Skip to main content

foxy-audit (SDK)

Governance-as-Code for AI. One decorator -> a tamper-evident, content-blind audit trail.

The SDK creates customer-keyed HMAC commitments for supported LLM inputs and outputs locally, throws raw text away before upload, and durably spools only metadata to the Foxy Audit backend. It also fires a best-effort local UDP ping so the desktop "fox" companion shows local capture activity and backend grading alerts.

Install

pip install -e .            # from this sdk/ folder, for local development

Runtime dependency: requests only.

Use

import os
from foxy_audit import FoxyClient

foxy = FoxyClient(api_key=os.getenv("FOXY_API_KEY"))   # or just rely on the env var

@foxy.audit(policy="hipaa_basic")
def ask_model(prompt: str) -> str:
    return llm_client.generate(prompt)     # your existing code — unchanged

Every call to ask_model is now hashed, logged, and graded. Or use the module-level decorator, which builds a client from the environment:

from foxy_audit import audit

@audit(policy="soc2")
def summarize(text: str) -> str:
    ...

Attributing the model (agent)

Pass agent= to record which model produced the interaction. The backend folds it into the tamper-evident hash chain, so the attribution can't be altered after the fact:

@foxy.audit(policy="soc2", agent="gpt-4o")
def ask_model(prompt: str) -> str:
    ...

agent is optional — rows logged without it hash exactly as before, so existing chains keep verifying.

Configuration

Setting Kwarg Env var Default
API key api_key FOXY_API_KEY (none → HTTP disabled)
Backend URL endpoint FOXY_BACKEND_URL http://127.0.0.1:8000
Desktop ping desktop_ping True (127.0.0.1:9999)
Commitment key commitment_key FOXY_COMMITMENT_KEY API key when omitted
Durable spool spool_path FOXY_SPOOL_PATH ~/.foxy-audit/spool.sqlite3
Stable client id client_id FOXY_CLIENT_ID persisted in the local spool when omitted
Required capture audit_required FOXY_AUDIT_REQUIRED False

With no API key the SDK is a graceful no-op for the cloud path: it still runs your function and still pings the desktop fox, but skips the HTTP upload. In the default mode, delivery is best-effort; for regulated workflows, set audit_required=True so the decorator waits for a server receipt and raises when durable delivery cannot be confirmed.

Guarantees

  • Default path is asynchronous — the HTTP upload runs on a background daemon thread after a local durable enqueue.
  • Retries do not discard events — failed uploads remain in the SQLite/WAL spool.
  • Content-blind by design — commitments, token counts, policy tags, and bounded identifiers leave the host; raw text is not sent by the SDK.
  • Works with sync, async, and generator functions; host return values are passed through unchanged.

What gets sent

To the backend (POST /v1/logs, Authorization: Bearer <key>):

{"event_id": "<uuid>", "client_id": "...", "client_seq": 1, "commitment_alg": "hmac-sha256", "prompt_hash": "<64 hex>", "response_hash": "<64 hex>", "token_count": 123, "policy_tag": "hipaa_basic"}

To the desktop fox (UDP 127.0.0.1:9999):

{"event": "hash_ok", "policy": "hipaa_basic", "tokens": 123, "ts": 1719300000}
{"event": "policy_breach", "reason": "...", "risk_score": 87, "policy": "hipaa_basic", "ts": ...}

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

foxy_audit-1.2.0.tar.gz (28.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

foxy_audit-1.2.0-py3-none-any.whl (25.4 kB view details)

Uploaded Python 3

File details

Details for the file foxy_audit-1.2.0.tar.gz.

File metadata

  • Download URL: foxy_audit-1.2.0.tar.gz
  • Upload date:
  • Size: 28.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for foxy_audit-1.2.0.tar.gz
Algorithm Hash digest
SHA256 57303f748d6dfa86b32ae621017bbcc957489debd64a84a76b66e3fe21583e2d
MD5 04add023825a410e291fd88d3119b7a0
BLAKE2b-256 89e072b08299dfc321356f355e8a15ea2f7b71f02f9e1d36c8f3bc479a6ac15e

See more details on using hashes here.

File details

Details for the file foxy_audit-1.2.0-py3-none-any.whl.

File metadata

  • Download URL: foxy_audit-1.2.0-py3-none-any.whl
  • Upload date:
  • Size: 25.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for foxy_audit-1.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 1ec97a447dbfa0d66d2ace7441590212a2a755d3880d041f34a2420c0a4ba2a4
MD5 28ab8d41e52d169ffc9abbe2f5b6a4a5
BLAKE2b-256 aa1ab5f176903e8ed54a3d744cb2313ef80c8258fe065898e57464bd58ffbbce

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page