attest
Explore page
LogsWhy nowHow it worksPlatformPricingDocsResearchFAQ

Machine verification infrastructure

A receipt for every machine action.

attest is independent verification infrastructure for AI and machine activity. Every action your systems take becomes a durable, cryptographically signed record — a signed receipt of what was submitted and accepted, held outside the systems that produced it. attest does not certify objective source truth.

+1,000,000 verified events and counting

  • Cryptographically signed
  • Replay-protected
  • Independently custodied
  • Audit-ready

01Logs

Logs live inside the system they describe.

Self-reported

Logs are inside.

Your application writes its own logs. Your AI records its own actions. Your agents generate their own audit trails. That makes logs essential for operations — but it also means the system being examined is usually the system providing the evidence.

If that system is compromised, misconfigured, incomplete, or simply wrong, its logs can be wrong too. Records can be changed, deleted, omitted, or never created in the first place.

Independent

attest sits outside that boundary.

When a machine action is sent to attest, a separate system receives it, verifies the record, protects against replay, and preserves the resulting evidence independently of the system that produced the action.

The originating system can keep running. Its logs can keep doing what logs do best: debugging, monitoring, and operations. But there is now another record outside that system — one designed for verification rather than self-reporting.

attest cryptographically hashes and signs the evidence it accepts so the integrity of that record can be checked independently of the originating system.

02Why now

Machines are acting faster than companies can account for them.

Frontier AI is becoming more capable, more autonomous, and harder to verify from self-controlled logs alone. Attest creates an independent evidence layer across machine boundaries.

At the same time, companies are being asked for more accountability: what acted, what happened, when it happened, and what evidence exists to support the answer. Regulatory and governance frameworks are increasingly moving toward auditability, traceability, and evidence — just as autonomous machine activity is accelerating.

That creates a widening gap:

Machines are doing more. Traditional systems are recording themselves. Independent evidence infrastructure has not kept pace.

03How it works

What your company gets.

Every machine event successfully submitted to and accepted by attest produces an independently held verification record — outside your infrastructure, outside your cloud, outside of where you’re most vulnerable. Your systems keep running. attest keeps track.

You can retrieve your verification history, confirm any event's status, and export records for auditors, counterparties, or regulators — backed by a verification layer your own team cannot modify.

As your volume grows, your evidence grows with it. Every Verification Pass adds to a cumulative, independently custodied record of what your systems submitted and attest accepted.

Not AI verifying AI — attest uses cryptography and the machine operations already in your stack to create a verifiable record.

A machine acts

An agent calls a tool, a model returns an inference, a workflow completes a step — anywhere in your stack, at any volume.

The event is submitted

One authenticated request carries the event to attest with its own identity, from any language or runtime.

attest verifies it

The record is canonicalized, hashed, signed, and checked against replay — then persisted outside the system that produced it.

The receipt stands

A durable Verification Pass joins your record — retrievable and exportable under the Service retention terms.

04Platform

Built to be depended on.

Verification only matters if the layer holding it is harder to dispute than the systems it records. attest is engineered as durable infrastructure — a small surface with strong guarantees, producing evidence that outlives the moment it was created.

Signedevery accepted event is hashed and signed
Deduplicatedreplays and retries never create a second record
Custodiedevidence is held outside your infrastructure
Exportablesupported history export, on demand

Cryptographic signing

Every accepted event is canonicalized, hashed, and signed. Integrity can be checked independently — without trusting the system that produced the event, or taking attest’s word for it.

Replay protection

Each event carries its own identity. Retries and replays are recognized as duplicates and excluded — one action, one receipt, one charge.

Independent custody

Records are preserved outside your infrastructure and outside your cloud. Your own team cannot rewrite them — which is exactly what makes them worth showing to someone else.

Scoped environments

Sandbox and Production are separated end to end, with their own credentials and their own history. Prove the integration before a single Production event is billed.

Credential lifecycle

Environment-scoped API keys are shown once, rotate cleanly, and revoke instantly — credentials that behave the way your security review expects.

Audit-ready export

Pull verification history by period and environment, as CSV or through the reporting API — shaped for auditors and counterparties, not only dashboards.

One verification layer across the machine economy — the same receipt, whatever the system behind it.

05Pricing

Pay for what gets verified.

One unique verified event equals one Verification Pass. Duplicates are excluded.

$0.001per Verification Pass

Usage-based, with no minimums. Prove the integration in Sandbox before Production is billed.

1,000 Verification Passes$1
1,000,000 Verification Passes$1,000

What counts as a Verification Pass?

A Verification Pass is created when attest successfully verifies one distinct machine action submitted with its own event identity.

  • one AI model inference
  • one API transaction
  • one automated workflow step
  • one tool or agent action
  • one machine-to-machine handoff

If the same event is retried or replayed with the same identity, attest recognizes it as a duplicate and does not create or bill another Verification Pass.

06Docs

Connect attest to your systems.

Integration is one authenticated request. Send machine activity with your environment credential, watch it verify in Sandbox, then point the same call at Production.

Install
npm install @attestinfra/sdk@0.2.0
Verify
await attest.verify({
  eventType: "ai.agent.tool_call",
  source: "research-agent",
  eventId: job.id
});
// → verified · signed · custodied

Raw HTTP works too — POST /v1/events with a Bearer credential. Any machine that can make an authenticated HTTPS request can use attest.

Witness
const prepared = attest.prepareWitness({
  eventType: "transfer.requested",
  source: "checkout",
  destination: "payments",
  action: "transfer",
  evidence: { actionId: "transfer_82" }
});

const { result, witness } = await prepared.execute(() => transferFunds());
// → assembly observation · delivery observation · matched

0.2.0 is published. Witness records machine observations before and after an operation crosses a system boundary, then reconciles those observations into authoritative pair state. Missing delivery does not establish whether the operation occurred.

07Research

The argument, in public.

attest publishes the case for independent evidence custody rather than asserting it. Everything below is readable in full and nothing is gated — the standards comment we filed, the paper on what independent evaluation actually requires, and the external research the argument rests on.

  1. Published by attest

    Independent evaluation needs independent evidence

    attest · September 2026 · Position paper

    Embedded evaluators make judgment independent. They do not make the evidence that judgment rests on independent — and the OpenAI–Hugging Face investigation is the field test.

    Read the paper →
  2. Published by attest

    Regulatory mapping matrix: agentic capability, audit requirements, and evidence custody

    attest · August 2026 · Standards comment · NIST AI Standards Zero Draft

    Every recordkeeping obligation now on the books lands on the same finding: the entity being examined is the entity that holds the evidence.

    Read the matrix →
  3. Cited research

    Seeing real value from AI depends on being able to verify its outputs

    MIT Sloan School of Management · June 2026 · Institutional research explainer

    AI is producing work faster than people can verify it, opening a measurable gap between automation and accountability.

    MIT Sloan ↗

Start verifying

Built to outlast the systems it records.

Start in Sandbox in minutes. Your first verified event becomes your first receipt — and the record only grows from there.