A clear route to an answer.
Get to know Cairn, work through a question, or tell us what needs to be better.
Ask a question
Product guidance, pilot setup or a workflow you want to understand.
Contact the team 02Report a bug
Tell us what happened, what you expected and how to reproduce it.
Prepare a bug report 03Improve the experience
Share a confusing step, missing feature or idea that would help your team.
Share feedbackThese routes prepare an email to the Cairn team. You review and send it from your email app.
The questions that matter.
A practical introduction to Cairn and its first pilots.
Browse the customer guides Read the assurance notesWhat does Cairn actually do?
Cairn sits between an AI agent and its connected tools. It evaluates tool calls against policy, allows or denies them, or holds them for a human decision. It records those decisions in a hash-chained ledger.
Can we use Cairn today?
Cairn has a working prototype and synthetic evaluation evidence. We are preparing the managed product for pilots. The first step is to agree a focused workflow, the tools it can use, the people who approve actions and the evidence you need. Discuss a pilot.
What is the difference between allow, hold and deny?
Allow lets a request continue within policy. Hold pauses it for a human decision. Deny blocks it. An approval is part of the record, so the decision can be traced afterwards.
Who will administer our workspace?
The managed product is being built with customer owners and administrators who manage their own team. Operators, approvers and auditors will have distinct permissions. The roles and access boundaries must be verified before your pilot starts.
Do the demos use real customer data?
No. The examples on this website are illustrative and use synthetic agents, organisations and transactions. Clicking a demonstration control does not move money or operate a customer's systems.
What does tamper-evident mean?
Each ledger entry includes a hash linked to the entry before it. Verification detects inconsistent changes to the retained chain. Detecting a complete rewrite also requires a trusted checkpoint held separately. The assurance page explains the limits.
Can we keep and verify our evidence?
The prototype ledger uses JSON Lines and includes an Apache-licensed verifier. Pilot requirements include evidence export and recovery, so a product interface is not the only way to read your record. Access and retention are agreed as part of setup.
What should I include in a bug report?
Include the page or workflow, time of the issue, browser or integration version, steps to reproduce, expected result and actual result. A redacted screenshot or error reference helps. Keep API keys, passwords and customer records out of an initial email. Prepare a bug report.
Where should I report a security concern?
Contact the team privately with a brief description and a way to reach you. We will arrange an appropriate channel for sensitive technical details.
No matching questions yet. Ask the team directly.
Start with one workflow worth controlling.
Bring the scenario. We will work through the tools, the policy and the evidence with you.