Skip to main content

pramana-verify

Independently check that a Pramana evidence bundle has not been altered.

Pramana records what an AI agent did. Every recorded event is fingerprinted with SHA-256 and chained to the one before it, the chain is summarised into a Merkle root, and that root is signed with Ed25519. This tool checks all of that, on your machine, with no network access and no Pramana account.

It exists so that you do not have to trust Pramana, or the company whose agent produced the bundle, in order to believe the bundle.

Install

pip install pramana-verify

One dependency (cryptography). Nothing else from the Pramana platform is required or installed.

Use

pramana-verify bundle.json --pubkey <hex>

--pubkey takes either the public key as hex, or a path to a file containing it.

A passing bundle:

OK — 428 event(s), merkle_root=3f9c1a...

A bundle that has been altered:

TAMPERED / INVALID:
  - event 17 (ev-8c21): hash chain broken — prev_hash does not match event 16

Exit code is 0 when the bundle verifies and 1 when it does not, so this can be wired into an automated compliance check.

Getting the public key

Obtain the public key out of band — from Pramana directly, from your own records, or from whoever you are auditing, through a channel separate from the bundle itself.

This tool will never read a key from inside the bundle, deliberately. A bundle carrying its own verification key proves nothing: anyone who altered the contents could re-sign them with a key of their own and embed that instead.

What a passing result proves

  • Nothing in the bundle has been changed since it was signed. Not one character of a prompt, a response, a tool argument, a timestamp or an ordering. Any edit breaks the hash chain, and the tool names the event where it broke.
  • The bundle was signed by the holder of the private key matching the public key you supplied.

What it does not prove

  • That the recording was complete or honest at the moment it was made. Cryptography proves nothing has been altered since signing. It cannot prove that what was captured was everything that happened.
  • That the agent behaved correctly. This is a proof of record, not a judgement of conduct.

Those two limits are inherent to any signed audit record, and stating them is part of using one properly.

Offline by design

This tool makes no network calls of any kind. You can verify a bundle on an air-gapped machine, and you can verify a bundle years after it was produced, without Pramana existing.


More about the platform that produces these bundles: https://www.reliai.in

Release files for pramana-verify 0.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pramana-verify 0.0.2
File Size Uploaded
pramana_verify-0.0.2.tar.gz 11.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pramana-verify 0.0.2
File Interpreter ABI Platform
pramana_verify-0.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 20.9 kB

Release files / pramana_verify-0.0.2.tar.gz

Download URL pramana_verify-0.0.2.tar.gz
Size 11.7 kB
Tags Source
SHA-256 checksum
How to use checksums
6b9a662809af5fce11a0ce13b3475aa9861b86019cbc4f4d641b27a2d7111b03
BLAKE2b-256 checksum
How to use checksums
bbba02a20c0af8557d7d789182fbc5a5a9a5b57183ed822f124c32061313446b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.8 {"installer":{"name":"uv","version":"0.11.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / pramana_verify-0.0.2-py3-none-any.whl

Download URL pramana_verify-0.0.2-py3-none-any.whl
Size 9.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
19491a917da09eb94a47b1411073e3b78461f67afdee2e917dde7feafbfbef9d
BLAKE2b-256 checksum
How to use checksums
971c00ac4f8285b415f9cb6da83c2290cc617a5d01323774517c86492ae89d13
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.8 {"installer":{"name":"uv","version":"0.11.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

0.0.3

2 release files

This release

0.0.2 This release

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page