Solution: Compliance evidence

Hand the auditor a signed evidence pack.

Every action your agents take enters the hash-chained ledger. KMS-rooted. Tenant-isolated. Self-audited on read. Exportable on demand for any window, any agent, any matter.

Hash-chained ledgerKMS-rooted signing keyDesigned for DCAA-aligned compliance

When my regulator, my auditor, my bar counsel, my CCO, or my board asks 'what exactly did the AI agent do, and when, and on whose behalf,' I want to produce a signed evidence pack within minutes, so that the answer isn't 'we don't know' or 'let me check the logs and get back to you next week.'

How it works

Run, filter, export.

Run

Agents run with policy + ledger by default — no extra setup. Every action is appended hash-chained to the org-scoped ledger as it happens.

Filter

Filter the ledger by window, agent, action, principal, matter — whatever scope the auditor wants.

Export

Signed evidence pack — JSON manifest plus body (CSV/TSV/JSON), asymmetric KMS signing path. Self-audited on read: the export verifies its own chain before serving.

Capabilities

The control surface auditors look for.

Hash-chained action ledger

KMS-rooted signing key. Regex-based PII redaction at ledger write time. BQ anchor for cross-validation.

Tenant isolation

Application-layer per-org Firestore sub-collections; org_id-required loaders; router-layer membership-derived org_id only.

Self-audit on read

Evidence export verifies its own chain before serving — broken-chain exports refuse to serve rather than emit silently invalid evidence.

Configurable retention

7-year regulated-industry default via the compliance profile. Profile is one-way self-serve — flipping in raises retention, pins audit version, forces PII filtering on.

Use cases

Where compliance and audit teams put us to work.

DCAA audit response

Produce evidence for any window. Designed for DCAA-aligned compliance — not DCAA-certified.

SEC Rule 204-2 recordkeeping

Assemble AI-assisted-communication records on demand. Verify suitability with your CCO and counsel.

ABA Op. 512 ethics review

Per-matter evidence with confidentiality scope. The duty is on the attorney; we provide the evidence trail.

HIPAA access-log audit

Surface PHI-touching actions. GoodHelp is not a HIPAA-covered entity; BAA availability is verified case-by-case with counsel.

Internal incident review

Replay-grade evidence for any agent action — who, when, what tool, what input, what output.

Same control infrastructure already in production.

~600+

DCAA-aligned contractors via sister brand Hour Timesheet

17

Production agents running LMNTL itself

7 years

Default retention via the Regulated Industry compliance profile

Where GoodHelp sits relative to your other tools.

CapabilityGoodHelpGeneric agent platformsVanta / DrataDIY
Hash-chained action ledgerEvidence collection, not action logDIY
Signed evidence exportDifferent scopeDIY
Tenant isolation by designVariesDIY
Runs your operations (not just your audit prep)DIY

Comparison reflects publicly documented capabilities as of 2026-05-25. Customer mileage may vary by configuration.

What audit and compliance teams ask first.

What's in an evidence pack?

JSON manifest plus body (CSV/TSV/JSON). Asymmetric KMS-signed. Verifiable offline. The manifest names every row included, and the self-audit step re-verifies the chain before serving.

Can I scope by matter / engagement / client?

Yes. Per-org Firestore sub-collections plus scoping at export time. Application-layer tenant isolation — org_id-required loaders, router-layer membership-derived org_id only.

Is SoD enforcement live today?

Yes — fail-CLOSED (SOD_REQUIRE_AUDIT_AVAILABLE=true): if the SoD audit context is unavailable the approval is blocked rather than allowed. Review the precise current state in the platform documentation before configuring agents for fund-moving systems.

What about ITAR / CUI?

Not supported today. Don't ship ITAR-controlled or CUI data through GoodHelp.

Pricing?

Per-agent + LLM passthrough. See the pricing page.

Tell us about your next audit.

Thirty minutes with a Trust Center walkthrough — bring your auditor’s checklist; we’ll walk through the controls one by one.