Skip to main content

Touchstone

Touchstone seals evaluation output into an evidence bundle: the plan, the per-item observations, and a SHA-256 over every file. Anyone can re-check that bundle offline, without this tool and without trusting whoever produced it.

Status

Early. Three of the seven pipeline commands work. The rest are stubs that exit 2, and nothing is published to PyPI yet.

Requirements

Python 3.12 or later. run will need Docker once it exists; nothing today does.

Install

git clone https://github.com/Quantile-Labs/touchstone
cd touchstone
python3 -m venv .venv
.venv/bin/pip install -e .

Check a plan

A plan names the packs to run and the systems to run them against. validate reads it against each pack's manifest.yaml and reports what does not line up:

$ touchstone validate plan.yaml
plan.yaml: ok, 1 pack(s)

$ touchstone validate broken.yaml
broken.yaml: 1 problem(s)
  example_pack: pack does not accept parameter 'max_itemz'

It resolves packs from ./packs. Pass --manifests to point somewhere else. No container runs, and it exits 1 if anything is wrong.

Seal and verify a bundle

bundle hashes every file under a directory and writes MANIFEST.json:

$ touchstone bundle run-004
run-004: sealed 3 file(s)
sha256 f57c02f1af4a277d404c29af41cb8953a513a1b0ca38884fcacaf0cbf3359d19

The printed hash covers the file list, so identical content seals to the same value on any machine. Sealing a directory that already has a manifest is an error.

verify re-checks the bundle and names what moved:

$ touchstone verify run-004
run-004: verified

$ touchstone verify tampered
tampered: 1 failure(s)
  hash mismatch: items.jsonl

Exit 0 means every file matches its recorded hash and no unrecorded file is present. Exit 1 means it does not. There is no network call, no database and no config file.

Verify without Touchstone

The bundle outlives the tool, so nothing in it needs the tool to read. Check any single file against its recorded hash:

$ shasum -a 256 run-004/items.jsonl
63a6e0f7ba35198b686265cab8c8b389599c8bb6c3fcff06234d5b68cda0d82f  run-004/items.jsonl

Recompute the bundle hash from the manifest alone:

$ jq -cS '.files' run-004/MANIFEST.json | tr -d '\n' | shasum -a 256
f57c02f1af4a277d404c29af41cb8953a513a1b0ca38884fcacaf0cbf3359d19  -

That hash detects a file edited after sealing. It does not detect a forger who reseals the whole bundle, which is what external anchoring is for. Anchoring is not built yet.

The pipeline

validate -> freeze -> run -> estimate -> grade -> bundle -> verify
Command Does State
validate check a plan against the manifests of the packs it names works
freeze pin image digests, hash the plan, fix seeds and thresholds exits 2
run execute packs, write per-item observations exits 2
estimate compute rates and intervals, by stratum exits 2
grade apply a score card, produce DQI indicators exits 2
bundle hash every file in a directory, write MANIFEST.json works
verify re-check a bundle against its manifest, offline works

Only run needs a container. Everything after it is a function over files.

Design

Three choices shape the rest:

  • Packs emit one observation per item, not a summary. Touchstone computes the rates and intervals, so a reader can recompute them from the sample in the bundle.
  • Runs are pinned before they start. freeze resolves image tags to digests and hashes the plan; run refuses a plan that has changed since.
  • A missing file, an unresolvable digest or a stale hash is an error with a non-zero exit, never a warning.

To write a pack, see docs/packs.md.

Licence

Apache 2.0. See LICENSE.

Contributing

Read CONTRIBUTING.md first. The commit message and code style rules are enforced by CI.

Maintained by Quantile Labs.

Metadata

Release files for touchstone-dqi 0.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for touchstone-dqi 0.0.1
File Size Uploaded
touchstone_dqi-0.0.1.tar.gz 23.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for touchstone-dqi 0.0.1
File Interpreter ABI Platform
touchstone_dqi-0.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 40.8 kB

Release files / touchstone_dqi-0.0.1.tar.gz

Download URL touchstone_dqi-0.0.1.tar.gz
Size 23.8 kB
Tags Source
SHA-256 checksum
How to use checksums
22e05410666bb9c938a7dccec5bc29922f3dc54be00aa3c34d5401e7837bc332
BLAKE2b-256 checksum
How to use checksums
2bec792f86474f8bce50400e17b9c3357cbe8a8378424632c1f6606f39285c01
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / touchstone_dqi-0.0.1-py3-none-any.whl

Download URL touchstone_dqi-0.0.1-py3-none-any.whl
Size 17.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7225a55698e818ff1b4488005e8ea5fbe63f91ae96ee8ce0636467ddb66ab0e9
BLAKE2b-256 checksum
How to use checksums
9a4caa2c2045f75e7d2e339320d828a4774e8bd1ed1f9c8f5f71ade001699246
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release history Release notifications | RSS feed

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

This release

0.0.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page