Skip to main content

Context governance for agentic AI — tamper-evident audit trails for LLM context inputs

Project description

Provena

CI PyPI Downloads Python 3.10+ License: Apache 2.0 Code style: ruff

Context governance for agentic AI systems. (MVP)

Your AI agent just made a decision based on data from 6 different sources. Can you tell me which ones? Can you prove the data wasn't tampered with? Can you verify it was still current?

Provena adds tamper-evident audit trails to any AI agent's context pipeline — in 3 lines of Python.

from provena import ContextTrail

trail = ContextTrail()

@trail.track(source="retriever")
def search(query):
    return retriever.search(query)

Every call to search() is now logged with a SHA-256 content hash, provenance validation, and a hash-chained audit trail that detects tampering.

Why Provena?

AGT governs what agents DO. Guardrails AI governs what agents SAY. Provena governs what agents KNOW.

No existing tool governs the context input layer. Provena fills this gap with:

  • Tamper-evident audit trails — SHA-256 hash-chained (Merkle-style) logging with optional HMAC signing
  • Provenance validation — Verify that context carries proper source metadata (VALID / MISSING / INCOMPLETE)
  • Freshness checking — Detect stale context via metadata timestamps and regex temporal detection (FRESH / STALE / UNKNOWN)
  • Any context source — RAG retrievers, tool outputs, agent messages, memory recalls, MCP resources
  • Sub-1ms overhead — Pure Python, no ML models, no ONNX, no model downloads
  • Zero dependencies — Core library uses only the Python standard library

Install

pip install provena              # core (zero dependencies)
pip install provena[cli]         # + CLI tools (click, rich)
pip install provena[otel]        # + OpenTelemetry export
pip install provena[langchain]   # + LangChain adapter
pip install provena[llamaindex]  # + LlamaIndex adapter
pip install provena[all]         # everything

Quick Start

from provena import ContextTrail, ProvenanceMetadata
from datetime import datetime, timezone

trail = ContextTrail(storage_path="audit.db")

# Track any function that produces context
@trail.track(source="retriever")
def search(query):
    return retriever.search(query)

@trail.track(source="tool:pricing_api")
def get_price(product_id):
    return api.get(f"/price/{product_id}")

# Manual logging with provenance metadata
trail.log(
    content="The enterprise plan costs $499/month.",
    source="tool:pricing_api",
    provenance=ProvenanceMetadata(
        source_url="https://api.example.com/pricing",
        created_at=datetime.now(timezone.utc),
    ),
)

# Verify the audit trail hasn't been tampered with
verdict = trail.verify_chain()
print(f"Chain intact: {verdict.intact}")
print(f"Total records: {verdict.total_records}")

CLI

Install with pip install provena[cli], then:

# Verify hash chain integrity
provena --db audit.db verify
# PASS — Chain intact (42 records verified)

# Query the audit log
provena --db audit.db audit --source retriever --format json

# Generate a governance report
provena --db audit.db report --format text

# Quick summary
provena --db audit.db summary

For HMAC-signed trails, pass --signing-key or set PROVENA_SIGNING_KEY.

Integrations

LangChain

from provena.integrations.langchain import ProvenaCallback

chain = RetrievalQA.from_chain_type(
    llm=llm,
    retriever=retriever,
    callbacks=[ProvenaCallback(trail=trail)],
)

LlamaIndex

from provena.integrations.llamaindex import ProvenaPostprocessor

query_engine = index.as_query_engine(
    node_postprocessors=[ProvenaPostprocessor(trail=trail)]
)

OpenTelemetry

trail = ContextTrail(
    storage_path="audit.db",
    otel_enabled=True,
    otel_service_name="my-agent",
)
# Every log() call now emits an OTel span with governance attributes

Architecture

Your Application
│
│  Retriever ──┐
│  Tool Call ──┤
│  Agent Msg ──┼──► ContextTrail ──► LLM Context Window
│  Memory    ──┤        │
│  MCP       ──┘        │
│                  ┌─────┴──────────────┐
│                  │ ProvenanceValidator │
│                  │ FreshnessChecker    │
│                  │ HashChain (SHA-256) │
│                  │ SQLite Backend      │
│                  │ OTel Exporter       │
│                  └────────────────────┘

Compliance

Provena maps directly to EU AI Act requirements (enforcement: August 2, 2026):

Article Requirement Provena Feature
Art. 10 Data lineage Provenance validation for every context input
Art. 12 Tamper-evident logging SHA-256 hash-chained audit trail with HMAC signing
Art. 13 Transparency trail.summary() and source tracking
Art. 14 Human oversight trail.annotate() for reviewer decisions

Also addresses OWASP ASI06 (Memory & Context Poisoning).

Contributing

We welcome contributions! See CONTRIBUTING.md for development setup, architecture guide, and PR process.

Please read our Code of Conduct before participating.

License

Apache 2.0

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

provena-0.6.0.tar.gz (49.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

provena-0.6.0-py3-none-any.whl (30.3 kB view details)

Uploaded Python 3

File details

Details for the file provena-0.6.0.tar.gz.

File metadata

  • Download URL: provena-0.6.0.tar.gz
  • Upload date:
  • Size: 49.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for provena-0.6.0.tar.gz
Algorithm Hash digest
SHA256 d51d666a578860f634ab1d463a118ae07ed5536f24d583a5a6f372a6d2d89bf1
MD5 3b0fb8eb993e8676adea8496649fc8a3
BLAKE2b-256 11ba6577db14c89eb9a3dba21f0a19689922a03251e880f7703efe431ba53550

See more details on using hashes here.

Provenance

The following attestation bundles were made for provena-0.6.0.tar.gz:

Publisher: publish.yml on rajfirke/provena

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file provena-0.6.0-py3-none-any.whl.

File metadata

  • Download URL: provena-0.6.0-py3-none-any.whl
  • Upload date:
  • Size: 30.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for provena-0.6.0-py3-none-any.whl
Algorithm Hash digest
SHA256 9ac7c9521aec87d5d470b46a90517233bcaf89bb1a0b0ad0bf0fb5dad719f274
MD5 deb8772ebcb49a6ded5ef3ac7ce8210c
BLAKE2b-256 0f6069efe516dc1163e56a1b5e0f95b945d360db843f37fb1eda9d63c47fa4c4

See more details on using hashes here.

Provenance

The following attestation bundles were made for provena-0.6.0-py3-none-any.whl:

Publisher: publish.yml on rajfirke/provena

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page