Skip to main content

csoai-evidence-fabric

Apache-2.0 code. The csoai.evidence-event/0.1 schema and its field mappings are CC0-1.0.

One evidence event says what a public surface declared, what was observed, which state that leaves, and the limits of the read. It is evidence, not a verdict. This package renders the same event into the carriers security and observability tools already read, and verifies a signed batch offline.

pip install csoai-evidence-fabric            # Python >= 3.9; add [validate] for jsonschema checks

csoai-evidence validate EVENTS.jsonl
csoai-evidence render ocsf      EVENTS.jsonl > findings.ocsf.jsonl   # OCSF 1.9.0 Detection Finding (class 2004)
csoai-evidence render otel      EVENTS.jsonl > evaluation.otlp.json  # OTel event gen_ai.evaluation.result
csoai-evidence render sarif     EVENTS.jsonl > evidence.sarif        # SARIF 2.1.0
csoai-evidence render intoto    EVENTS.jsonl > statements.jsonl      # in-toto Statement v1
csoai-evidence render ecs-hec   EVENTS.jsonl > hec.ndjson            # ECS document in HEC NDJSON
csoai-evidence render w3c-acr01 EVENTS.jsonl > report.json           # W3C Agent Conformance Reporting v0.1 (Community Group text)
csoai-evidence ingest sarif REPORT.sarif --read-at <UTC> > events.jsonl   # third-party SARIF as the declared side
csoai-evidence ingest garak REPORT.jsonl ...                              # garak report recount (garak holds the method)
csoai-evidence verify batch.json batch.signed.json events.jsonl --did did.json --tamper-control

did.json is a saved copy of https://csoai.org/.well-known/did.json. Pin it; do not fetch it at verification time.

States, never grades

  • state is one of CONSISTENT, DIVERGENT, PARTIAL, UNMEASURED, UNCHECKABLE, NOT_DISCRIMINATING. There is no pass state and no score.
  • UNMEASURED and UNCHECKABLE never carry a number. Every renderer refuses an event that breaks this.
  • A CONSISTENT event must carry a negative control that was actually run.
  • event_id = sha256: + sha256 of the RFC 8785 (JCS) bytes of the event without event_id, signature and anchors. A correction is a new event whose supersedes names the old id.

Carrier choices

  • OCSF: Detection Finding (2004), never Compliance Finding (2003); severity_id is always 1 (Informational). A measured value goes under unmapped, never confidence_score or risk_score.
  • OTel: gen_ai.evaluation.score.value is absent unless a number was measured.
  • SARIF: kind carries the state (pass / fail / open / review / notApplicable); level is none unless kind is fail.
  • ECS: event.category is configuration; UNMEASURED maps to event.outcome: unknown; event.risk_score is never emitted.
  • in-toto: predicate type https://councilof.ai/spec/evidence-event/v0.1; the DSSE envelope is emitted unsigned (the batch signature covers the events).

What a VALID verification shows

verify checks the Ed25519 signature of did:web:csoai.org#board-attestation-1 over the batch record and the sha256 of the events file, and with --tamper-control it also proves that three one-byte edits are rejected. VALID shows who signed these bytes. It does not show that any claim inside is true.

Not measured. Live ingestion into a SIEM, collector or tenant was not run. Each carrier output is checked only against that carrier's published schema or registry, pinned in vendor/.

Install notes and the other connectors: https://councilof.ai/connect/

Metadata

Release files for csoai-evidence-fabric 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for csoai-evidence-fabric 0.1.0
File Size Uploaded
csoai_evidence_fabric-0.1.0.tar.gz 81.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for csoai-evidence-fabric 0.1.0
File Interpreter ABI Platform
csoai_evidence_fabric-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 174.1 kB

Release files / csoai_evidence_fabric-0.1.0.tar.gz

Download URL csoai_evidence_fabric-0.1.0.tar.gz
Size 81.5 kB
Tags Source
SHA-256 checksum
How to use checksums
eb4774850266a8602945fc9fd7209ab0121bbca6b23ff26e4b8c4f14e700320b
BLAKE2b-256 checksum
How to use checksums
24ba6b0758f3a2976f7e67f86ae3cca4bd5213f2bbaa6f6a09745fe9b860b964
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.10

Release files / csoai_evidence_fabric-0.1.0-py3-none-any.whl

Download URL csoai_evidence_fabric-0.1.0-py3-none-any.whl
Size 92.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2ce998fce818a126497f908ce61939eaad8cabc20668eac49b16a171a3641d5f
BLAKE2b-256 checksum
How to use checksums
8074551817d47fcfbf26fc65a866176ef75d64fdcba28f52b281595aa1f17b6a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.10

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page