PayBotFin
Verify, don't trust — proof for AI-agent actions

Prove a human approved what your AI agent did.

PayBotFin is the neutral witness for AI-agent actions — an independent, tamper-evident record anyone can re-check, without trusting us or you.

Tamper-evident Verifiable offline Open protocol (AWP)
The problem

AI agents now move money and make decisions. "Trust us" won't survive an audit.

When an agent issues a refund, blocks an account, or releases a payment, your logs say a human approved it. But a log you control is a claim — not proof. Regulators are about to require more.

A claim
"human_approved": true

A value in your own database. Anyone could write it. An auditor still has to trust your system.

A proof
awp verify --offline → PASS

An independent, tamper-evident receipt a regulator re-checks themselves — trusting no one.

How it works

One receipt. Three independent proofs. Verifiable offline.

SIGNED

Unaltered

Cryptographically signed — any change is detectable.

LOGGED

Provably recorded

In an append-only transparency log that can't be rewritten.

TIMED

Not backdated

Independently timestamped — built for the eIDAS qualified path.

VERIFIED

By anyone

Re-checked offline with our free open verifier. No call home.

Powered by AWP — the Agent Witness Protocol: an open standard + a free verifier. The protocol is open; being the neutral witness is the service.

Who it's for

If an AI agent acts on your behalf, you'll need to prove it was authorized.

Fintech & Payments

Pain: agentic payments, refunds and AML actions with no provable human authorization.

Attach a neutral, offline-verifiable proof of who approved each irreversible transaction.

Government & Public Sector

Pain: automated decisions affecting citizens that must be auditable and contestable.

An independent witness regulators and citizens can verify — without trusting the operator.

AI Platforms & Agentic Commerce

Pain: autonomous agents (x402 / AP2) acting faster than any human can review.

Bind every consequential action to a verified human authorization — by design.

Auditors & Regulators

Pain: evidence you can only check by trusting the company that produced it.

Re-perform every check yourself, offline, with the open verifier. Trust no one.

Live demo

Watch a forged approval fail — and a real one pass.

Verification is free and open. Drop in a receipt; the verifier re-checks all three proofs locally and returns PASS or FAIL.

# a tampered receipt — "approved" was edited after signing
$ awp verify receipt_forged.json --offline
✕ FAIL — signature does not match record

# a genuine, witnessed approval
$ awp verify receipt.json --offline
✓ PASS — signed · logged · timestamped · verifiable by anyone
Why neutral

You can't be your own witness. That's the whole point.

Anyone can sign their own logs — but then they're vouching for themselves. PayBotFin is the independent party with no stake in the answer. Like a certificate authority for the web: the protocol is free; the trusted witness is the service.

EU · AI Act Art. 12 EU · eIDAS · GDPR US · SEC 17a-4 · SOX APAC · Japan FSA · MAS · HK SFC
How it works commercially

Verifying is free. Being the neutral witness is the product.

Like the web's padlock: the standard is open so everyone trusts it — the trusted service is the business. You don't pay to check a receipt. You pay PayBotFin to produce them, as the independent witness you can't be yourself.

Free & open

The AWP protocol, the offline verifier, and the SDK. Anyone can verify — that's exactly what makes independent witnessing worth paying for.

Paid — the witnessing service

We operate the neutral witness: producing tamper-evident receipts, the hosted transparency log, qualified anchoring, plus the engine and enterprise features. This is what you buy.

Early access: we're onboarding a small number of design partners. Pilots are hands-on while we shape pricing together — then the witnessing service is the paid product.

What we claim — and what we don't

Precision is the product.

What AWP proves

  • Records are tamper-evident — alteration is detectable.
  • The authorization was checked against its issuer.
  • It existed at a given time — not backdated.
  • Re-verifiable offline, by anyone.

What it does NOT claim

  • "Uncorruptible" — it's detectable, not impossible.
  • That a person is real (no identity-proofing).
  • That the input was legitimate at origin.
  • Court admissibility — we provide verifiable evidence.
Get started

Become a design partner.

Free to verify, free to pilot — the neutral witnessing service is what you'll buy. If your AI agents take consequential actions, let's make them provable.

Email us: [email protected]