vidimus
Verifiable custody of agent-produced records.
vidimus (Latin, "we have seen"): the medieval certificate by which an authority attests it has inspected a record and recites it verbatim. Scandinavian law still stamps certified true copies with the word — vidimerad kopia, vidimeret kopi.
Status
Pre-release extraction target — nothing here verifies anything yet. The machinery arrives by extraction from three production systems that each built it independently (pre-registered forecast records, an observation-ledger release chain, a signed statute corpus), behind a byte-equivalence gate: the extracted verifier must reproduce the source verifier's verdict, pass and fail alike, on the live production chain at a pinned commit before any system consumes the package.
What it will provide
vidimus.chain— append-only hash-chained manifests over record sets: enumerated genesis, content-addressed links, immutable-prefix verificationvidimus.tsa— RFC 3161 timestamps from independent authorities, two per record, with per-witness honest degradation (an unavailable witness is recorded with a reason, never silently skipped)vidimus.sign— Ed25519 producer signatures verified against SPKI fingerprints pinned in the consumer's own committed code; N-of-M thresholds; rotation as an explicit recorded eventvidimus.attest— CI push attestation with self-anchoring enforcement epochs and a completeness sweep over every record-touching commitvidimus.ratchet— shrink-only exception registries recomputed from live state; an excused failure that starts passing is an error until removedvidimus.chronology— record-vs-event ordering tiers: does witnessed time prove the record existed ante quem — before the event it predicts or observes?vidimus verify— the outside auditor's command: a clone, commodity tools, one offline fail-closed verdict
Design principle
Trust anchors live in the consumer's committed code, never in runtime configuration a producer could swap. The package ships machinery; consumers pin roots.
The name
"Control" descends from the counter-roll (contre-rôle): the independent duplicate record kept so the roll could be audited. This package is the counter-roll for agent-produced records.
License
Apache-2.0.
Metadata
Release files for vidimus 0.1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vidimus-0.1.2.tar.gz | 58.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vidimus-0.1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 87.0 kB
Release files / vidimus-0.1.2.tar.gz
| Download URL | vidimus-0.1.2.tar.gz |
|---|---|
| Size | 58.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ef0f798ecea994ce8796358442c046ddd77a9f7fc5608ca1bf35f9aa73a05b3f
|
|
BLAKE2b-256 checksum How to use checksums |
e94b83079ebfa8a96e47e73743b7a7f7d18ca6e7d41b8ef99d94a57e6da44cab
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 20, 2026.
Transparency logRelease files / vidimus-0.1.2-py3-none-any.whl
| Download URL | vidimus-0.1.2-py3-none-any.whl |
|---|---|
| Size | 28.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f6662a73b31bb7c67b038b7179680c48de93c368ad2d9fd0bcde34fd3f6841ba
|
|
BLAKE2b-256 checksum How to use checksums |
b80dfa474cfbd58439eacd8268d2d956c7440667b1b67252188c20454f17607c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 20, 2026.
Transparency log