Proofs & checkout
Selectively reveal one file without exposing the rest, and reconstruct the exact code of any snapshot from a single, signature-bound bundle.
Selective-disclosure proofs
The state is a Merkle tree, so you can prove specific files were in a signed snapshot while every other file stays a salted hash. Name one or more files for a single self-contained proof:
kveritas prove report.pdf src/train.py configs/train.yaml
# -> writes one self-contained kveritas-proof.json
kveritas verify-proof kveritas-proof.json
# -> VERIFIED src/train.py (run 2, train)
# VERIFIED configs/train.yaml (run 1, preprocess)The proof reveals only those files' contents; everything else stays a commitment. It embeds the signed seal, so verify-proof checks it on its own, across any run of a session.
report.pdf.provkey.json is a local keystore written next to the report at seal time. It holds real paths and salts and powers prove. Keep it private and do not share it.Verify in the browser
A proof is one self-contained file, so anyone can check it with no tools. Drop it on kveritas.org/verify to see a VERIFIED badge and contents for each revealed file. Drop several at once and it verifies each.
Checkout bundle
Sealing at --disclosure open writes one bundle, report.pdf.kvbundle.zip, that reconstructs the code at any snapshot. All runs of a session merge into that single zip.
kveritas checkout report.pdf.kvbundle.zip run_end /tmp/out --report report.pdf
# multi-run: select a run and snapshot
kveritas checkout report.pdf.kvbundle.zip run2:train /tmp/out --report report.pdfIt holds the source contents (content-addressed and deduplicated), a per-snapshot manifest, and an index. Never datasets, weights, or withheld files.
Integrity
Signed with RSA-PSS over the canonical data, so any change breaks the data hash.
Its hash is bound inside the signed report, so a modified bundle is rejected.
Every object is re-hashed against its manifest on checkout, so a swapped file is caught even without the report.
Verify a bundle
Pass --report to checkout so the bundle is checked against the signature. On the web verifier, upload the report with the bundle; the Source Bundle check reads MATCH.