Skip to main content

GOVP — Sign once. Verify anywhere.

Open protocol stewarded by Gemacode.

GOVP is an open protocol for making files and digital artifacts independently verifiable without an account, a central API or a proprietary verifier.

A publisher places a small Ed25519-signed GOVP record next to a document, dataset, model or build artifact. A recipient can then verify the record and the exact artifact bytes locally with any conforming implementation.

Documentation · GOVP-1 specification · Browser verifier · Conformance vectors · Security

Sign a portable GOVP record, distribute it beside an artifact, then verify both locally.

Why GOVP exists

Digital artifacts leave the systems that created them. They are downloaded, mirrored, emailed, archived and consumed by software that cannot safely depend on the original publisher remaining online.

  • A checksum detects changed bytes, but does not carry a signature.
  • A raw signature does not define a shared record format, canonical signing input, identifier or interoperability test suite.
  • A hosted verification API works only while its service, account and trust boundary remain available.

GOVP standardizes that missing layer: a readable signed record, deterministic verification rules, content-derived identifiers, JSON Schema and byte-exact conformance vectors. GOVP is a protocol and testable contract, not a hosted trust service.

A GOVP record is readable text

This complete record is a synthetic fixture from the examples/ directory:

# GOVP public verification record
# Synthetic fixture: reserved example domain, no production or customer data
# Verify locally with the bundled manufacturing-record.statement.txt asset
Version: GOVP-1
Canonical: https://manufacturer.example/.well-known/govp.txt
Publisher: Example Manufacturing Organization
Asset-Type: document
Asset-ID: SAMPLE-LOT-0001
Asset-SHA256: 2e6870bced11f1ddf51a5ce5514244b9e670c553560915b6c13ea6b49263a2d0
Profile: industrial-manufacturing
Generated-At: 2026-08-04T12:00:00Z
GOVP-ID: GOVP-DOC-cb352d4b8a77
Evidence: https://manufacturer.example/evidence/sample-manufacturing-record.txt
Public-Key: IXxXtLEM5a0OxZqhFTv3Z6yR/zV/pZ2yFx2VGGyr34g=
Signature: YM9VhQ7d/Wihmn8z4sA8WxT7Gz9pejxAU5DdnG51cnJVwxEhDkPhH5nZzXudPzja/nfGqoTrstDpxSy6k1kqDw==

Comments are unsigned. GOVP signs the normalized field lines, including unknown extension fields, so implementations cannot silently reinterpret or discard signed data.

Verify it in 60 seconds

Python 3.10 or newer is required for the reference implementation.

python -m pip install govp==0.1.10
govp self-test
govp conformance --run

Extract and verify the signed synthetic fixtures included in the installed package:

govp examples --extract govp-examples
govp verify govp-examples/manufacturing-record.govp.txt \
  --asset govp-examples/manufacturing-record.statement.txt

Expected result:

GOVP verification: VALID
  format       pass
  signature    pass
  govp-id      pass
  canonical    not checked
  asset        pass
  record       GOVP-DOC-cb352d4b8a77

Verification is local. Neither the record nor the artifact is uploaded to GOVP. canonical is not checked in this example because the record was loaded from disk rather than fetched from its signed HTTPS location.

Break the artifact, break the binding

The repository also includes a synthetic copy with one changed line. It uses the same signed GOVP record, so the record signature still passes, but the modified artifact bytes no longer match the signed SHA-256 digest.

The original synthetic artifact passes GOVP verification while a one-line modification fails the asset SHA-256 check.

govp verify govp-examples/manufacturing-record.govp.txt \
  --asset govp-examples/manufacturing-record.tampered.statement.txt

Expected rejection:

GOVP verification: INVALID
  format       pass
  signature    pass
  govp-id      pass
  canonical    not checked
  asset        FAIL
  record       GOVP-DOC-cb352d4b8a77

This failure does not mean the signed record was forged. It means the supplied artifact is not the exact artifact described by that record. The command exits with status 1, making the same check usable in local workflows and CI.

For machine-readable output, add --json. Exit code 0 means verification succeeded, 1 means the record was evaluated and is not valid, and 2 means the command or input could not be processed.

Integrate the verifier

from pathlib import Path

from govp import load_record, verify

record = load_record(Path("record.govp.txt"))
asset = Path("artifact.bin").read_bytes()
result = verify(record, asset_bytes=asset)

if not result.ok:
    raise ValueError(result.checks)

print(result.derived_govp_id)

The Python package is a reference implementation, not a network service. Applications remain responsible for authorization, download limits, persistence, display escaping and their own trust policy. See the integration guide for the complete result contract.

Evaluate the protocol's live key and revocation status separately:

govp status-url https://govp.io/.well-known/govp.txt \
  --status-url https://govp.io/.well-known/govp/revoked.json

Offline integrity remains available when the status service is unavailable; only a current same-origin HTTPS fetch can produce currently_trusted=true. See GOVP-STATUS-1.

What GOVP proves — and what it does not

A valid result establishes A valid result does not establish
The GOVP record has a valid signature from its included public key The legal identity or authority behind that key
The GOVP-ID matches the declared artifact identity That a signed statement is factually true
Supplied artifact bytes match the signed SHA-256 digest Independent existence time or timestamp anchoring
A remotely fetched record ended at its signed canonical HTTPS URL Current authorization unless GOVP-STATUS-1 is also evaluated

GOVP deliberately separates cryptographic verification from identity, certification and business-policy decisions. Deployments can add PKI, registries, transparency logs, witnesses or timestamp authorities where those properties are required.

Where GOVP fits

GOVP is intentionally narrower than several established technologies:

  • W3C Verifiable Credentials model claims issued about subjects and their presentation between issuers, holders and verifiers.
  • C2PA Content Credentials capture rich provenance and history for digital content through manifests, assertions and content bindings.
  • Sigstore secures software supply chains with identity-bound signing, short-lived certificates and transparency logs.
  • GOVP binds a small, portable signed record to exact artifact bytes with deterministic, service-independent verification.

They solve different trust problems and can be complementary. Read the composition guide for the layered verification model and links to each upstream specification.

Use cases

Artifact Example
Document Bind a published declaration, policy or report to its exact bytes
Dataset Identify the frozen snapshot used for analysis or evaluation
Model Attach a portable signed record to model artifacts or model cards
Build output Verify a release after download, mirroring or archival
Benchmark Bind a declared result to the exact published result set
Operational record Carry a signed declaration outside its originating system

Use GOVP when recipients need a durable answer to: “Does this artifact match the signed record I received?” Add other systems when they must also answer: “Who is legally responsible?”, “When was this independently witnessed?” or “Is this claim acceptable under my policy?”.

Implementations

The wire protocol is language-neutral. Conformance is determined by the normative text and published vectors, not by matching Python internals.

Language/runtime Project Status
Python 3.10+ govp Reference verifier · 0.1.10
JavaScript · Node 20+ and browsers @govp/verifier Independent verifier · 0.1.0
Browser demo govp.io Interactive GOVP-1 verification
Go Start an implementation Wanted
Rust Start an implementation Wanted
Other Read the conformance guide Welcome

An implementation should consume the byte-exact vectors, report every core check and stop on specification ambiguity rather than choosing undocumented behavior.

Stability and provenance

GOVP-1 is frozen. Low protocol churn is a compatibility guarantee by design. Changes to signing inputs or wire behavior require explicit versioning, new conformance vectors and migration analysis.

The current reference verifier is 0.1.10. Download the v0.1.10 immutable release or verify its GitHub release attestation:

gh release verify v0.1.10 --repo govp-protocol/govp

The public provenance manifest records that commit, its Git tree, the reviewed source-archive hash and the exact hashes of every normative artifact. Documentation-only commits on main do not redefine the GOVP-1 wire format.

Repository map

  • spec/ — normative and concise protocol text
  • schema/ — machine-readable record and bundle schema
  • conformance/ — byte-exact text and JSON vectors
  • extensions/ — independently versioned protocol extensions such as status
  • audits/ — hash-bound external review evidence with explicit limitations
  • src/govp/ — Python reference verifier and CLI
  • examples/ — valid signed records with fully synthetic content
  • tests/ — protocol, transport and CLI regression tests
  • docs/ — adoption, integration, security and release guidance
  • brand/ — canonical editable GOVP visual identity and usage rules
  • tools/ — repository integrity checks for non-normative publication assets

Contribute

GOVP especially welcomes independent implementations, conformance reports, synthetic vectors, integration guides and ambiguity reports found while implementing the specification.

Contributing guide · Report a specification ambiguity · Propose an implementation · Governance · Support

License, scope and stewardship

The specification, conformance material, software and repository documentation are licensed under Apache License 2.0. Copyright is held by Brilyetz Holding S.L.; Gemacode is its brand. The visual identity files in brand/ are separately governed by their usage rules. Apache-2.0 does not grant rights to the GOVP or Gemacode names or marks—see the trademark policy. Earlier license grants are recorded separately in LICENSE-HISTORY.md.

The repository is protocol-only. Issuing products, control panels, customer systems, private keys and commercial extensions are excluded by SCOPE.md and are not required for GOVP-1 conformance.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

govp-0.1.10.tar.gz (65.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

govp-0.1.10-py3-none-any.whl (51.6 kB view details)

Uploaded Python 3

File details

Details for the file govp-0.1.10.tar.gz.

File metadata

  • Download URL: govp-0.1.10.tar.gz
  • Upload date:
  • Size: 65.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for govp-0.1.10.tar.gz
Algorithm Hash digest
SHA256 bc8ef492b124a2af7b7007162b8eca44d8ce83c31a0ee3a135c30a7a391dbf28
MD5 864012d51bc83a4f5839397208087097
BLAKE2b-256 b4a5941f07de1f55a5150b3600f145d8b876fc732ab8d8c2f7bb3752f675eead

See more details on using hashes here.

Provenance

The following attestation bundles were made for govp-0.1.10.tar.gz:

Publisher: publish-pypi.yml on govp-protocol/govp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file govp-0.1.10-py3-none-any.whl.

File metadata

  • Download URL: govp-0.1.10-py3-none-any.whl
  • Upload date:
  • Size: 51.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for govp-0.1.10-py3-none-any.whl
Algorithm Hash digest
SHA256 36616709856be3c857d525077dd66d4c20497928f75a2a1624a50ce76c94884f
MD5 6f09dc0c7988a0d7e45546cbbfc69c8e
BLAKE2b-256 f59e7d2d1a52084775a8f4c28dfc462817d9a4ab6e172cea6881d492d372842d

See more details on using hashes here.

Provenance

The following attestation bundles were made for govp-0.1.10-py3-none-any.whl:

Publisher: publish-pypi.yml on govp-protocol/govp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.1.13

2 files

0.1.12

2 files

0.1.11

2 files

This release

0.1.10 This release

2 files

0.1.9

2 files

0.1.8

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page