Skip to main content

Mnestiq

A flight recorder for AI agents. Tamper-evident, signed evidence of what an agent saw, decided and did, built for incident response.

Mnestiq records every model call, tool call, approval and outbound connection an agent makes, and tags each piece of model input with its origin: the user, a web page, tool output or another agent. Records are hash-chained and sealed with signed checkpoints. When an incident occurs, investigators can identify the run, the step and the input that drove it, and demonstrate that the record has not been altered since.

Install

pip install "mnestiq[anthropic]"     # or mnestiq[openai], or plain mnestiq

Optional extras:

Extra Adds
azure Signing with keys held in Azure Key Vault or Managed HSM
timestamps RFC 3161 timestamps from public timestamp authorities, and their verification

Quick start

import anthropic
from mnestiq import FileSink, Recorder
from mnestiq.egress import instrument_egress
from mnestiq.integrations.anthropic import instrument_anthropic
from mnestiq.keys import load_private_key

recorder = Recorder(FileSink("evidence.jsonl"), agent_id="support-bot",
                    signing_key=load_private_key("keys/signing.key"))
client = instrument_anthropic(anthropic.Anthropic(), recorder)
instrument_egress()

with recorder.run():
    ...  # your agent, unchanged

recorder.close()
mnestiq keygen --out keys
mnestiq verify evidence.jsonl --trusted-key keys/signing.pub
mnestiq dashboard . --trusted-key keys/signing.pub

Production signing

A key file readable by the agent is suitable for evaluation only. In production, keep the signing key out of the agent's reach, so that a compromised agent cannot copy it or re-sign earlier evidence:

from mnestiq import AzureKeyVaultSigner, FileSink, Recorder, SignerClient, Timestamper

# Azure Key Vault: the key never leaves the vault; only a SHA-256 digest is sent.
signer = AzureKeyVaultSigner("https://<vault>.vault.azure.net/keys/<name>/<version>")

# Or a local signing service running under a separate account (`mnestiq signer serve`).
signer = SignerClient.from_env()

recorder = Recorder(FileSink("evidence.jsonl"), agent_id="support-bot", signer=signer,
                    timestamper=Timestamper(),       # independent RFC 3161 timestamps
                    checkpoint_interval=300)         # signed heartbeat when idle

Keys are rotated with a signed hand-over (recorder.rotate_signer(new_signer)), which the verifier follows. See the signing guide.

Security model

Evidence is tamper-evident after it is written: edits, deletions, reordering, re-signing with another key and backdating are detected. It cannot prove that a compromised agent told the truth at the time of writing. The threat model lists each attack considered, how it is detected, and the automated test that demonstrates it. Independent reviewers are invited to try the break-it challenge.

Licensed under Apache-2.0.

Metadata

Release files for mnestiq 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mnestiq 0.2.1
File Size Uploaded
mnestiq-0.2.1.tar.gz 104.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for mnestiq 0.2.1
File Interpreter ABI Platform
mnestiq-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 189.5 kB

Release files / mnestiq-0.2.1.tar.gz

Download URL mnestiq-0.2.1.tar.gz
Size 104.7 kB
Tags Source
SHA-256 checksum
How to use checksums
da30e252e7c1930d7ad1317dd818e50c78fd2e13507c7603c85ea72386fcdaa3
BLAKE2b-256 checksum
How to use checksums
a9932efdf4fbadcb85662b45492d72d3112bf0d5f8c53f78130175cc23feab0f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release files / mnestiq-0.2.1-py3-none-any.whl

Download URL mnestiq-0.2.1-py3-none-any.whl
Size 84.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
754b2ce990c624a4db610b6f6e6b9d0c12a5cf0abf6f1c13f261e71797e9029e
BLAKE2b-256 checksum
How to use checksums
6827fc497940593f20e7e8c010f9ec49948f9e22c0cb7bcaa4442f8a33b0d2a1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.1 This release

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page