AI agent monitoring & evidence

Black Box records everything your AI agents do.

Every tool your agents touch, every action they take, every result they get back — captured on the wire, tamper-evident and independently anchored, and turned into evidence your risk, compliance and legal teams can actually use.

Ask a pilot: flight data recorders aren't black. They're fluorescent yellow, so investigators can always find them. Ours too.

Live recording — tap any record to try tampering with it verify → OK · record intact

Every entry is cryptographically linked to the one before it. Change anything — even one character, even years later — and every link downstream breaks, visibly. That is the difference between a log and evidence.

Monitoring that watches the AI itself.

Your agents — in Cursor, Claude, and your own systems — connect to company tools through MCP. Black Box sits on that wire and records every interaction as it happens. The AI can't opt out, can't forget to log, and can't edit the record afterwards.

What your team sees

One view that answers the auditor's first question: is everything recorded?

Risk, compliance and legal don't read logs. They open Black Box and see coverage, proof of integrity, and a button that produces the document a regulator accepts.

Replay any session step by step when something needs explaining. Export a time-bounded incident pack with chain-of-custody proof when something needs reporting. Retention and legal hold enforced — and provable.

You're asked forBlack Box produces
EU AI Act Art. 12Automatic recording of every agent action over the system lifetime — without rebuilding your AI systems.
EU AI Act Art. 19 / 26Retention you can prove — six-month minimum, legal hold, on your own infrastructure.
EU AI Act Art. 73The incident pack — everything between two timestamps, reconstructed, with integrity proof attached.
GDPR Art. 17Audited erasure — content deleted on request, integrity preserved, the deletion itself on record.
ISO 42001 · SOC 2The evidence pack — one period-bounded document, mapped to the framework, ready to hand over.
Minutes to deploy

Your IT team runs one command. Recording starts everywhere.

1 — Install

One command finds every AI tool connection on a machine — Cursor, Claude, your own agents — and routes it through the recorder. Nothing else changes.

2 — Forget

Black Box runs silently on every session from then on. No dashboards to watch, no alerts to tune, nothing to maintain. Your teams won't notice it exists.

3 — Prove

When audit season, an incident, or a regulator arrives, the evidence already exists. Open the portal, export the pack, hand it over.

For the engineers evaluating: open source · pip install blackbox-fdr · bbx install · reversible, inspectable, no agent SDK required.

For developers

Connect a tool in two minutes. It records into your platform.

Black Box sits on the MCP wire between your AI agents and the tools they use. You wrap a tool's command; every call it makes is captured — observed, signed, and shipped to your own workspace. Any MCP server works.

1

Install

pip install blackbox-fdr on any machine running an AI tool. Open source, no agent SDK.

2

Wrap a tool

Point any MCP server through bbx with your workspace token. Jira, Slack, GitHub, Notion, your own.

3

It's recorded

Every call appears in your dashboard live — a verifiable sequence, attributed to the employee who ran it.

# connect Jira (or any MCP server) to your Black Box workspace
bbx --remote https://app.blackbox.io/api/ingest --token $BBX_TOKEN \
    --chain-name jira \
    wrap -- npx -y @atlassian/mcp-server-jira
your AI agent  ⟶  bbx wrap  ⟶  the tool (Jira / Slack / Notion …)
 
bbx taps the wire and ships a signed record to your platform — the agent never knows, and can't edit what was seen.
Coverage

What we capture today — and what we're building next.

We're honest about reach: Black Box records what passes through it now, and we're actively expanding to cover every way your teams reach AI. This is where we're headed — and we're moving fast.

Recording today

Any MCP server you connectJira, Slack, GitHub, Notion, Postgres, your own — wrapped through bbx, observed on the wire.
Editor & desktop agentsCursor, Claude Code, and the Claude desktop app — bbx install wires their MCP tools automatically.
Files on diskWhat actually changed, as observed ground truth — the counterpart to what an agent claims.

One log for every AI agent in your company — observed, attributed to a person, tamper-evident. We're building toward total coverage, and shipping it ring by ring. Tell us what your team uses →

The independent witness

A record you keep is your word. A record someone else witnessed is proof.

Self-kept audit trails — even cryptographically perfect ones — are still the audited party's own account. Black Box anchors a fingerprint of your records with an independent witness, on a schedule. Your data never leaves your infrastructure; the anchor proves the record existed, exactly as it is, at that moment — and was never rewritten after.

your infrastructure [ full records ] —— fingerprint only ———▶ independent anchor [ witnessed & timestamped ]

Recording before the incident — or explaining after it.

Black Box is in early access. The recorder is open source; design partners get the compliance portal, the anchor service, and the evidence pack first.

Get early access