szl-calibration
Calibration Intelligence Plane — the bridge between the SZL formula corpus, governed runtime, and observability. Exact calibration math on caller-supplied probabilities, every scored batch receipted, Prometheus-native surface, fail-closed weight gates in CI.
Doctrine v11. Lambda = Conjecture 1 (advisory). Apache-2.0.
Honesty labels
- SOFTWARE. Metrics are exact math on probabilities the caller supplies. No model weights are loaded by this service. No hardware, energy, or accuracy claims are made.
- Receipts are UNSIGNED_HONEST: a SHA-256 hash chain that proves integrity and order of the log, never the correctness of a score. Verification is offline and dependency-free.
- The safetensors gate is fail-closed: structural failures are BLOCK and cannot be waived; an unavailable NaN scan degrades to REVIEW, never to ALLOW.
API
| Route | Purpose |
|---|---|
GET /healthz |
liveness + receipt-chain validity |
GET /metrics |
Prometheus exposition (requests, latency, ECE histogram) |
POST /v1/score |
ECE/MCE/Brier/log-loss/AUROC + receipt for a batch |
POST /v1/calibration/score |
backwards-compatible alias for the same scorer |
GET /v1/calibration/receipts |
full hash-chained receipt log (JSONL) |
GET /v1/receipts/verify |
chain validity; HTTP 503 if integrity fails |
POST /v1/decisions/assess |
source-bound offline decision study, per-group risk and abstention; no execution authorization |
Invalid batches return HTTP 422 and do not append a receipt. Receipts are stored in memory for the current service process; restarting the process starts a new chain. This service does not claim persistent or shared multi-worker history.
Receipt payloads are detached from both caller inputs and returned receipt objects.
Non-finite JSON values are rejected. A broken chain makes /healthz and both
scoring routes return HTTP 503; no new receipt is appended. Append verifies the
existing chain while holding its lock, so verification cost grows with history.
The hash chain detects changes relative to retained receipts; it is unsigned and
does not prevent a privileged writer from replacing or truncating the entire log.
Run
pip install -e '.[serve]'
uvicorn szl_calibration.service:app --host 127.0.0.1 --port 8080
Typed decisions and optional Jev integration
Decision studies reuse the existing calibration metrics
for labeled multiclass predictions, bind the exact cohort and frozen policy in an
unsigned receipt, and measure selective error for every declared cohort. Missing
evidence and small samples remain REVIEW; failed prerequisites remain BLOCK.
The highest result is ELIGIBLE_FOR_SHADOW, never deployment or action authority.
The optional Jev adapter uses the documented TypeSafe API with an explicit model version, strict response validation and a bounded request. It does not change the service into a provider proxy. The included synthetic example can be assessed offline without a key:
python -m szl_calibration.decision_cli examples/decision-study.json
CI weight gate
python tests/make_fixtures.py
python -m szl_calibration.gate_cli tests/fixtures/tiny.safetensors --expect ALLOW
Exit codes: ALLOW 0 / BLOCK 1 / REVIEW 2 / expectation mismatch 3. Structure (header framing, dtype/shape/offset consistency) is validated stdlib-only; NaN/Inf scanning uses numpy when present and honestly degrades to REVIEW otherwise.
Alerts
deploy/grafana-alerts.yaml ships p95-latency, ECE-drift, chain-broken (critical,
fail-closed), and memory alerts as a PrometheusRule-compatible manifest.
Metadata
Release files for szl-calibration 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| szl_calibration-0.1.0.tar.gz | 29.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| szl_calibration-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 54.8 kB
Release files / szl_calibration-0.1.0.tar.gz
| Download URL | szl_calibration-0.1.0.tar.gz |
|---|---|
| Size | 29.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5098a52e399d1e1d764719f47692cc4a6d2c188130fdaa40b39e01dc5e6a60ba
|
|
BLAKE2b-256 checksum How to use checksums |
392ca732c339b0d51e5e8a14566204da4793676d79961e3af36ce2c53fa67ea9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency logRelease files / szl_calibration-0.1.0-py3-none-any.whl
| Download URL | szl_calibration-0.1.0-py3-none-any.whl |
|---|---|
| Size | 25.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7ff1b0e032925b3e281eb3fb3ed831a65bac9bafb54ae2d5514db6df88070858
|
|
BLAKE2b-256 checksum How to use checksums |
fbe59c86f575ff44a829a13c28eef449c5559d67d07f3a04dc1e1cf43ac39cf4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency log