howldr wolf watermark
Open source · MIT
Platform → howldr ProofWorks

Governance,
built for proof.

howldr ProofWorks turns the governance work you already do — policies, approvals, staff acknowledgements, evidence, and risk decisions — into proof you can hand an auditor. Its modules share one evidence spine: every action is attributed, timestamped, and receipted, so the audit trail is a by-product of doing the work, not a scramble after it. The code is open source under the MIT license: run it yourself, or let howldr host it for you.

You do the work.
Can you prove it?

Most organizations run governance on shared drives, email chains, and spreadsheets. It works — right up until an insurer, auditor, or incident response asks for proof: who approved this version, who acknowledged it, who accepted that risk, and when. Reconstructing that after the fact is painful, and often impossible. ProofWorks makes the proof a by-product of the workflow, not a scramble at the end.

Six modules,
one evidence spine.
// module 01
Policy Hub
The full policy lifecycle — draft, authorize, distribute, collect staff acceptance, and review on schedule. Every sign-off and acknowledgement is a non-repudiable, authenticated receipt.
// module 02
Evidence Locker
A register of evidence items — attributed, timestamped, hash-pinned. Verify any document by digest, and export a self-verifying evidence pack an auditor can check offline.
// module 03
Risk Register
5×5 risk assessments — inherent and residual, append-only. Acceptance is a named, attributed receipt pinned to the assessment it covered: re-assess, and it visibly needs re-acceptance.
// module 04
Access Reviews
Who has access to what, reviewed on a cycle and signed off by a named reviewer. Each decision — keep, revoke, or flag — lands as an attributed receipt instead of a spreadsheet nobody kept.
// module 05
Vendor Register
The third parties you depend on, tiered by how much damage they could do. Approvals and declines are both receipted — a rejected vendor is evidence too, and the one auditors ask about.
// module 06
Obligations
The layer underneath the rest: the contracts, regulations and frameworks you are actually bound by, linked to the controls that answer them. An obligation with nothing linked to it is the loudest thing on the screen.

Modules are enabled per workspace — start with what you need, add as your obligations grow. AI governance is handled here rather than as a separate product: acceptable-use policies and data-handling rules live in Policy Hub, the regulations driving them sit in Obligations, and control over what your agents may actually do is leaps and bounds. More modules are on the roadmap.

One workflow,
start to finish.

Every policy follows the same auditable path, with each transition logged and each authorizer sign-off captured as a non-repudiable receipt.

01
Initiation
A policy is created and assigned a permanent serialized identifier — POL-YYYY-NNN.
02
Drafting
Owners and contributors draft in a restricted workspace; every saved revision is versioned.
03
Authorization
Approvers sign off via authenticated secure message — recording who, when, and from where.
04
Distribution
The authorized version is published and sent to every member of staff it applies to.
05
Acceptance
Staff acknowledge receipt; reminders chase the outstanding, escalations flag the overdue.
06
Active
The policy is live. The register tracks its version, owner, and next review date.
07
Review
On schedule, the cycle reopens automatically — advance notice, then escalation if overdue.
↻
Repeat
Each cycle promotes the version and extends the next review date. Nothing falls through.
Audit-ready
by design.
Non-repudiation
Authorizations and acknowledgements use authenticated LiquidFiles secure messages — recording identity, timestamp, and IP per recipient. The evidentiary record lives on your own infrastructure.
Serialized & versioned
Permanent POL-YYYY-NNN identifiers and semantic versioning. You always know which edition is live, which is in draft, and what changed between them.
Live registers
A single view of every policy, evidence item, and risk — status, version, owner, and next review date — with a full changelog behind each one.
Role-based gates
Owners, contributors, authorizers, and staff each see and do only what their role permits. Sign-off identity comes from authentication, never a form field.
Automated reminders
Configurable reminder cadence for outstanding acceptances, with overdue escalation to line managers — so chasing acknowledgements isn't your job.
Scheduled review
A daily scheduler fires advance-notice warnings, reopens review cycles on time, and escalates anything that slips past its date.
Powered by
LiquidFiles.

ProofWorks is built on top of LiquidFiles — the same secure messaging platform behind howldr's Secure File Transfer service. Authenticated read receipts, per-recipient download tracking, and non-repudiation logging come from LiquidFiles, which means the audit trail lives on your own infrastructure, under your control, retained for as long as your regulatory framework requires.

ProofWorks needs a LiquidFiles appliance. LiquidFiles is a commercial product with its own license, and howldr is an authorized reseller. About LiquidFiles →

Free to run.
Three ways to run it.

The ProofWorks code is published under the MIT license. Read it, change it, run it, host it.

Hosted. howldr runs the software for you: your branding and your policies on howldr's infrastructure.
Self-hosted, with software support. Run it in your own VMware, AWS, or Azure environment with full branding (your logo, your domain). Your IT team or provider deploys and operates it. howldr supports the software itself: releases, fixes, and product questions.
Self-hosted, on your own. Clone the repository and run it. github.com/howldr/proofworks →

The license covers the code, not the names. You're welcome to fork it, but call your fork something other than howldr or ProofWorks.

Configured for
your environment.

The code is public and free to run. Early access to the hosted service and to software support is opening one organization at a time. Reach out and we'll talk through how ProofWorks would be configured for yours.

No spam, no commitment — just a conversation about your setup.