foxy-audit (SDK)
Governance-as-Code for AI. One decorator -> a tamper-evident, content-blind audit trail.
The SDK creates customer-keyed HMAC commitments for supported LLM inputs and outputs locally, throws raw text away before upload, and durably spools only metadata to the Foxy Audit backend. It also fires a best-effort local UDP ping so the desktop "fox" companion shows local capture activity and backend grading alerts.
Install
pip install -e . # from this sdk/ folder, for local development
Runtime dependency: requests only.
Use
import os
from foxy_audit import FoxyClient
foxy = FoxyClient(api_key=os.getenv("FOXY_API_KEY")) # or just rely on the env var
@foxy.audit(policy="hipaa_basic")
def ask_model(prompt: str) -> str:
return llm_client.generate(prompt) # your existing code — unchanged
Every call to ask_model is now hashed, logged, and graded. Or use the module-level decorator,
which builds a client from the environment:
from foxy_audit import audit
@audit(policy="soc2")
def summarize(text: str) -> str:
...
Attributing the model (agent)
Pass agent= to record which model produced the interaction. The backend folds it into the
tamper-evident hash chain, so the attribution can't be altered after the fact:
@foxy.audit(policy="soc2", agent="gpt-4o")
def ask_model(prompt: str) -> str:
...
agent is optional — rows logged without it hash exactly as before, so existing chains keep
verifying.
Configuration
| Setting | Kwarg | Env var | Default |
|---|---|---|---|
| API key | api_key |
FOXY_API_KEY |
(none → HTTP disabled) |
| Backend URL | endpoint |
FOXY_BACKEND_URL |
http://127.0.0.1:8000 |
| Desktop ping | desktop_ping |
— | True (127.0.0.1:9999) |
| Commitment key | commitment_key |
FOXY_COMMITMENT_KEY |
API key when omitted |
| Durable spool | spool_path |
FOXY_SPOOL_PATH |
~/.foxy-audit/spool.sqlite3 |
| Stable client id | client_id |
FOXY_CLIENT_ID |
persisted in the local spool when omitted |
| Required capture | audit_required |
FOXY_AUDIT_REQUIRED |
False |
With no API key the SDK is a graceful no-op for the cloud path: it still runs your function and
still pings the desktop fox, but skips the HTTP upload. In the default mode, delivery is best-effort;
for regulated workflows, set audit_required=True so the decorator waits for a server receipt and
raises when durable delivery cannot be confirmed.
Guarantees
- Default path is asynchronous — the HTTP upload runs on a background daemon thread after a local durable enqueue.
- Retries do not discard events — failed uploads remain in the SQLite/WAL spool.
- Content-blind by design — commitments, token counts, policy tags, and bounded identifiers leave the host; raw text is not sent by the SDK.
- Works with sync, async, and generator functions; host return values are passed through unchanged.
What gets sent
To the backend (POST /v1/logs, Authorization: Bearer <key>):
{"event_id": "<uuid>", "client_id": "...", "client_seq": 1, "commitment_alg": "hmac-sha256", "prompt_hash": "<64 hex>", "response_hash": "<64 hex>", "token_count": 123, "policy_tag": "hipaa_basic"}
To the desktop fox (UDP 127.0.0.1:9999):
{"event": "hash_ok", "policy": "hipaa_basic", "tokens": 123, "ts": 1719300000}
{"event": "policy_breach", "reason": "...", "risk_score": 87, "policy": "hipaa_basic", "ts": ...}
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file foxy_audit-1.1.1.tar.gz.
File metadata
- Download URL: foxy_audit-1.1.1.tar.gz
- Upload date:
- Size: 28.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e1f5976e88ff7fe777f26e3baf0a6d161de6c9d5362cab642b9c8a72909d73f2
|
|
| MD5 |
22df522df17f2e082af6a05ca84a12ed
|
|
| BLAKE2b-256 |
d03e382114f1ac17165703911b71eb2af7df1a63c3338610322100ab17e1a07c
|
File details
Details for the file foxy_audit-1.1.1-py3-none-any.whl.
File metadata
- Download URL: foxy_audit-1.1.1-py3-none-any.whl
- Upload date:
- Size: 25.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9f8a16a5476d6ba29d804d148a65aef07d2f5d57f1015443b93843225cdf12f2
|
|
| MD5 |
427c3a74211c52415687c95b9bd7a540
|
|
| BLAKE2b-256 |
105bdfe2e45fb89dc4cb902a4471da270ce3c7d5ddea9655dbe538612b7fdb17
|