proofbundle
Portable evidence for AI work, verifiable offline. Integrity, not truth
One file. No verification server. No network required.
Quick start · What it proves · Current release · Adoption review · Documentation
Current release
v6.2.0 · Beta · Closing audit record named in the release notes
Known limitations · Release notes · Release scope
What was checked, and what remains open
6.2.0 closes five findings in the released 6.0.0 and 6.1.0 at the verify boundary, and one class of eight more: a related map that says it is empty no longer hides a retraction, an edge's declaredAt takes ASCII digits only as the Rust verifier does, a low-order Ed25519 key is refused both as a trusted key and as the holder key of a key binding, a caller's resolver promotes a verdict only on the exact True, and a public verify surface reads each argument of its caller once, by what it stores, so the caller's own methods no longer decide a verdict.
It closes six more findings in four classes, five of them in the released 6.0.0 and 6.1.0: every evaluator applies the rule of load_policy, so a policy field of another type is refused instead of read as no constraint; no value a check judges is read after caller code could change it, the anchors, the relying party's trust material and the answers of a resolver included; a restricting warn of a registered anchor verifier marks the anchor pending; and a container of the wrong type is refused instead of read as empty. The sixth, the warn reading, is a regression of this release cycle and not in the released versions.
A later gate round found two more, both in the released 6.0.0 and 6.1.0: an attached target's subject state is read against the four words its resolver writes, so a state it never writes no longer binds a declared subject pin to the first subject of an ambiguous target; and a restricting command-line option given an empty value, such as --policy '', is refused or applied instead of being read as absent. The gate round at d388ed3d found two more, also in the released 6.0.0 and 6.1.0: the decision and outcome verifiers read a caller's related map once, so a callback of the caller can no longer hide an attached retraction between two readings, and every public function now reads all of its arguments in one reading at its call, before its body reads any of them; and decision verify --anchors refuses a file holding null or an empty list instead of reading it as no option, as the receipt verify commands refuse a policy with nothing in it they evaluate.
The gate round at fda55f98 found one more in the released 6.0.0 and 6.1.0, and closed what that reading still handed on. Every rule a policy sets is now applied by the command it is given to, or the policy is refused; outcome verify printed POLICY: OK over an attached, verified retraction under a rule it never applies. No object of the caller reaches the body of a public function except where an argument's contract names it: an iterator or a generator is refused (pass a list or a tuple), a memoryview no private copy can take is refused, and a value of the caller's own class reaches the body as a stand-in that holds nothing of the caller. The reading does not yet prove a joint state of mutable inputs: a change made and undone between its two reads is not seen, as RESTRISIKO_620.md names. The release notes name the affected versions, the effect and the upgrade.
The closing round runs at a later head than the one this file describes, so this file cannot state its result. In the tagged tree its verdict is the gate line of audit_artifacts/360/fuzz_soak_latest.json and audit_artifacts/360/rust_differential_matrix.json, and the pre-tag receipt audit_artifacts/620/pre_tag_receipt_v6.2.0.json records its own audit command and result; the release notes name the same places.
The package being published and its closing audit passing are separate facts. An audit that was not run makes no statement about the absence of defects.
Quick start
Install the verifier, download an example, then verify the local file.
python -m pip install proofbundle==6.2.0
curl -fsSLo receipt.json \
https://raw.githubusercontent.com/b7n0de/proofbundle/v6.2.0/examples/example_bundle.json
proofbundle verify receipt.json
Python 3.10 or newer. Installation and download use the network. Verification reads the local file only.
Exit codes and the tamper demo
These exit codes apply to proofbundle verify, not to every command in the package.
| Exit code | Meaning |
|---|---|
0 |
Verified |
1 |
Verification failed |
2 |
Malformed input or usage error |
3 |
Relying party policy not met |
decision verify, outcome verify and relation-statement verify have separate contracts in their own --help.
To try deliberate tampering, install the evaluation extra and run the demo.
python -m pip install 'proofbundle[eval]==6.2.0'
proofbundle demo
The demo checks an honest receipt, tampered variants and a sample swap. It exits with a nonzero code if a tamper is accepted.
What a receipt proves
| What verification can establish | What it does not establish |
|---|---|
| Which key signed the content | Whether you should trust that key |
| Whether signed content has changed | Whether the reported result is true |
| Whether supplied proofs and requested policy checks pass | Whether the work was correct or complete |
A valid signature does not make a reported result true. Checks depend on the receipt format and the policy you request.
Choose your task
| I want to | Start here |
|---|---|
| Verify a receipt | Quick start |
| Create evaluation evidence | Evaluation walkthrough |
| Add receipts to Inspect AI | Inspect integration |
| Assess proofbundle for adoption | Adversarial review guide |
Other workflows and optional features
| Workflow | Package or reference |
|---|---|
| Evaluation receipts and preregistration | proofbundle[eval] · Claim format |
| Inspect AI | proofbundle[inspect] · Integration guide |
| Agent review disclosures | Profile inventory · Conformance examples |
| RFC 3161 and OpenTimestamps | proofbundle[anchors] · Anchor guide |
| ML-DSA-44 witness cosignatures | proofbundle[pq] · Anchor guide |
| TEE attestation bridge | proofbundle[experimental] · Experimental bridge |
Shipped features do not all have the same maturity. Agent review disclosures are self declarations. Anchor and enclave paths have experimental boundaries. Check the predicate inventory for the exact profile before relying on it.
Documentation
| Your question | Reference |
|---|---|
| How do I implement the format? | Specification · Conformance |
| How do I integrate my workflow? | Integrations · Glossary |
| Which keys and claims should I accept? | Policies · Trust anchors |
| How is security assessed? | Threat model · Security policy |
| How was this release prepared? | Release process · Pre tag audit |
How it works
Your evaluation, review, decision or action
↓
Canonical statement, signature and supplied proofs
↓
One portable receipt file
↓
Offline verification and explicit policy checks
The verifier checks the evidence it receives. Expected subjects, trusted keys, freshness requirements and acceptance policies come from the relying party. Missing evidence is not evidence that omitted work never happened.
Capabilities and maturity
The core supports signed receipts and Merkle inclusion proofs. Evaluation receipts can bind metrics, thresholds, provenance and commitments. Selective disclosure can hide selected values while preserving the checks supported by its profile.
Decision receipts record a verdict over named evidence. That does not establish that the decision was correct. Outcome, relation, run ledger, trust pack and verification summary profiles have their own maturity limits.
The Rust cross verifier is experimental and advisory. Agreement on recorded cases does not prove either implementation correct, and the Rust tool is not part of the Python package.
Security and trust
The core uses cryptography and rfc8785, rather than implementing its own cryptographic primitives. The test approach includes external vectors, mutation checks and parser fuzzing. Those are test signals, not a proof of correctness.
Receipt signatures are Ed25519, not post quantum. ML-DSA-44 witness cosignatures and the experimental renewal path do not turn the payload signature into a post quantum signature. See the anchor documentation.
Build provenance and package attestations answer questions about the build and its bytes. They do not establish the truth of an evaluation or replace a security audit. See the release process.
Report a vulnerability · Conformance · Adoption review
The OpenSSF Scorecard is a heuristic, not a product verdict. Read the per check explanations and self assessment.
Standards and interoperability
proofbundle complements other evidence systems. A format mapping or an open proposal is not the same as adoption by the upstream project.
Tool comparison · Receipt envelope profile · in-toto mapping · SCITT mapping · Related work
The interop discussion with inspect-receipts records a specific envelope comparison. It must not be read as evidence of a second independent implementation of every predicate.
Scope, citation and contributing
proofbundle is not a hosted transparency service, a complete in-toto client, a trusted execution environment, a consensus system or a compliance product by itself.
Release scope records what belongs to this release. Deferred work is not a delivered capability.
Use CITATION.cff for citation metadata. The software archive has concept DOI 10.5281/zenodo.21110642. The Technical Note has concept DOI 10.5281/zenodo.21230466. Software and Technical Note versions are separate records.
Contributing guide · Code of Conduct · Good first issues · Security reports
MIT license · Part of b7n0de, Verified AI Work
Metadata
Release files for proofbundle 6.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| proofbundle-6.2.0.tar.gz | 3.9 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| proofbundle-6.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 4.8 MB
Release files / proofbundle-6.2.0.tar.gz
| Download URL | proofbundle-6.2.0.tar.gz |
|---|---|
| Size | 3.9 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5098f790a1c5978be907fb2a5338c86bfc3e081a8f027ac6a88c38ffeadaeedb
|
|
BLAKE2b-256 checksum How to use checksums |
3282fa0a541654cdac54800e8f76cce2e3d837f9f422f202cdf5f97117afaa04
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency logRelease files / proofbundle-6.2.0-py3-none-any.whl
| Download URL | proofbundle-6.2.0-py3-none-any.whl |
|---|---|
| Size | 836.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c8a32a1e29f19df47d5e07f87bd8d60b07fd9c4a3ab5cb3c1ceaf44a4715afe7
|
|
BLAKE2b-256 checksum How to use checksums |
a24c5032c41c59e181e0e8559c1c034c6e1c92193142681fe61ed00c23560fb3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency log