Skip to main content

arcaeon-audit

Tamper-evident, audit-ready logs for AI agents. Observability shows you what your agent did. This lets you prove it wasn't altered — the evidence your ISO 42001 / SOC 2 auditor (and, by 2027, the EU AI Act) asks for.

pip install arcaeon-audit

Why this exists

If you ship an AI agent into anything regulated or enterprise-sold, you're already being asked to keep records of what it did and produce them on demand — by your SOC 2 auditor, by ISO/IEC 42001 (Annex A.6.2.8: keep AI event logs across the lifecycle), and by the security/AI-governance questionnaires your enterprise customers send today. The EU AI Act, Article 12 adds a hard tamper-evident-logging mandate for high-risk systems from 2 December 2027 (Digital Omnibus, Reg. (EU) 2026/1744; penalties to €35M or 7% of revenue).

Almost all of that forces you to keep records. Almost none of it is satisfied by a plain log file — anyone with write access can edit, delete, or reorder a past record and nothing shows. What auditors and regulators want is an append-only, integrity-protected record you can hand over and have independently verified. That integrity layer — the provable part — is exactly what this gives you.

A normal log file doesn't meet the bar: anyone with write access can edit, delete, or reorder a past record and nothing shows. The regulators' expectation is an append-only, integrity-protected record — in practice, a hash chain.

arcaeon-audit is the small, boring, correct layer that gives you exactly that, in two lines and a folder. It wraps arcaeon-ledger (a hash-chained append-only log, zero heavy deps) with the event vocabulary and the regulator-ready export that Article 12 asks for.

Use

from arcaeon_audit import AuditLog

log = AuditLog("agent-audit.jsonl", system_id="triage-agent-v3", provider="Acme AI")

log.record(event="system_start", agent="triage-agent-v3")
log.record(event="input",  agent="triage-agent-v3", inputs={"patient_msg": "chest pain"})
log.record(event="decision", agent="triage-agent-v3", decision="escalate",
           outputs={"routed_to": "ER", "priority": 1}, capability_version="v2")

log.verify().ok            # True — any edit to history would make this False
log.export_bundle("audit-export/")   # regulator-ready folder

export_bundle() writes a self-verifying folder:

file what it is
records.jsonl the full hash-chained audit log, verbatim
integrity.json verification result — ok?, row count, exact first break if any
manifest.json system id, provider, period covered, counts by event type
ARTICLE_12_SUMMARY.md human-readable mapping to Article 12's requirements

The bundle is self-verifying: records.jsonl is hash-chained, so anyone can re-run arcaeon-ledger's verify_file() and reproduce integrity.json. Tamper evidence does not depend on trusting this tool or its author — that's the point.

CLI

arcaeon-audit verify  agent-audit.jsonl
arcaeon-audit export  agent-audit.jsonl audit-export/ --system-id triage-v3 --provider "Acme AI"

What this is and isn't

Is: an engineering control that produces automatic, tamper-evident, exportable records — the integrity + export primitive Article 12 leans on.

Isn't: legal advice, and not compliance-in-a-box on its own. Article 12 compliance also depends on what you choose to log and your broader obligations under the Act. This tool gives you the hard part (provable integrity + a clean export); the coverage is yours to define.

How it works

Every record is hash-chained: chain = sha256(prev_chain + canonical(row)). Edit, delete, or reorder any record and every later link breaks; verify() names the exact row. Records also carry an authority block (principal + capability version) so "was this edited?" sharpens to "was this edited and was the writer authorized?"

MIT licensed. Built by Arcaeon — the evidence layer for AI.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

arcaeon_audit-0.1.2.tar.gz (8.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

arcaeon_audit-0.1.2-py3-none-any.whl (9.2 kB view details)

Uploaded Python 3

File details

Details for the file arcaeon_audit-0.1.2.tar.gz.

File metadata

  • Download URL: arcaeon_audit-0.1.2.tar.gz
  • Upload date:
  • Size: 8.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.3

File hashes

Hashes for arcaeon_audit-0.1.2.tar.gz
Algorithm Hash digest
SHA256 fd0cf82e61a69de638c9a43a75f700b54f7205d03a11dda8914c14a75efa8860
MD5 cdfed05a4dd5a46f4e658f4695f40929
BLAKE2b-256 c4545212d34689c606e7469f7b7710432fa1bbe3e7e8aba4abb9f4eef311fd15

See more details on using hashes here.

File details

Details for the file arcaeon_audit-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: arcaeon_audit-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 9.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.3

File hashes

Hashes for arcaeon_audit-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 17483c870f43881ac93fc9e0bca787e08933f33bd3de30904333892e54398447
MD5 53a68b343eab7cb2011891821a9d2ed2
BLAKE2b-256 624c86569a8836cdd67020d5a9b13d6cbb9d8f582ac8d36e97773151ffc64593

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page