For second-line risk and audit
Loxodrome tests your controls daily against every AI‑assisted decision, with results an auditor can verify.
What we do
A loxodrome is a constant compass bearing for navigation. We tell you the day your AI veers off it.
The problem
It checks a slice of decisions and assumes the rest behave the same. AI decisions don’t.
“Point in time and sample based assurance methods [are] ill suited to probabilistic models that learn, adapt and degrade over time.”
Letter to industry on AI, 30 April 2026“I spend a lot of time with the board talking about what QA missed because of sample size… it feels pretty archaic.”
“The AI governance work is front-loaded: framework, committee, approvals. There is no mechanism to prove a control worked after deployment.”
“Line two cannot do this job by hand.”
“Point in time and sample based assurance methods [are] ill suited to probabilistic models that learn, adapt and degrade over time.”
Letter to industry on AI, 30 April 2026“I spend a lot of time with the board talking about what QA missed because of sample size… it feels pretty archaic.”
“The AI governance work is front-loaded: framework, committee, approvals. There is no mechanism to prove a control worked after deployment.”
“Line two cannot do this job by hand.”
“Point in time and sample based assurance methods [are] ill suited to probabilistic models that learn, adapt and degrade over time.”
Letter to industry on AI, 30 April 2026“I spend a lot of time with the board talking about what QA missed because of sample size… it feels pretty archaic.”
“The AI governance work is front-loaded: framework, committee, approvals. There is no mechanism to prove a control worked after deployment.”
“Line two cannot do this job by hand.”
Loxodrome’s solution
Other tools tell you what the AI did. Loxodrome tests whether your controls worked, on every decision, and raises a finding you can act on when one didn’t.
Your control library becomes a test suite, run daily against your existing AI logs. Testing confirms whether a named control operated on every decision in the period, versus monitoring which watches a model’s outputs.

Where a control isn’t operating effectively, Loxodrome raises an exception against the named first-line control. The output is a finding you can act on, with the decision record and logs attached as support.

Locate the evidence you need and show what it covers. Decision records and test results are sealed when produced and exported with a verification script, so an auditor can check them without needing to re-test.

Independent chain of custody
Every decision record and every test result is sealed when produced, outside the systems being tested. Your auditor can verify them without relying on the first line, the AI vendor, or Loxodrome.
01
What the AI actually did, written to the system of record. Inputs, model and version, tool calls, data accessed, the human review step, and the outcome. It has to be sealed at capture, because it cannot be reconstructed afterwards.
02
What was checked, against which population, on what date, using which version of the test definition. A valid test result must be tied to a specific test version and a specific set of records.
The link between them
The decision and the test are hash-chained together, so the test result is bound to the exact records it examined. Your auditor can independently confirm that neither was altered afterwards.
Security and data
Customer data, prompts and model outputs stay in your environment, under your existing retention and access controls. Loxodrome holds cryptographic commitments only.
Internal audit, external assurers and regulators can verify our evidence directly, without relying on Loxodrome or the first line.
Every decision record is hash-chained at capture. Any later alteration, deletion or reordering is detectable.
Loxodrome operates outside the decision path. An interruption to our service cannot interrupt a customer outcome.
Where to start
Thanks. We will be in touch within two business days.