Run
Agents run with policy + ledger by default — no extra setup. Every action is appended hash-chained to the org-scoped ledger as it happens.
Solution: Compliance evidence
Every action your agents take enters the hash-chained ledger. KMS-rooted. Tenant-isolated. Self-audited on read. Exportable on demand for any window, any agent, any matter.
When my regulator, my auditor, my bar counsel, my CCO, or my board asks 'what exactly did the AI agent do, and when, and on whose behalf,' I want to produce a signed evidence pack within minutes, so that the answer isn't 'we don't know' or 'let me check the logs and get back to you next week.'
How it works
Agents run with policy + ledger by default — no extra setup. Every action is appended hash-chained to the org-scoped ledger as it happens.
Filter the ledger by window, agent, action, principal, matter — whatever scope the auditor wants.
Signed evidence pack — JSON manifest plus body (CSV/TSV/JSON), asymmetric KMS signing path. Self-audited on read: the export verifies its own chain before serving.
Capabilities
KMS-rooted signing key. Regex-based PII redaction at ledger write time. BQ anchor for cross-validation.
Application-layer per-org Firestore sub-collections; org_id-required loaders; router-layer membership-derived org_id only.
Evidence export verifies its own chain before serving — broken-chain exports refuse to serve rather than emit silently invalid evidence.
7-year regulated-industry default via the compliance profile. Profile is one-way self-serve — flipping in raises retention, pins audit version, forces PII filtering on.
Use cases
Produce evidence for any window. Designed for DCAA-aligned compliance — not DCAA-certified.
Assemble AI-assisted-communication records on demand. Verify suitability with your CCO and counsel.
Per-matter evidence with confidentiality scope. The duty is on the attorney; we provide the evidence trail.
Surface PHI-touching actions. GoodHelp is not a HIPAA-covered entity; BAA availability is verified case-by-case with counsel.
Replay-grade evidence for any agent action — who, when, what tool, what input, what output.
DCAA-aligned contractors via sister brand Hour Timesheet
Production agents running LMNTL itself
Default retention via the Regulated Industry compliance profile
| Capability | GoodHelp | Generic agent platforms | Vanta / Drata | DIY |
|---|---|---|---|---|
| Hash-chained action ledger | ✅ | ❌ | Evidence collection, not action log | DIY |
| Signed evidence export | ✅ | ❌ | Different scope | DIY |
| Tenant isolation by design | ✅ | Varies | ✅ | DIY |
| Runs your operations (not just your audit prep) | ✅ | ✅ | ❌ | DIY |
Comparison reflects publicly documented capabilities as of 2026-05-25. Customer mileage may vary by configuration.
JSON manifest plus body (CSV/TSV/JSON). Asymmetric KMS-signed. Verifiable offline. The manifest names every row included, and the self-audit step re-verifies the chain before serving.
Yes. Per-org Firestore sub-collections plus scoping at export time. Application-layer tenant isolation — org_id-required loaders, router-layer membership-derived org_id only.
Yes — fail-CLOSED (SOD_REQUIRE_AUDIT_AVAILABLE=true): if the SoD audit context is unavailable the approval is blocked rather than allowed. Review the precise current state in the platform documentation before configuring agents for fund-moving systems.
Not supported today. Don't ship ITAR-controlled or CUI data through GoodHelp.
Per-agent + LLM passthrough. See the pricing page.
Thirty minutes with a Trust Center walkthrough — bring your auditor’s checklist; we’ll walk through the controls one by one.