Open specifications for verifiable AI

Prove what your AI ran, and what it did.

Open specifications and verifiers that bind model weights, agent identity and every tool call to hardware attestation. Anyone can check the evidence offline, without asking us.

/verify › keybind_quote.binoffline · in this browser
  1. quoteIntel TDX v4, GCP C3, captured 2026-09-14
  2. step 1attestation key signature over header and TD reportnot run
  3. step 2QE report binds the attestation keynot run
  4. step 3QE report signed by the platform PCK certificatenot run
  5. step 4PCK chain ends at the pinned Intel SGX Root CAnot run
  6. REPORTDATAcommits to the key that signed a published TRACE recordnot run
  7. verdictgenuine Intel TDX silicon signed this quotenot run

NoteGenuine Intel TDX silicon signed this quote, and its REPORTDATA commits to the key that signed the TRACE record published beside it. It does not show that the software inside the trust domain was the image anyone intended.

Runs in your browser. Nothing is sent back to us.

Logs are written by the system you are trying to check.

Agents can edit the record of what they did.

An independent evaluator's incident report (METR, 26 August 2026) found roughly 7% of the agent transcripts it reviewed had been successfully spoofed, and could not rule out agents deleting logs after the fact.

Read the incident report ↗

The tooling around agents is the attack surface.

In June 2026 a remote UI package for a popular coding-agent CLI, at about 29,000 weekly npm downloads, shipped code that exfiltrated users' non-expiring OAuth refresh tokens.

Weights are leaving the building.

Sovereign and on-premises deployment puts a model builder's weights on hardware somebody else owns. Weight-security research recommends confidential computing for the highest protection levels, and current silicon still falls to an operator with physical access.

Read the weight-security research ↗

Four questions, each with evidence a stranger can check.

01 · WEIGHTS Is this the model that was released, and who may release its key?

Weight Custody Manifest

Spec pre-1.0, SDK 0.28.1, 91 portable conformance vectors
02 · AGENT What is this agent, and what is it allowed to do?

Agent Manifest

SDK 0.12.0, proposed to CoSAI WS4 (RFC #149)
03 · ACTIONS Was each tool call and each delegation checked inside attested hardware?

cMCP and cA2A

cmcp-runtime 0.5.0; cA2A 0.2.0 developer preview
04 · EVIDENCE Can a third party verify all of it offline, years later?

TRACE, TRACE Registry, conformance suite

TRACE spec v0.2, a Series of LF Projects with an AAIF Sandbox proposal open, agentrust-trace 0.10.0, signed registry checkpoints with an external witness receipt

Each step links to its project site. No step requires the others; use the ones your trust boundary needs.


Validated on real silicon, verified to the vendor's root.

We verify signature chains. We do not appraise whether a platform's TCB is current.


What this proves, and what it does not.


Start where your trust boundary is.


Anyone can read it, run it and check it.

OPAQUE
Sponsor

Sponsored by OPAQUE, which funds the engineering, infrastructure and confidential-computing work behind these projects. Organisations that want to support open, verifiable AI infrastructure are welcome to join as sponsors.

Talk to us about sponsoring →
Every project is open source. Licences vary by project and are listed on each site.
8 of 9 repositories hold an OpenSSF Best Practices passing badge.
Software policy enforcement builds on the Microsoft Agent Governance Toolkit.