Skip to main content

TRACE v0.1 — hardware-attested governance records for AI agents

Project description

TRACE

TRACE: Trust Runtime Attestation and Compliance Evidence

Full Documentation

Specification  |  Schema  |  Examples  |  Registry  |  Test Suite  |  Reference Impl

License: CC BY 4.0 Spec PyPI CI Discord

Developer Preview. Launching at Confidential Computing Summit, June 23 2026.

An open specification for hardware-attested AI agent governance records. TRACE defines the format, anchoring protocol, and verification rules for cryptographically provable evidence that an AI agent ran under a specific policy, in a verified hardware environment, on classified data, invoking identified tools — bound into a single signed artifact rooted in silicon attestation.

A TRACE Trust Record answers: what ran, where, under which policy, touching which data, calling which tools — in a form any third party can verify without trusting the operator.

Quick start

pip install agentrust-trace
from agentrust_trace import TrustRecord, sign_record

record = TrustRecord(
    subject="spiffe://trust.example.org/agent/payments-processor",
    model_id="claude-sonnet-4-6",
    platform="amd-sev-snp",
    policy_hash="sha256:b2c3d4...",
)
signed = sign_record(record, key=signing_key)

Resources

📖 Full documentation trace.agentrust-io.com
📄 Specification spec/trace-v0.1.md
🔍 Schema schema/trace-claim.json
📦 PyPI agentrust-trace
🧪 Test suite trace-tests
🗂 Registry trace-registry
🔗 Reference implementation cmcp
💬 Discussions GitHub Discussions
📋 Changelog CHANGELOG.md

Standards alignment

Targeting the Agentic AI Foundation (AAIF) at the Linux Foundation. Active standardization track in CoSAI WS4. Builds on RFC 9711 (EAT), RFC 9334 (RATS), and SCITT draft-22.

Contributing

See CONTRIBUTING.md and GOVERNANCE.md. All contributors must agree to the ANTITRUST.md policy.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agentrust_trace-0.3.0.tar.gz (87.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

agentrust_trace-0.3.0-py3-none-any.whl (17.1 kB view details)

Uploaded Python 3

File details

Details for the file agentrust_trace-0.3.0.tar.gz.

File metadata

  • Download URL: agentrust_trace-0.3.0.tar.gz
  • Upload date:
  • Size: 87.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for agentrust_trace-0.3.0.tar.gz
Algorithm Hash digest
SHA256 3ad491dace4a64c4708833b12d70e15a7448942bd64e20e535361faa5a170ac9
MD5 1e91e73508fc1fdc1184e24866457e2d
BLAKE2b-256 767049165503ae191c8a3305a36545c22a24c9873fff0e5a78c9b9f0a04a6f40

See more details on using hashes here.

Provenance

The following attestation bundles were made for agentrust_trace-0.3.0.tar.gz:

Publisher: publish.yml on agentrust-io/trace-spec

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file agentrust_trace-0.3.0-py3-none-any.whl.

File metadata

  • Download URL: agentrust_trace-0.3.0-py3-none-any.whl
  • Upload date:
  • Size: 17.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for agentrust_trace-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 beb6febf861514db6ff1624c258e026321990ec438f7d2b0a9ab711f419cd50f
MD5 ec426e982bba9959d82165c03e2be94c
BLAKE2b-256 14cee57617c1a552a86d7b310fecd97d9ba3fa1f3a0785e5c4ddc9b49da70381

See more details on using hashes here.

Provenance

The following attestation bundles were made for agentrust_trace-0.3.0-py3-none-any.whl:

Publisher: publish.yml on agentrust-io/trace-spec

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page