pramana-verify
Independently check that a Pramana evidence bundle has not been altered.
Pramana records what an AI agent did. Every recorded event is fingerprinted with SHA-256 and chained to the one before it, the chain is summarised into a Merkle root, and that root is signed with Ed25519. This tool checks all of that, on your machine, with no network access and no Pramana account.
It exists so that you do not have to trust Pramana, or the company whose agent produced the bundle, in order to believe the bundle.
Install
pip install pramana-verify
One dependency (cryptography). Nothing else from the Pramana platform is required or installed.
Use
pramana-verify bundle.json --pubkey <hex>
--pubkey takes either the public key as hex, or a path to a file containing it.
A passing bundle:
OK — 428 event(s), merkle_root=3f9c1a...
A bundle that has been altered:
TAMPERED / INVALID:
- event 17 (ev-8c21): hash chain broken — prev_hash does not match event 16
Exit code is 0 when the bundle verifies and 1 when it does not, so this can be wired into an
automated compliance check.
Getting the public key
Obtain the public key out of band — from Pramana directly, from your own records, or from whoever you are auditing, through a channel separate from the bundle itself.
This tool will never read a key from inside the bundle, deliberately. A bundle carrying its own verification key proves nothing: anyone who altered the contents could re-sign them with a key of their own and embed that instead.
What a passing result proves
- Nothing in the bundle has been changed since it was signed. Not one character of a prompt, a response, a tool argument, a timestamp or an ordering. Any edit breaks the hash chain, and the tool names the event where it broke.
- The bundle was signed by the holder of the private key matching the public key you supplied.
What it does not prove
- That the recording was complete or honest at the moment it was made. Cryptography proves nothing has been altered since signing. It cannot prove that what was captured was everything that happened.
- That the agent behaved correctly. This is a proof of record, not a judgement of conduct.
Those two limits are inherent to any signed audit record, and stating them is part of using one properly.
Offline by design
This tool makes no network calls of any kind. You can verify a bundle on an air-gapped machine, and you can verify a bundle years after it was produced, without Pramana existing.
More about the platform that produces these bundles: https://www.reliai.in
Release files for pramana-verify 0.0.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pramana_verify-0.0.3.tar.gz | 14.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pramana_verify-0.0.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 24.0 kB
Release files / pramana_verify-0.0.3.tar.gz
| Download URL | pramana_verify-0.0.3.tar.gz |
|---|---|
| Size | 14.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3c1632cd8045876b0ad513356b58f89f3fb4674ca70459f9a86d8d6017f1c1b4
|
|
BLAKE2b-256 checksum How to use checksums |
9da9db2c664e5f9abad20ef5ef7a35a4bba1990c44bcbf17f065fb63a9a0e862
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.8 {"installer":{"name":"uv","version":"0.11.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / pramana_verify-0.0.3-py3-none-any.whl
| Download URL | pramana_verify-0.0.3-py3-none-any.whl |
|---|---|
| Size | 9.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
54490b3d8e69f198569c44f7d5b83035301d17dfce1d01a3714bea5ef5a2dc0a
|
|
BLAKE2b-256 checksum How to use checksums |
90523b3dbbc29d507d5fd44003851297c75e0cc317319577c30c059c0933b41f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.8 {"installer":{"name":"uv","version":"0.11.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|