Verifiable custody of agent-produced records: chained manifests, dual RFC 3161 witnesses, pinned Ed25519 signatures, push attestation, chronology tiers, shrink-only waivers — one offline verification command
Project description
vidimus
Verifiable custody of agent-produced records.
vidimus (Latin, "we have seen"): the medieval certificate by which an authority attests it has inspected a record and recites it verbatim. Scandinavian law still stamps certified true copies with the word — vidimerad kopia, vidimeret kopi.
Status
Pre-release extraction target — nothing here verifies anything yet. The machinery arrives by extraction from three production systems that each built it independently (pre-registered forecast records, an observation-ledger release chain, a signed statute corpus), behind a byte-equivalence gate: the extracted verifier must reproduce the source verifier's verdict, pass and fail alike, on the live production chain at a pinned commit before any system consumes the package.
What it will provide
vidimus.chain— append-only hash-chained manifests over record sets: enumerated genesis, content-addressed links, immutable-prefix verificationvidimus.tsa— RFC 3161 timestamps from independent authorities, two per record, with per-witness honest degradation (an unavailable witness is recorded with a reason, never silently skipped)vidimus.sign— Ed25519 producer signatures verified against SPKI fingerprints pinned in the consumer's own committed code; N-of-M thresholds; rotation as an explicit recorded eventvidimus.attest— CI push attestation with self-anchoring enforcement epochs and a completeness sweep over every record-touching commitvidimus.ratchet— shrink-only exception registries recomputed from live state; an excused failure that starts passing is an error until removedvidimus.chronology— record-vs-event ordering tiers: does witnessed time prove the record existed ante quem — before the event it predicts or observes?vidimus verify— the outside auditor's command: a clone, commodity tools, one offline fail-closed verdict
Design principle
Trust anchors live in the consumer's committed code, never in runtime configuration a producer could swap. The package ships machinery; consumers pin roots.
The name
"Control" descends from the counter-roll (contre-rôle): the independent duplicate record kept so the roll could be audited. This package is the counter-roll for agent-produced records.
License
Apache-2.0.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file vidimus-0.1.0.tar.gz.
File metadata
- Download URL: vidimus-0.1.0.tar.gz
- Upload date:
- Size: 57.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ba8e9df5b2d66a1157a2bc821d8502321119fe138c0adb68642ac5ee1f89bb28
|
|
| MD5 |
8053051c6269640bc6da8c119823df2a
|
|
| BLAKE2b-256 |
4ead7ffd24a7a5f10f4e4a546162513ccd731edec50896f9a363f904ddb7cf1f
|
Provenance
The following attestation bundles were made for vidimus-0.1.0.tar.gz:
Publisher:
publish.yml on TheAxiomFoundation/vidimus
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vidimus-0.1.0.tar.gz -
Subject digest:
ba8e9df5b2d66a1157a2bc821d8502321119fe138c0adb68642ac5ee1f89bb28 - Sigstore transparency entry: 2206897706
- Sigstore integration time:
-
Permalink:
TheAxiomFoundation/vidimus@a0731b3a77bdbeba22dfcb44294c8b6bfbd0d5a0 -
Branch / Tag:
refs/tags/v0.1.0 - Owner: https://github.com/TheAxiomFoundation
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@a0731b3a77bdbeba22dfcb44294c8b6bfbd0d5a0 -
Trigger Event:
release
-
Statement type:
File details
Details for the file vidimus-0.1.0-py3-none-any.whl.
File metadata
- Download URL: vidimus-0.1.0-py3-none-any.whl
- Upload date:
- Size: 28.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
979bde510f16ae4c71014daf7fcf86502c79c932785a301e58fcb054726cbc24
|
|
| MD5 |
b903281a701b34bbf28ac839dc9c4789
|
|
| BLAKE2b-256 |
a8f4d7676a638710344d1ab9f49ed42133733cf48fb97a0e6bf4770e06b12489
|
Provenance
The following attestation bundles were made for vidimus-0.1.0-py3-none-any.whl:
Publisher:
publish.yml on TheAxiomFoundation/vidimus
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vidimus-0.1.0-py3-none-any.whl -
Subject digest:
979bde510f16ae4c71014daf7fcf86502c79c932785a301e58fcb054726cbc24 - Sigstore transparency entry: 2206897717
- Sigstore integration time:
-
Permalink:
TheAxiomFoundation/vidimus@a0731b3a77bdbeba22dfcb44294c8b6bfbd0d5a0 -
Branch / Tag:
refs/tags/v0.1.0 - Owner: https://github.com/TheAxiomFoundation
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@a0731b3a77bdbeba22dfcb44294c8b6bfbd0d5a0 -
Trigger Event:
release
-
Statement type: