HP customer case study · May 2026

Someone elsechecked our work

Every AI vendor says its audit trail can be trusted. HP examined ours on their own hardware and published what they found, under their copyright and their document number.

Everything below links to the page it came from. Check us against them.

HP supplied evaluation hardware and published their findings. This is their document. It is not an endorsement, and it is not a review of any particular deployment.

May 2026 edition · 13 MB

Cover of HP's published customer case study, document c09271400: Governed Autonomous AI on the HP ZGX Nano AI Station.Open all 13 pages
HP Development Company, L.P. · c09271400 · May 2026

What they found

Every point below carries the page it came from. Click the page and HP’s document opens there. We would rather you check than take our word.

The record is written before the action, not after it

The reasoning behind a decision is captured before execution begins, so the record of why exists whether the action succeeded, failed, or was interrupted. HP's document draws the consequence out: evidence created at the time holds up better than an account assembled afterward.

Contemporaneous evidence of decision-making is more defensible than post-hoc reconstruction.

Change one record and every record after it says so

Each record carries the fingerprint of the one before it, forming an append-only chain. An edit is not merely against the rules; it becomes arithmetic that stops adding up. Chain integrity can be verified on demand.

Sealed with published federal standards

SHA3-256 under FIPS 202, Ed25519 under FIPS 186-5, and ML-DSA-65 under FIPS 204, the post-quantum signature standard. A record sealed today stays verifiable against tomorrow's computing. For anything you keep for decades, that is the whole argument.

The air gap is proven, not configured

A built-in command runs an automated packet capture across every network interface and produces auditable evidence that traffic stayed inside. The difference between a setting somebody could change and a measurement somebody can check.

Auditors can look without touching

A dedicated read-only portal gives external auditors full inspection while leaving the record exactly as they found it. Exports run to JSON and CSV, and the compliance layer maps them against the frameworks you already answer to.

The trust layer is open, so you can check it yourself

The audit core is open source under Apache 2.0, with perpetual royalty-free patent grants that expressly extend to government systems, plus public conformance vectors. Read the code, confirm what it connects to, and verify your own records on your own.

Open source means you can audit the code, verify there are no hidden connections, examine the security implementation, and build on it. For regulated environments, this is not a feature. It is a requirement for trust.

Where this shows up

Three questions that arrive without warning, and what you reach for.

An auditor asks what the system did last quarter.

Hand them the read-only portal. They inspect the chain themselves and leave the record as they found it.

A regulator asks who authorized a specific action.

The authorization is inside the record, signed, alongside the reasoning captured before the action ran.

A record is challenged years from now.

It was sealed with published federal standards, including the post-quantum signature standard, and the chain still proves it stands unaltered.

What they measured

Observed during deployment, as reported in the document.

Install to operational
~30 minutes
External connectivity
None required
Cloud services
None required
Compliance frameworks
10 with built-in tooling
Air-gap verification
Automated, auditable

Read it yourself

The full document runs 13 pages. HP hosts the current edition and revises it without notice, so their copy is the one to trust. Ours is a dated snapshot, kept so the record survives if a link ever moves.

May 2026 edition · 13 MB

HP Development Company, L.P. Document c09271400, May 2026. Reproduced here as published.

See how the record works

The audit chain HP examined is the Capsule protocol. It is open, specified in public, and yours to verify.