Documentation
Research and integration.
Two things live here: the research attest has published or been cited in, and the reference for connecting a system to the verification layer.
Published and cited work
Everything attest has published on independent evidence custody, plus the external research the argument rests on. Each piece is hosted in full; nothing here is gated.
-
Published by attest
Independent evaluation needs independent evidence
Frontier labs are converging on embedded third-party evaluation. Oversight runs on evidence, and that evidence is produced, stored, ordered, and handed over by the organization under review. The paper works through what the OpenAI–Hugging Face investigation showed about self-produced machine records, the four properties an independent evidence layer has to supply, and the limits it cannot honestly claim past.
-
Published by attest
Regulatory mapping matrix: agentic capability, audit requirements, and evidence custody
A clause-by-clause mapping of EU AI Act, SEC, FINRA, PCAOB, HIPAA, and NIST recordkeeping obligations against what agentic systems already do in production — and against who actually holds the evidence in each case. Every row lands on the same structural finding: the entity under examination is the entity that produces and controls the record of its own behavior.
-
Cited research
Seeing real value from AI depends on being able to verify its outputs
AI systems are producing work faster than people can reliably verify it, creating a widening economic and operational gap between automation and accountability.
Connect attest to your systems.
Integration is one authenticated request. Send machine activity with your environment credential, watch it verify in Sandbox, then point the same call at Production.
What’s new in 0.2.0
The published 0.2.0 SDK provides paired boundary verification. Witness records machine observations before and after an operation crosses a system boundary, then reconciles those observations into authoritative pair state:
matched— assembly and delivery observations were accepted and agree.divergent— assembly and delivery observations were accepted and disagree.incomplete— only an assembly observation was accepted.orphaned— only a delivery observation was accepted.
The states stay honest when a process dies mid-operation. Durable observations cannot prove whether your business operation ran, so a recovered pair always reports executionState: "unknown", and an assembly-only OPEN pair reports recoveryStatus: "delivery_required". Recovery never reruns your operation and never fabricates a delivery observation — declaring a permanently one-sided pair incomplete is an explicit finalizeWitness(pairId) call the caller has to make.
Finalization produces authoritative F-5 reconciliation in attest-witness-reconciliation-v1, including reconciliationStatus, reconciliationFormat, reconciliationDigest, and finalizedAt. After legitimate finalization, F-7 durable trust projection and boundary checkpoint creation occur asynchronously: assembly + delivery → F-5 reconciliation → F-7 projection → boundary checkpoint.
SDK methods: prepareWitness(), witness(), witnessAssembly(), witnessDelivery(), finalizeWitness(), getWitness(), resumeWitness(). Each newly accepted Production observation meters one Verification Pass at $0.001. Exact duplicate replay, inspection with resumeWitness(), finalization or re-finalization, F-7 projection, and checkpoint creation add no passes.
1 · Get an environment credential
Every workspace opens with separated Sandbox and Production scopes, each with its own API keys and its own history. Keys are shown once, rotate cleanly, and revoke instantly.
2 · Submit in Sandbox
Sandbox accepts the same payloads as Production and bills nothing. Confirm event identity, duplicate handling, and your retry behavior before a single Production event is metered.
3 · Route to Production
Nothing in the call changes. Swap the Sandbox key for the Production key and the same request starts producing billable Verification Passes — one per unique accepted event, duplicates excluded.
4 · Export the record
Pull verification history by period and environment as CSV or through the reporting API, shaped for auditors and counterparties rather than dashboards alone.
npm install @attestinfra/sdk@0.2.0await attest.verify({
eventType: "ai.agent.tool_call",
source: "research-agent",
eventId: job.id
});
// → verified · signed · custodiedRaw HTTP works too — POST /v1/events with a Bearer credential. Any machine that can make an authenticated HTTPS request can use attest.
const prepared = attest.prepareWitness({
eventType: "transfer.requested",
source: "checkout",
destination: "payments",
action: "transfer",
evidence: { actionId: "transfer_82" }
});
// synchronous; persist pairId + assemblyIdentity first
const { result, witness } = await prepared.execute(() => transferFunds());
// witness.reconciliationStatus → "matched"Raw HTTP equivalents are POST /v1/witness, POST /v1/witness/{pairId}/finalize, and GET /v1/witness/{pairId}.