Skip to main content

AIXV repository banner

AIXV - AI Integrity eXchange & Verification

CI Conformance CodeQL Scorecard Workflow PyPI version

AIXV is an open standard for AI artifact attestation, provenance, rollback, compromise detection, and investigation.

In practical terms, AIXV helps organizations answer high-stakes questions before deploying or accepting AI artifacts:

  • What exactly is this artifact?
  • Who produced or approved it?
  • What evidence supports trusting it?
  • Is it currently affected by an advisory or policy violation?
  • If compromised, what is the safest rollback path?

AIXV is built for three audiences that need shared, verifiable answers:

  • Technical teams: deterministic verification and machine-readable admission decisions.
  • Enterprise and public-sector risk owners: auditable evidence, policy controls, and incident traceability.
  • Policy, governance, and assurance functions: explicit trust assumptions, conformance checks, and compatibility contracts.

AIXV composes Sigstore cryptographic primitives and adds AI-native semantics:

  • Artifact typing,
  • Lineage graphs,
  • ML-specific attestations,
  • Advisory/recall workflows,
  • Policy-driven verification.

Release Posture

Current maturity: Pre-Alpha

This repository is a functional preview of the AIXV standard, but not yet a final ratified standard release.

Stable enough for pilot evaluation

  • Core primitives and schemas:
    • SignedRecord (aixv.signed-record/v1)
    • VerifyPolicy (aixv.policy/v1)
    • AdmissionDecision
  • Fail-closed verification and policy semantics.
  • Deterministic JSON output mode (--json) with tested contract behavior.
  • CI quality gates (ruff, mypy, pytest, build).

Still evolving

  • Broader conformance vector coverage and certification workflow.
  • Formal governance and external audit signals.
  • Wider ecosystem integrations and migration tooling.

Adoption Signals

For security and procurement reviews, the strongest immediate signals are:

  • aixv conformance --json produces a machine-readable conformance report.
  • docs/THREAT_MODEL.md, SECURITY.md, and docs/COMPATIBILITY.md define trust, reporting, and compatibility expectations.
  • CI enforces lint, typing, tests, build, and dedicated conformance workflow checks.
  • Scorecard and CodeQL workflows provide continuous security posture visibility in GitHub Security.

Standards and Security Docs

  • docs/AIXV_STANDARD.md
  • docs/NORMATIVE_CORE.md
  • docs/QUALITY.md
  • docs/THREAT_MODEL.md
  • docs/COMPATIBILITY.md
  • docs/TERMINOLOGY.md
  • docs/REGISTRIES.md
  • docs/ASSURANCE_LEVELS.md
  • docs/CONFORMANCE.md
  • docs/GOVERNANCE.md
  • docs/REPO_CONTROLS.md
  • SECURITY.md
  • RELEASE.md

Installation

pip install aixv

Quickstart (Core Flow)

# 1) Sign an artifact
aixv sign model.safetensors --identity-token-env SIGSTORE_ID_TOKEN

# 2) Create and sign a policy record
aixv policy create --input policy.json --sign

# 3) Verify artifact with signed policy + trusted policy signer
aixv verify model.safetensors \
  --policy .aixv/policies/policy.json \
  --policy-trusted-subject security-policy@aixv.org \
  --assurance-level level-2 \
  --json

# 4) Run conformance checks
aixv conformance --json

# 5) Optional: enforce signed-and-trusted attestations in lineage/export flows
aixv provenance model.safetensors \
  --require-signed-attestations \
  --trusted-attestation-subject ci-attestations@aixv.org \
  --json

CLI Surface

# Version
aixv version

# Signing
aixv sign model.safetensors --identity-token-env SIGSTORE_ID_TOKEN

# Verification
aixv verify model.safetensors --identity alice@example.com --issuer https://accounts.google.com

# Attestation
aixv attest model.safetensors --predicate training --input training.json

# Provenance
aixv provenance model.safetensors --depth 3
aixv provenance model.safetensors --view explain --depth 3 --json

# Advisory
aixv advisory create --advisory-id ADV-2026-0001 --severity critical --input advisory.json --sign
aixv advisory verify .aixv/advisories/ADV-2026-0001.json --trusted-subject security@aixv.org
aixv advisory sync --feed advisory-feed.json --trusted-subject security@aixv.org --max-bundle-age-days 30

# Policy
aixv policy create --input policy.json --sign
aixv policy verify .aixv/policies/policy.json --trusted-subject security-policy@aixv.org
aixv policy template --assurance-level level-2 --json
aixv policy migrate --input policy.json --to-assurance-level level-3 --max-bundle-age-days 30

# Record
aixv record create --kind waiver --record-id WVR-2026-01 --input waiver.json --sign
aixv record verify .aixv/policies/policy.json --kind policy --trusted-subject security-policy@aixv.org

# Bundle
aixv bundle create --input bundle.json --sign
aixv bundle verify .aixv/records/bundle/bundle-main.json --trusted-subject release@aixv.org

# Conformance
aixv conformance --json

# Rollback
aixv rollback model-v2.safetensors --to sha256:... --identity-token-env SIGSTORE_ID_TOKEN

# Export
aixv export model.safetensors --format in-toto
aixv export model.safetensors --format slsa --json
aixv export model.safetensors --format ml-bom --json

Policy Example

{
  "policy_type": "aixv.policy/v1",
  "allow_subjects": ["alice@example.com"],
  "allow_issuers": ["https://accounts.google.com"],
  "advisory_allow_subjects": ["security@aixv.org"],
  "max_bundle_age_days": 30,
  "deny_advisory_severity_at_or_above": "high",
  "require_no_active_advisories": false,
  "require_signed_advisories": true
}

Development

git clone https://github.com/aixv-org/aixv.git
cd aixv
python3 -m venv .venv
. .venv/bin/activate
pip install -e '.[dev]'

Quality Gates

ruff check .
ruff format --check .
mypy src
pytest
python -m build

Metadata

Release files for aixv 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aixv 0.2.1
File Size Uploaded
aixv-0.2.1.tar.gz 48.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aixv 0.2.1
File Interpreter ABI Platform
aixv-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 79.5 kB

Release files / aixv-0.2.1.tar.gz

Download URL aixv-0.2.1.tar.gz
Size 48.8 kB
Tags Source
SHA-256 checksum
How to use checksums
67ee59e27f8daef464671327aa9bfdffa8d4104c8b46d43d2c856b7f84091492
BLAKE2b-256 checksum
How to use checksums
6a0f12129a6b7c579b2c095dd419f282f5a1b276cd8de8b5bca50935292c1da1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 17, 2026.

Transparency log

Release files / aixv-0.2.1-py3-none-any.whl

Download URL aixv-0.2.1-py3-none-any.whl
Size 30.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c689c8c59e990064d720e6f159ea7deb12626934256587a959b2f91b4fa29789
BLAKE2b-256 checksum
How to use checksums
0193a9ed31ab398c67d0dd68fc57663bedb509d30b89103ce5bd3938b7136e79
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 17, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.1 This release

2 release files

0.2.0

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page