Governance,
built for proof.
howldr ProofWorks turns the governance work you already do — policies, approvals, staff acknowledgements, evidence, and risk decisions — into proof you can hand an auditor. Its modules share one evidence spine: every action is attributed, timestamped, and receipted, so the audit trail is a by-product of doing the work, not a scramble after it. The code is open source under the MIT license: run it yourself, or let howldr host it for you.
Can you prove it?
Most organizations run governance on shared drives, email chains, and spreadsheets. It works — right up until an insurer, auditor, or incident response asks for proof: who approved this version, who acknowledged it, who accepted that risk, and when. Reconstructing that after the fact is painful, and often impossible. ProofWorks makes the proof a by-product of the workflow, not a scramble at the end.
one evidence spine.
Modules are enabled per workspace — start with what you need, add as your obligations grow. AI governance is handled here rather than as a separate product: acceptable-use policies and data-handling rules live in Policy Hub, the regulations driving them sit in Obligations, and control over what your agents may actually do is leaps and bounds. More modules are on the roadmap.
start to finish.
Every policy follows the same auditable path, with each transition logged and each authorizer sign-off captured as a non-repudiable receipt.
by design.
LiquidFiles.
ProofWorks is built on top of LiquidFiles — the same secure messaging platform behind howldr's Secure File Transfer service. Authenticated read receipts, per-recipient download tracking, and non-repudiation logging come from LiquidFiles, which means the audit trail lives on your own infrastructure, under your control, retained for as long as your regulatory framework requires.
ProofWorks needs a LiquidFiles appliance. LiquidFiles is a commercial product with its own license, and howldr is an authorized reseller. About LiquidFiles →
Three ways to run it.
The ProofWorks code is published under the MIT license. Read it, change it, run it, host it.
Hosted. howldr runs the software for you: your branding and your policies on howldr's infrastructure.
Self-hosted, with software support. Run it in your own VMware, AWS, or Azure environment with full branding (your logo, your domain). Your IT team or provider deploys and operates it. howldr supports the software itself: releases, fixes, and product questions.
Self-hosted, on your own. Clone the repository and run it. github.com/howldr/proofworks →
The license covers the code, not the names. You're welcome to fork it, but call your fork something other than howldr or ProofWorks.
your environment.
The code is public and free to run. Early access to the hosted service and to software support is opening one organization at a time. Reach out and we'll talk through how ProofWorks would be configured for yours.