Skip to main content
proofbundle, flat rabbit head with a pink ear tip

proofbundle

CI demo reproducible PyPI Python License: MIT DOI

Portable evidence for AI work, verifiable offline. Integrity, not truth

One file. No verification server. No network required.

Quick start · What it proves · Current release · Adoption review · Documentation

Current release

v6.2.0 · Beta · Closing audit record named in the release notes

Known limitations · Release notes · Release scope

What was checked, and what remains open

6.2.0 closes five findings in the released 6.0.0 and 6.1.0 at the verify boundary, and one class of eight more: a related map that says it is empty no longer hides a retraction, an edge's declaredAt takes ASCII digits only as the Rust verifier does, a low-order Ed25519 key is refused both as a trusted key and as the holder key of a key binding, a caller's resolver promotes a verdict only on the exact True, and a public verify surface reads each argument of its caller once, by what it stores, so the caller's own methods no longer decide a verdict.

It closes six more findings in four classes, five of them in the released 6.0.0 and 6.1.0: every evaluator applies the rule of load_policy, so a policy field of another type is refused instead of read as no constraint; no value a check judges is read after caller code could change it, the anchors, the relying party's trust material and the answers of a resolver included; a restricting warn of a registered anchor verifier marks the anchor pending; and a container of the wrong type is refused instead of read as empty. The sixth, the warn reading, is a regression of this release cycle and not in the released versions.

A later gate round found two more, both in the released 6.0.0 and 6.1.0: an attached target's subject state is read against the four words its resolver writes, so a state it never writes no longer binds a declared subject pin to the first subject of an ambiguous target; and a restricting command-line option given an empty value, such as --policy '', is refused or applied instead of being read as absent. The gate round at d388ed3d found two more, also in the released 6.0.0 and 6.1.0: the decision and outcome verifiers read a caller's related map once, so a callback of the caller can no longer hide an attached retraction between two readings, and every public function now reads all of its arguments in one reading at its call, before its body reads any of them; and decision verify --anchors refuses a file holding null or an empty list instead of reading it as no option, as the receipt verify commands refuse a policy with nothing in it they evaluate.

The gate round at fda55f98 found one more in the released 6.0.0 and 6.1.0, and closed what that reading still handed on. Every rule a policy sets is now applied by the command it is given to, or the policy is refused; outcome verify printed POLICY: OK over an attached, verified retraction under a rule it never applies. No object of the caller reaches the body of a public function except where an argument's contract names it: an iterator or a generator is refused (pass a list or a tuple), a memoryview no private copy can take is refused, and a value of the caller's own class reaches the body as a stand-in that holds nothing of the caller. The reading does not yet prove a joint state of mutable inputs: a change made and undone between its two reads is not seen, as RESTRISIKO_620.md names. The release notes name the affected versions, the effect and the upgrade.

The closing round runs at a later head than the one this file describes, so this file cannot state its result. In the tagged tree its verdict is the gate line of audit_artifacts/360/fuzz_soak_latest.json and audit_artifacts/360/rust_differential_matrix.json, and the pre-tag receipt audit_artifacts/620/pre_tag_receipt_v6.2.0.json records its own audit command and result; the release notes name the same places.

The package being published and its closing audit passing are separate facts. An audit that was not run makes no statement about the absence of defects.

Residual risks

Quick start

Install the verifier, download an example, then verify the local file.

python -m pip install proofbundle==6.2.0

curl -fsSLo receipt.json \
  https://raw.githubusercontent.com/b7n0de/proofbundle/v6.2.0/examples/example_bundle.json

proofbundle verify receipt.json

Python 3.10 or newer. Installation and download use the network. Verification reads the local file only.

Exit codes and the tamper demo

These exit codes apply to proofbundle verify, not to every command in the package.

Exit code Meaning
0 Verified
1 Verification failed
2 Malformed input or usage error
3 Relying party policy not met

decision verify, outcome verify and relation-statement verify have separate contracts in their own --help.

To try deliberate tampering, install the evaluation extra and run the demo.

python -m pip install 'proofbundle[eval]==6.2.0'
proofbundle demo

The demo checks an honest receipt, tampered variants and a sample swap. It exits with a nonzero code if a tamper is accepted.

Guided walkthrough · Inspect walkthrough

What a receipt proves

What verification can establish What it does not establish
Which key signed the content Whether you should trust that key
Whether signed content has changed Whether the reported result is true
Whether supplied proofs and requested policy checks pass Whether the work was correct or complete

A valid signature does not make a reported result true. Checks depend on the receipt format and the policy you request.

Threat model · Non claims

Choose your task

I want to Start here
Verify a receipt Quick start
Create evaluation evidence Evaluation walkthrough
Add receipts to Inspect AI Inspect integration
Assess proofbundle for adoption Adversarial review guide
Other workflows and optional features
Workflow Package or reference
Evaluation receipts and preregistration proofbundle[eval] · Claim format
Inspect AI proofbundle[inspect] · Integration guide
Agent review disclosures Profile inventory · Conformance examples
RFC 3161 and OpenTimestamps proofbundle[anchors] · Anchor guide
ML-DSA-44 witness cosignatures proofbundle[pq] · Anchor guide
TEE attestation bridge proofbundle[experimental] · Experimental bridge

Shipped features do not all have the same maturity. Agent review disclosures are self declarations. Anchor and enclave paths have experimental boundaries. Check the predicate inventory for the exact profile before relying on it.

Documentation

Your question Reference
How do I implement the format? Specification · Conformance
How do I integrate my workflow? Integrations · Glossary
Which keys and claims should I accept? Policies · Trust anchors
How is security assessed? Threat model · Security policy
How was this release prepared? Release process · Pre tag audit

How it works
Your evaluation, review, decision or action
                    ↓
Canonical statement, signature and supplied proofs
                    ↓
One portable receipt file
                    ↓
Offline verification and explicit policy checks

The verifier checks the evidence it receives. Expected subjects, trusted keys, freshness requirements and acceptance policies come from the relying party. Missing evidence is not evidence that omitted work never happened.

Capabilities and maturity

The core supports signed receipts and Merkle inclusion proofs. Evaluation receipts can bind metrics, thresholds, provenance and commitments. Selective disclosure can hide selected values while preserving the checks supported by its profile.

Decision receipts record a verdict over named evidence. That does not establish that the decision was correct. Outcome, relation, run ledger, trust pack and verification summary profiles have their own maturity limits.

The Rust cross verifier is experimental and advisory. Agreement on recorded cases does not prove either implementation correct, and the Rust tool is not part of the Python package.

Predicate inventory · Conformance boundaries

Security and trust

The core uses cryptography and rfc8785, rather than implementing its own cryptographic primitives. The test approach includes external vectors, mutation checks and parser fuzzing. Those are test signals, not a proof of correctness.

Receipt signatures are Ed25519, not post quantum. ML-DSA-44 witness cosignatures and the experimental renewal path do not turn the payload signature into a post quantum signature. See the anchor documentation.

Build provenance and package attestations answer questions about the build and its bytes. They do not establish the truth of an evaluation or replace a security audit. See the release process.

Report a vulnerability · Conformance · Adoption review

The OpenSSF Scorecard is a heuristic, not a product verdict. Read the per check explanations and self assessment.

Standards and interoperability

proofbundle complements other evidence systems. A format mapping or an open proposal is not the same as adoption by the upstream project.

Tool comparison · Receipt envelope profile · in-toto mapping · SCITT mapping · Related work

The interop discussion with inspect-receipts records a specific envelope comparison. It must not be read as evidence of a second independent implementation of every predicate.

Scope, citation and contributing

proofbundle is not a hosted transparency service, a complete in-toto client, a trusted execution environment, a consensus system or a compliance product by itself.

Release scope records what belongs to this release. Deferred work is not a delivered capability.

Use CITATION.cff for citation metadata. The software archive has concept DOI 10.5281/zenodo.21110642. The Technical Note has concept DOI 10.5281/zenodo.21230466. Software and Technical Note versions are separate records.

Contributing guide · Code of Conduct · Good first issues · Security reports


MIT license · Part of b7n0de, Verified AI Work

Metadata

Release files for proofbundle 6.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for proofbundle 6.2.0
File Size Uploaded
proofbundle-6.2.0.tar.gz 3.9 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for proofbundle 6.2.0
File Interpreter ABI Platform
proofbundle-6.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 4.8 MB

Release files / proofbundle-6.2.0.tar.gz

Download URL proofbundle-6.2.0.tar.gz
Size 3.9 MB
Tags Source
SHA-256 checksum
How to use checksums
5098f790a1c5978be907fb2a5338c86bfc3e081a8f027ac6a88c38ffeadaeedb
BLAKE2b-256 checksum
How to use checksums
3282fa0a541654cdac54800e8f76cce2e3d837f9f422f202cdf5f97117afaa04
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.

Transparency log

Release files / proofbundle-6.2.0-py3-none-any.whl

Download URL proofbundle-6.2.0-py3-none-any.whl
Size 836.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c8a32a1e29f19df47d5e07f87bd8d60b07fd9c4a3ab5cb3c1ceaf44a4715afe7
BLAKE2b-256 checksum
How to use checksums
a24c5032c41c59e181e0e8559c1c034c6e1c92193142681fe61ed00c23560fb3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

6.2.0 This release

2 release files

6.1.0

2 release files

6.0.0

2 release files

5.1.0

2 release files

5.0.0

2 release files

4.0.0

2 release files

3.8.0

2 release files

3.7.0

2 release files

3.6.3

2 release files

3.6.2

2 release files

3.6.1

2 release files

3.6.0

2 release files

3.3.0

2 release files

3.2.3

2 release files

3.2.2

2 release files

3.2.1

2 release files

3.2.0

2 release files

3.1.3

2 release files

3.1.2

2 release files

3.1.1

2 release files

3.1.0

2 release files

3.0.1

2 release files

3.0.0

2 release files

2.1.0

2 release files

2.0.0

2 release files

1.9.2

2 release files

1.9.1

2 release files

1.9.0

2 release files

1.8.0

2 release files

1.7.0

2 release files

1.4.0

2 release files

1.3.0

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.0

2 release files

0.9.0

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page