers - payloads containing PII are rejected with a 422 and never persisted, logged or queued. You send anonymous tokens only; we never hold the mapping.

Tamper-evident by design

Per-tenant SHA-256 hash chains, daily Merkle roots on locked WORM storage, and independent RFC 3161 timestamps. Prove to anyone - including a regulator - that history was never rewritten.

Sovereign by default

All data persists in Azure Australia East. Region-locked by policy. Encrypted at rest with per-tenant keys. Scale tier adds single-tenant database isolation.

FAQ

Frequently asked questions

Do you ever see our customers' personal information?

No. You send client-generated anonymous tokens (e.g. cand_88192_x) - never names, emails or phone numbers. Our API applies validation controls and rejects payloads that match configured PII patterns before persistence. You keep the identifier mapping in your own systems.

How long does integration take?

Our target is under 30 minutes from your first API call to first decision visible in your dashboard. A full production rollout across several decision points typically fits in one afternoon.

Where is our data stored?

Exclusively in Azure's Australia East region, enforced by cloud policy. Archived audit batches are held on write-once (WORM) storage with locked retention - they cannot be altered or deleted, even by us.

Does ADM Guard make us legally compliant?

ADM Guard provides the technical evidence layer - the immutable record of what your automated systems actually did, plus the live register and disclosure-ready reports the obligations anticipate. Legal compliance also involves your privacy policy and processes; we integrate cleanly with the advice of your privacy counsel. ADM Guard does not provide legal advice.

What counts as an automated decision we should log?

Anything programmatic that materially affects a person's rights, entitlements or finances: credit and risk scoring, resume screening and ranking, tenancy application filtering, insurance eligibility rules, keyword auto-rejections, even conditional macros. If a human didn't decide it, log it.

What happens if we exceed our monthly decision volume?

Nothing breaks - we never drop your compliance data over a billing threshold. We'll notify you and talk about the right tier.

Do we need to install a client library to avoid losing decision events?

No. ADM Guard is a plain REST API - every write takes a client-generated idempotency key, so you can safely retry on any timeout or network failure without ever creating a duplicate or losing an event. We publish reference retry snippets for common languages, but there's no package to install, version, or keep patched.

Does ADM Guard judge whether our decisions were fair or lawful?

No - and deliberately so. ADM Guard is a recorder, not a decision-maker: like a flight data recorder, it faithfully captures what your systems actually did without evaluating whether the decision itself was correct, fair, or lawful. That judgment call - and the legal responsibility for it - stays with you.

See it on your own decision points

Get in touch and we'll walk through a live integration on your data shape.

Contact Us