Skip to main content

Mnestiq

A flight recorder for AI agents. Tamper-evident, signed evidence of what an agent saw, decided and did, built for incident response.

Mnestiq records every model call, tool call, approval and outbound connection an agent makes, and tags each piece of model input with its origin: the user, a web page, tool output or another agent. Records are hash-chained and sealed with signed checkpoints. When an incident occurs, investigators can identify the run, the step and the input that drove it, and demonstrate that the record has not been altered since.

Install

pip install "mnestiq[anthropic]"     # or mnestiq[openai], or plain mnestiq

Optional extras:

Extra Adds
azure Signing with keys held in Azure Key Vault or Managed HSM
timestamps RFC 3161 timestamps from public timestamp authorities, and their verification

Quick start

import anthropic
from mnestiq import FileSink, Recorder
from mnestiq.egress import instrument_egress
from mnestiq.integrations.anthropic import instrument_anthropic
from mnestiq.keys import load_private_key

recorder = Recorder(FileSink("evidence.jsonl"), agent_id="support-bot",
                    signing_key=load_private_key("keys/signing.key"))
client = instrument_anthropic(anthropic.Anthropic(), recorder)
instrument_egress()

with recorder.run():
    ...  # your agent, unchanged

recorder.close()
mnestiq keygen --out keys
mnestiq verify evidence.jsonl --trusted-key keys/signing.pub
mnestiq dashboard . --trusted-key keys/signing.pub

Production signing

A key file readable by the agent is suitable for evaluation only. In production, keep the signing key out of the agent's reach, so that a compromised agent cannot copy it or re-sign earlier evidence:

from mnestiq import AzureKeyVaultSigner, FileSink, Recorder, SignerClient, Timestamper

# Azure Key Vault: the key never leaves the vault; only a SHA-256 digest is sent.
signer = AzureKeyVaultSigner("https://<vault>.vault.azure.net/keys/<name>/<version>")

# Or a local signing service running under a separate account (`mnestiq signer serve`).
signer = SignerClient.from_env()

recorder = Recorder(FileSink("evidence.jsonl"), agent_id="support-bot", signer=signer,
                    timestamper=Timestamper(),       # independent RFC 3161 timestamps
                    checkpoint_interval=300)         # signed heartbeat when idle

Keys are rotated with a signed hand-over (recorder.rotate_signer(new_signer)), which the verifier follows. See the signing guide.

Security model

Evidence is tamper-evident after it is written: edits, deletions, reordering, re-signing with another key and backdating are detected. It cannot prove that a compromised agent told the truth at the time of writing. The threat model lists each attack considered, how it is detected, and the automated test that demonstrates it. Independent reviewers are invited to try the break-it challenge.

Licensed under Apache-2.0.

Metadata

Release files for mnestiq 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mnestiq 0.2.0
File Size Uploaded
mnestiq-0.2.0.tar.gz 102.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for mnestiq 0.2.0
File Interpreter ABI Platform
mnestiq-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 186.3 kB

Release files / mnestiq-0.2.0.tar.gz

Download URL mnestiq-0.2.0.tar.gz
Size 102.5 kB
Tags Source
SHA-256 checksum
How to use checksums
c056fea89ef669f7f38d53d189b73b9cfb47c41e6938b068cec8765269efe461
BLAKE2b-256 checksum
How to use checksums
2a21de80926fdf10fc27ae31013b5963671dd86c0abc7e7031743373d155a769
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / mnestiq-0.2.0-py3-none-any.whl

Download URL mnestiq-0.2.0-py3-none-any.whl
Size 83.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
dfe918a3d247f13ecab0a4f5fab95ddb762ba9dffdfbc9a797b6837fcb75fb8c
BLAKE2b-256 checksum
How to use checksums
8e405d51d33cf7eae6ac994b419db20f2014e0ebd230deb7887ec7d51cbe0954
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.1

2 release files

This release

0.2.0 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page