Skip to main content

pramana-verify

Independently check that a Pramana evidence bundle has not been altered.

Pramana records what an AI agent did. Every recorded event is fingerprinted with SHA-256 and chained to the one before it, the chain is summarised into a Merkle root, and that root is signed with Ed25519. This tool checks all of that, on your machine, with no network access and no Pramana account.

It exists so that you do not have to trust Pramana, or the company whose agent produced the bundle, in order to believe the bundle.

Install

pip install pramana-verify

One dependency (cryptography). Nothing else from the Pramana platform is required or installed.

Use

pramana-verify bundle.json --pubkey <hex>

--pubkey takes either the public key as hex, or a path to a file containing it.

A passing bundle:

OK — 428 event(s), merkle_root=3f9c1a...

A bundle that has been altered:

TAMPERED / INVALID:
  - event 17 (ev-8c21): hash chain broken — prev_hash does not match event 16

Exit code is 0 when the bundle verifies and 1 when it does not, so this can be wired into an automated compliance check.

Getting the public key

Obtain the public key out of band — from Pramana directly, from your own records, or from whoever you are auditing, through a channel separate from the bundle itself.

This tool will never read a key from inside the bundle, deliberately. A bundle carrying its own verification key proves nothing: anyone who altered the contents could re-sign them with a key of their own and embed that instead.

What a passing result proves

  • Nothing in the bundle has been changed since it was signed. Not one character of a prompt, a response, a tool argument, a timestamp or an ordering. Any edit breaks the hash chain, and the tool names the event where it broke.
  • The bundle was signed by the holder of the private key matching the public key you supplied.

What it does not prove

  • That the recording was complete or honest at the moment it was made. Cryptography proves nothing has been altered since signing. It cannot prove that what was captured was everything that happened.
  • That the agent behaved correctly. This is a proof of record, not a judgement of conduct.

Those two limits are inherent to any signed audit record, and stating them is part of using one properly.

Offline by design

This tool makes no network calls of any kind. You can verify a bundle on an air-gapped machine, and you can verify a bundle years after it was produced, without Pramana existing.


More about the platform that produces these bundles: https://www.reliai.in

Release files for pramana-verify 0.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pramana-verify 0.0.1
File Size Uploaded
pramana_verify-0.0.1.tar.gz 8.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pramana-verify 0.0.1
File Interpreter ABI Platform
pramana_verify-0.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 15.4 kB

Release files / pramana_verify-0.0.1.tar.gz

Download URL pramana_verify-0.0.1.tar.gz
Size 8.2 kB
Tags Source
SHA-256 checksum
How to use checksums
08df3d74636c937c820d9fbc9397bc741a32fc35fe9f1580d055606f2b4cfde7
BLAKE2b-256 checksum
How to use checksums
222effae42dc088dd11f52bf898b8ef99ba7ff317c8a22ffaab26edecd0450c5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.8 {"installer":{"name":"uv","version":"0.11.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / pramana_verify-0.0.1-py3-none-any.whl

Download URL pramana_verify-0.0.1-py3-none-any.whl
Size 7.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
723b02ae76459132d7e292fdbba2c79282d4416ae062f514961e1c073b95fcc7
BLAKE2b-256 checksum
How to use checksums
3349f74c395ca573cf6638957c66db3c344e82c94d8f82bd4bc385914e35a838
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.8 {"installer":{"name":"uv","version":"0.11.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

0.0.3

2 release files

0.0.2

2 release files

This release

0.0.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page