Technical report / Version 1
Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary Model Weights
OPAQUE Systems
Abstract
Deploying proprietary model weights into infrastructure controlled by a customer reverses the usual confidential-computing trust problem: the model builder, rather than the infrastructure owner, supplies the secret. Existing confidential-computing stacks can attest workloads and release secrets, while model-signing systems authenticate model artifacts. Neither capability alone specifies continuing custody of a particular weight artifact after release. This technical report describes the Weight Custody Manifest (WCM), a vendor-neutral protocol and conformance model that binds an exact weight digest, an approved workload measurement, attestation policy, a fresh transport key, renewable authorization, terminal refusal and wipe evidence, and derivative lineage. WCM distinguishes cryptographic custody against software adversaries from accountability-grade controls when the infrastructure operator physically owns the machine. The evaluated Python reference implementation, version 0.28.0, supplies 91 portable conformance vectors across four levels. Its test suite produced 618 passing tests and three skips on September 3, 2026, and the same counts when rerun at the same commit for this edition. Two later findings bound those results: a published advisory showed that the evaluated key broker did not require GPU confidential-compute mode before release, and the SEV-SNP platform used for the hardware run does not enable the ciphertext hiding that the cryptographic-custody claim against a hypervisor-privileged operator requires. The contribution is a portable artifact-to-runtime custody contract with explicit lifecycle evidence, derivative accountability, and conformance, not a new attestation primitive or a certification of any deployment.
What this report contributes
A portable custody contract binding exact weights, measured workload, fresh channel-bound release, renewable authority, terminal evidence and derivative lineage.
Evidence and limits
- The evaluated version is WCM 0.28.0 (commit 2acedfa). Its software results were rerun on September 27, 2026 with the same counts: 618 passed, 3 skipped, 91 of 91 conformance vectors. The SEV-SNP hardware runs were not repeated.
- Advisory GHSA-j665-99rh-w85h affects the evaluated version: the key broker did not require GPU confidential-compute mode before release. The fail-closed result does not cover GPU mode.
- The measured Azure SEV-SNP platform does not enable ciphertext hiding, so the cryptographic-custody claim does not hold there against a hypervisor-privileged operator. Against an operator who physically owns the machine, WCM claims accountability, not custody.
The source package preserves the recorded inputs and results. The software results were rerun at the evaluated commit for this edition; the hardware runs were not repeated. No independent replication is claimed.
Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.
Cite this report
Imran Siddique. Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary Model Weights. AgenTrust technical report, version 1, 2026.
Download BibTeX / Download CITATION.cff
@techreport{agentrust2026weightcustodymanifest,
title = {Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary Model Weights},
author = {Imran Siddique},
institution = {AgenTrust},
year = {2026},
type = {Technical report},
note = {Version 1; not peer reviewed},
doi = {10.5281/zenodo.23020644},
url = {https://agentrust-io.com/research/weight-custody-manifest/v1/}
}
Version history
Version 1, September 27, 2026: Adds a post-evaluation findings section, corrects the descriptions of the three skipped tests and of the memory-sweep receipt, fixes two citations, and records a software rerun at the evaluated commit.
Revises a manuscript dated September 3, 2026.
File checksums. Published version files are retained; substantive revisions receive a new version.
Questions and corrections
Open an issue in the project repository and identify the report version and section.