csoai-evidence-fabric
Apache-2.0 code. The csoai.evidence-event/0.1 schema and its field mappings are CC0-1.0.
One evidence event says what a public surface declared, what was observed, which state that leaves, and the limits of the read. It is evidence, not a verdict. This package renders the same event into the carriers security and observability tools already read, and verifies a signed batch offline.
pip install csoai-evidence-fabric # Python >= 3.9; add [validate] for jsonschema checks
csoai-evidence validate EVENTS.jsonl
csoai-evidence render ocsf EVENTS.jsonl > findings.ocsf.jsonl # OCSF 1.9.0 Detection Finding (class 2004)
csoai-evidence render otel EVENTS.jsonl > evaluation.otlp.json # OTel event gen_ai.evaluation.result
csoai-evidence render sarif EVENTS.jsonl > evidence.sarif # SARIF 2.1.0
csoai-evidence render intoto EVENTS.jsonl > statements.jsonl # in-toto Statement v1
csoai-evidence render ecs-hec EVENTS.jsonl > hec.ndjson # ECS document in HEC NDJSON
csoai-evidence render w3c-acr01 EVENTS.jsonl > report.json # W3C Agent Conformance Reporting v0.1 (Community Group text)
csoai-evidence ingest sarif REPORT.sarif --read-at <UTC> > events.jsonl # third-party SARIF as the declared side
csoai-evidence ingest garak REPORT.jsonl ... # garak report recount (garak holds the method)
csoai-evidence verify batch.json batch.signed.json events.jsonl --did did.json --tamper-control
did.json is a saved copy of https://csoai.org/.well-known/did.json. Pin it; do not fetch it at verification time.
States, never grades
stateis one of CONSISTENT, DIVERGENT, PARTIAL, UNMEASURED, UNCHECKABLE, NOT_DISCRIMINATING. There is no pass state and no score.- UNMEASURED and UNCHECKABLE never carry a number. Every renderer refuses an event that breaks this.
- A CONSISTENT event must carry a negative control that was actually run.
event_id=sha256:+ sha256 of the RFC 8785 (JCS) bytes of the event withoutevent_id,signatureandanchors. A correction is a new event whosesupersedesnames the old id.
Carrier choices
- OCSF: Detection Finding (2004), never Compliance Finding (2003);
severity_idis always 1 (Informational). A measured value goes underunmapped, neverconfidence_scoreorrisk_score. - OTel:
gen_ai.evaluation.score.valueis absent unless a number was measured. - SARIF:
kindcarries the state (pass / fail / open / review / notApplicable);levelisnoneunlesskindisfail. - ECS:
event.categoryisconfiguration; UNMEASURED maps toevent.outcome: unknown;event.risk_scoreis never emitted. - in-toto: predicate type
https://councilof.ai/spec/evidence-event/v0.1; the DSSE envelope is emitted unsigned (the batch signature covers the events).
What a VALID verification shows
verify checks the Ed25519 signature of did:web:csoai.org#board-attestation-1 over the batch record and the sha256 of the events file, and with --tamper-control it also proves that three one-byte edits are rejected. VALID shows who signed these bytes. It does not show that any claim inside is true.
Not measured. Live ingestion into a SIEM, collector or tenant was not run. Each carrier output is checked only against that carrier's published schema or registry, pinned in vendor/.
Install notes and the other connectors: https://councilof.ai/connect/
Metadata
Release files for csoai-evidence-fabric 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| csoai_evidence_fabric-0.1.0.tar.gz | 81.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| csoai_evidence_fabric-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 174.1 kB
Release files / csoai_evidence_fabric-0.1.0.tar.gz
| Download URL | csoai_evidence_fabric-0.1.0.tar.gz |
|---|---|
| Size | 81.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
eb4774850266a8602945fc9fd7209ab0121bbca6b23ff26e4b8c4f14e700320b
|
|
BLAKE2b-256 checksum How to use checksums |
24ba6b0758f3a2976f7e67f86ae3cca4bd5213f2bbaa6f6a09745fe9b860b964
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.10
|
Release files / csoai_evidence_fabric-0.1.0-py3-none-any.whl
| Download URL | csoai_evidence_fabric-0.1.0-py3-none-any.whl |
|---|---|
| Size | 92.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2ce998fce818a126497f908ce61939eaad8cabc20668eac49b16a171a3641d5f
|
|
BLAKE2b-256 checksum How to use checksums |
8074551817d47fcfbf26fc65a866176ef75d64fdcba28f52b281595aa1f17b6a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.10
|