Skip to main content

Actseal

Decision contracts you can replay.

If your application uses a model to choose an action, a confidence score alone does not tell you when that action is justified. Actseal freezes your policy, checks its errors and coverage on labelled cases, exercises provider failures, and saves evidence that you can replay without the model.

Try the packaged demo

With uv installed, run this on macOS or Linux. It selects Python 3.12 and installs the GitHub release wheel in uv's tool environment; no source checkout, model or API key is needed.

uvx --python 3.12 --from https://github.com/ajaysurya1221/actseal/releases/download/v0.1.0/actseal-0.1.0-py3-none-any.whl actseal demo --out ./actseal-demo

Choose an output directory that does not already exist. Its parent must exist; Actseal refuses to overwrite an existing destination. Use a different directory name for another demo run.

The demo evaluates the same policy against two authored sets of answers. The independently tested wheel produced bad: BLOCK, fixed: PASS, with both freshly replayed. The overall demo exits 0 only when those conditions hold. Here “fixed” names the fixture whose authored answers match the labels; no model was trained or repaired.

actseal-demo/
  inputs/          # copied contracts, labelled cases and recorded answers
  bad/lock.json
  bad/evidence/    # deliberately wrong authored answers
  fixed/lock.json
  fixed/evidence/  # authored answers that match the labels
Authored demo Verdict Accepted actions Wrong actions
Bad answers BLOCK 128 / 128 32 / 128
Matching-label answers PASS 128 / 128 0 / 128

The installed demo took 0.17 seconds on the reference Mac after environment preparation. Both bundles replayed correctly, and all eight Linux/macOS CI jobs produced identical evidence. The quickstart records exact bounds and measurement scope. First-time uv/Python/wheel downloads are separate; this is a synthetic fixture measurement, not an inference benchmark.

Replay an individual bundle in a separate command:

uvx --python 3.12 --from https://github.com/ajaysurya1221/actseal/releases/download/v0.1.0/actseal-0.1.0-py3-none-any.whl actseal replay ./actseal-demo/fixed/evidence

Replay reconstructs the policy decisions and verdict from recorded data; it does not call a provider. Replaying bad/evidence should return BLOCK and exit 1, even when replay correctly reproduces the result. See the detailed quickstart for JSON output, individual lock/verify commands and checking an externally obtained lock digest.

Read the result

An ACT is a decision permitted by the frozen allowlist and selected-label probability threshold. Coverage is ACT decisions divided by all scheduled cases. Risk is wrong ACT decisions divided by ACT decisions. Actseal reports bounds around those rates; a high score or zero observed errors alone is not PASS.

Exit Verdict Meaning
0 PASS The valid evidence satisfies the frozen risk/coverage limits and fault checks.
1 BLOCK Valid evidence establishes a limit violation or a deterministic fault-check failure.
2 INCONCLUSIVE Valid evidence cannot establish either PASS or BLOCK.
3 ERROR Inputs/evidence are invalid or incomplete, setup/usage fails, or the native worker experiment is invalidated.

lock also returns 0 on success. demo returns 0 for its expected BLOCK/PASS pair plus matching replays; it does not turn the bad run into PASS. Append --json to a command for structured output. Failures and warnings are surfaced.

Use your own policy

v0.1.0 supports one categorical question with 2–16 labels, a frozen action allowlist and threshold, recorded fixtures, and an optional pinned native Laya CPU adapter. Start with the quickstart, statistical contract and provider setup and limitations. The core and replay require no model package or hosted service. Jev is deferred, not a v0.1.0 dependency.

The native Laya CLI check at candidate 434c682 also preserved an honest result: all 128 synthetic cases ABSTAINed at the fixed threshold, with no provider failures. Verification and replay both returned BLOCK for insufficient coverage; no accepted cases means risk remains unestimated, [0,1]. The policy was not tuned or retried to obtain PASS. Provider details record the environment, warnings and bounds; this is an integration check, not a population or model-quality benchmark.

The demonstration is synthetic, marked evidence_scope=demo, and establishes no population or model-quality result. For real data, the statistical interpretation requires independent cases and one prespecified attempt under a fixed policy and operating regime. Actseal does not enforce another application's behavior.

Hashes and replay check consistency. Even a trusted lock digest cannot authenticate rewritten responses under that lock, prove inference occurred or prove the labels true. Read the threat model before using evidence to authorize actions.

Apache-2.0; see LICENSE, NOTICE and dependency notices. Contributions: CONTRIBUTING. Changes: CHANGELOG.

Metadata

Release files for actseal 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for actseal 0.1.0
File Size Uploaded
actseal-0.1.0.tar.gz 505.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for actseal 0.1.0
File Interpreter ABI Platform
actseal-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 590.3 kB

Release files / actseal-0.1.0.tar.gz

Download URL actseal-0.1.0.tar.gz
Size 505.7 kB
Tags Source
SHA-256 checksum
How to use checksums
1781149ff09a21f14691daf0f6777f29022ec01293463394ac4f569f6897be2a
BLAKE2b-256 checksum
How to use checksums
fd2206ff053f88f30ab6d2bd052e1c4907b1c8df4473f0d9f8b2afb606db5911
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release files / actseal-0.1.0-py3-none-any.whl

Download URL actseal-0.1.0-py3-none-any.whl
Size 84.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
672b60815394cf9673c6a9f78437750ffc40d44467627604f48c5e1c5f77e906
BLAKE2b-256 checksum
How to use checksums
4242c3790bc35cd52157934d39ec2fccce111017c8935e6e3fc472bdb6642f2a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release history Release notifications | RSS feed

1.0.0

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page