Technical report / Version 1

Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary Model Weights

Imran Siddique

OPAQUE Systems

September 27, 2026Not peer reviewedPatent Pending

Abstract

Deploying proprietary model weights into infrastructure controlled by a customer reverses the usual confidential-computing trust problem: the model builder, rather than the infrastructure owner, supplies the secret. Existing confidential-computing stacks can attest workloads and release secrets, while model-signing systems authenticate model artifacts. Neither capability alone specifies continuing custody of a particular weight artifact after release. This technical report describes the Weight Custody Manifest (WCM), a vendor-neutral protocol and conformance model that binds an exact weight digest, an approved workload measurement, attestation policy, a fresh transport key, renewable authorization, terminal refusal and wipe evidence, and derivative lineage. WCM distinguishes cryptographic custody against software adversaries from accountability-grade controls when the infrastructure operator physically owns the machine. The evaluated Python reference implementation, version 0.28.0, supplies 91 portable conformance vectors across four levels. Its test suite produced 618 passing tests and three skips on September 3, 2026, and the same counts when rerun at the same commit for this edition. Two later findings bound those results: a published advisory showed that the evaluated key broker did not require GPU confidential-compute mode before release, and the SEV-SNP platform used for the hardware run does not enable the ciphertext hiding that the cryptographic-custody claim against a hypervisor-privileged operator requires. The contribution is a portable artifact-to-runtime custody contract with explicit lifecycle evidence, derivative accountability, and conformance, not a new attestation primitive or a certification of any deployment.

What this report contributes

A portable custody contract binding exact weights, measured workload, fresh channel-bound release, renewable authority, terminal evidence and derivative lineage.

Evidence and limits

The source package preserves the recorded inputs and results. The software results were rerun at the evaluated commit for this edition; the hardware runs were not repeated. No independent replication is claimed.

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

Cite this report

Imran Siddique. Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary Model Weights. AgenTrust technical report, version 1, 2026.

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026weightcustodymanifest,
  title = {Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary Model Weights},
  author = {Imran Siddique},
  institution = {AgenTrust},
  year = {2026},
  type = {Technical report},
  note = {Version 1; not peer reviewed},
  doi = {10.5281/zenodo.23020644},
  url = {https://agentrust-io.com/research/weight-custody-manifest/v1/}
}

Version history

Version 1, September 27, 2026: Adds a post-evaluation findings section, corrects the descriptions of the three skipped tests and of the memory-sweep receipt, fixes two citations, and records a software rerun at the evaluated commit.

Revises a manuscript dated September 3, 2026.

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.