Guide

Proofs & checkout

Selectively reveal one file without exposing the rest, and reconstruct the exact code of any snapshot from a single, signature-bound bundle.

Selective-disclosure proofs

The state is a Merkle tree, so you can prove specific files were in a signed snapshot while every other file stays a salted hash. Name one or more files for a single self-contained proof:

kveritas prove report.pdf src/train.py configs/train.yaml
# -> writes one self-contained kveritas-proof.json

kveritas verify-proof kveritas-proof.json
# -> VERIFIED src/train.py       (run 2, train)
#    VERIFIED configs/train.yaml (run 1, preprocess)

The proof reveals only those files' contents; everything else stays a commitment. It embeds the signed seal, so verify-proof checks it on its own, across any run of a session.

report.pdf.provkey.json is a local keystore written next to the report at seal time. It holds real paths and salts and powers prove. Keep it private and do not share it.

Verify in the browser

A proof is one self-contained file, so anyone can check it with no tools. Drop it on kveritas.org/verify to see a VERIFIED badge and contents for each revealed file. Drop several at once and it verifies each.

Checkout bundle

Sealing at --disclosure open writes one bundle, report.pdf.kvbundle.zip, that reconstructs the code at any snapshot. All runs of a session merge into that single zip.

kveritas checkout report.pdf.kvbundle.zip run_end /tmp/out --report report.pdf
# multi-run: select a run and snapshot
kveritas checkout report.pdf.kvbundle.zip run2:train /tmp/out --report report.pdf

It holds the source contents (content-addressed and deduplicated), a per-snapshot manifest, and an index. Never datasets, weights, or withheld files.

Integrity

Report

Signed with RSA-PSS over the canonical data, so any change breaks the data hash.

Bundle

Its hash is bound inside the signed report, so a modified bundle is rejected.

Each file

Every object is re-hashed against its manifest on checkout, so a swapped file is caught even without the report.

Verify a bundle

Pass --report to checkout so the bundle is checked against the signature. On the web verifier, upload the report with the bundle; the Source Bundle check reads MATCH.