Open specifications and verifiers that bind model weights, agent identity and every tool call to hardware attestation. Anyone can check the evidence offline, without asking us.
/verify › keybind_quote.binoffline · in this browser
quoteIntel TDX v4, GCP C3, captured 2026-09-14
step 1attestation key signature over header and TD reportnot run
step 2QE report binds the attestation keynot run
step 3QE report signed by the platform PCK certificatenot run
step 4PCK chain ends at the pinned Intel SGX Root CAnot run
REPORTDATAcommits to the key that signed a published TRACE recordnot run
verdictgenuine Intel TDX silicon signed this quotenot run
NoteGenuine Intel TDX silicon signed this quote, and its REPORTDATA commits to the key that signed the TRACE record published beside it. It does not show that the software inside the trust domain was the image anyone intended.
Runs in your browser. Nothing is sent back to us.
Why now
Logs are written by the system you are trying to check.
Agents can edit the record of what they did.
An independent evaluator's incident report (METR, 26 August 2026) found roughly 7% of the agent transcripts it reviewed had been successfully spoofed, and could not rule out agents deleting logs after the fact.
In June 2026 a remote UI package for a popular coding-agent CLI, at about 29,000 weekly npm downloads, shipped code that exfiltrated users' non-expiring OAuth refresh tokens.
Weights are leaving the building.
Sovereign and on-premises deployment puts a model builder's weights on hardware somebody else owns. Weight-security research recommends confidential computing for the highest protection levels, and current silicon still falls to an operator with physical access.
TRACE spec v0.2, a Series of LF Projects with an AAIF Sandbox proposal open, agentrust-trace 0.10.0, signed registry checkpoints with an external witness receipt
Each step links to its project site. No step requires the others; use the ones your trust boundary needs.
Where it runs
Validated on real silicon, verified to the vendor's root.
AMD SEV-SNP
Azure confidential VM. Report signatures verify to the AMD root.
We verify signature chains. We do not appraise whether a platform's TCB is current.
Scope
What this proves, and what it does not.
A signature shows who signed a record and that it has not changed. It says nothing about where the signer ran.
Hardware origin needs a verified attestation that binds the signing key.
Memory-bus attacks such as TEE.fail and BadRAM defeat current confidential-computing silicon against an operator who physically owns the machine. Weight custody is scoped to match.
The start pages and demos run in software mode, with no hardware isolation.
Conformance vectors are self-tests. They are not certification.
A registry entry shows a record was anchored. It does not validate the record's claims.
Who it is for
Start where your trust boundary is.
Model builders
Deploying weights into customer or sovereign infrastructure.
TRACE is its own Series of LF Projects, announced by the Linux Foundation on 25 August 2026 and developed with AMD, Intel, Microsoft, OPAQUE and TII. It has also been proposed to the Agentic AI Foundation at the Sandbox stage (aaif/project-proposals #42, opened 14 September 2026).
Sponsored by OPAQUE, which funds the engineering, infrastructure and confidential-computing work behind these projects. Organisations that want to support open, verifiable AI infrastructure are welcome to join as sponsors.