Mnestiq
A flight recorder for AI agents. Tamper-evident, signed evidence of what an agent saw, decided and did, built for incident response.
Mnestiq records every model call, tool call, approval and outbound connection an agent makes, and tags each piece of model input with its origin: the user, a web page, tool output or another agent. Records are hash-chained and sealed with signed checkpoints. When an incident occurs, investigators can identify the run, the step and the input that drove it, and demonstrate that the record has not been altered since.
Install
pip install "mnestiq[anthropic]" # or mnestiq[openai], or plain mnestiq
Optional extras:
| Extra | Adds |
|---|---|
azure |
Signing with keys held in Azure Key Vault or Managed HSM |
timestamps |
RFC 3161 timestamps from public timestamp authorities, and their verification |
Quick start
import anthropic
from mnestiq import FileSink, Recorder
from mnestiq.egress import instrument_egress
from mnestiq.integrations.anthropic import instrument_anthropic
from mnestiq.keys import load_private_key
recorder = Recorder(FileSink("evidence.jsonl"), agent_id="support-bot",
signing_key=load_private_key("keys/signing.key"))
client = instrument_anthropic(anthropic.Anthropic(), recorder)
instrument_egress()
with recorder.run():
... # your agent, unchanged
recorder.close()
mnestiq keygen --out keys
mnestiq verify evidence.jsonl --trusted-key keys/signing.pub
mnestiq dashboard . --trusted-key keys/signing.pub
Production signing
A key file readable by the agent is suitable for evaluation only. In production, keep the signing key out of the agent's reach, so that a compromised agent cannot copy it or re-sign earlier evidence:
from mnestiq import AzureKeyVaultSigner, FileSink, Recorder, SignerClient, Timestamper
# Azure Key Vault: the key never leaves the vault; only a SHA-256 digest is sent.
signer = AzureKeyVaultSigner("https://<vault>.vault.azure.net/keys/<name>/<version>")
# Or a local signing service running under a separate account (`mnestiq signer serve`).
signer = SignerClient.from_env()
recorder = Recorder(FileSink("evidence.jsonl"), agent_id="support-bot", signer=signer,
timestamper=Timestamper(), # independent RFC 3161 timestamps
checkpoint_interval=300) # signed heartbeat when idle
Keys are rotated with a signed hand-over (recorder.rotate_signer(new_signer)), which the
verifier follows. See the signing guide.
Security model
Evidence is tamper-evident after it is written: edits, deletions, reordering, re-signing with another key and backdating are detected. It cannot prove that a compromised agent told the truth at the time of writing. The threat model lists each attack considered, how it is detected, and the automated test that demonstrates it. Independent reviewers are invited to try the break-it challenge.
Links
- Documentation and examples: https://github.com/mnestiq/mnestiq
- Evidence format specification: https://github.com/mnestiq/mnestiq/blob/main/spec/SPEC.md
- Changelog: https://github.com/mnestiq/mnestiq/blob/main/CHANGELOG.md
- Security policy and vulnerability reporting: https://github.com/mnestiq/mnestiq/blob/main/SECURITY.md
Licensed under Apache-2.0.
Metadata
Release files for mnestiq 0.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| mnestiq-0.2.1.tar.gz | 104.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| mnestiq-0.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 189.5 kB
Release files / mnestiq-0.2.1.tar.gz
| Download URL | mnestiq-0.2.1.tar.gz |
|---|---|
| Size | 104.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
da30e252e7c1930d7ad1317dd818e50c78fd2e13507c7603c85ea72386fcdaa3
|
|
BLAKE2b-256 checksum How to use checksums |
a9932efdf4fbadcb85662b45492d72d3112bf0d5f8c53f78130175cc23feab0f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.
Transparency logRelease files / mnestiq-0.2.1-py3-none-any.whl
| Download URL | mnestiq-0.2.1-py3-none-any.whl |
|---|---|
| Size | 84.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
754b2ce990c624a4db610b6f6e6b9d0c12a5cf0abf6f1c13f261e71797e9029e
|
|
BLAKE2b-256 checksum How to use checksums |
6827fc497940593f20e7e8c010f9ec49948f9e22c0cb7bcaa4442f8a33b0d2a1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.
Transparency log