Technical Specification

Protocol for verifiable computational experiments

K-Veritas records what an experiment or an AI agent did as signed evidence, so any reviewer can independently check what ran and who did it.

Core principles

Passivity

Observers monitor execution without mutating original experiment logic.

Data boundaries

Captured evidence focuses on metadata and telemetry, not proprietary datasets.

Environment integrity

Dependencies and runtime fingerprints are recorded to detect drift.

Integrity

Any change to a signed report makes it fail verification.

Data models

SessionGlobal

Experiment UUID, machine fingerprint, attestation token, project root

RunRecordProcess

Command, duration, exit status, stdout and stderr hashes, run digest

SealRecordCrypto

Canonical data hash, RSA-PSS signature, nonce, timestamp

Cryptographic Signing

signing
payload = "{data_hash}:{nonce}:{signed_at}"
signature = RSA-PSS-SHA256(payload, salt=MAX, key=4096)

The DataHash is a SHA-256 digest of the captured run. The seal also binds a visual PDF hash and a source-code hash, and the server refuses to seal if the code changed after the runs, or if any run differs from the digest it received when that run ended. Verification re-hashes the report and checks the signature offline, then confirms it was signed with the K-Veritas key. A report signed with any other key is self-attested: valid, but of unconfirmed origin.

Metric Capture

K-Veritas reads metrics from your script's output as it runs. Each one stays tied to the run that produced it.

protocol
KVERITAS_METRIC name=<id> value=<float> [step=<label>]

Example (Python): print(f"KVERITAS_METRIC name=accuracy value={acc}")
Example (Bash): echo "KVERITAS_METRIC name=loss value=0.24"

Standard Workflow

  1. init

    Client registers with the server using a machine fingerprint.

  2. run

    Experiment executes while outputs are hashed. Its digest goes to the server when it ends.

  3. seal

    Session is finalized and cryptographically signed.

  4. verify

    Independent audit of the embedded signature and metrics.

Agent Session Protocol

For AI agents, K-Veritas keeps a hash-chained log, so no one can later deny or change what an agent did. The server signs a first entry that fixes which actions get recorded. Every such action is logged before it runs, and each entry links to the one before it.

chain
genesis     = sign(designation_policy)
entry[i].hash = SHA-256(entry[i] : entry[i-1].hash)
head        = sign(entry[n].hash)

Each entry records who acted, the action's inputs and outputs, and its place in order, giving three guarantees: existence, content, and order. The server signs the final head, and verification rebuilds the chain to pinpoint any change to the exact entry. It handles multiple agents and non-sequential flows, attributing every action to the right agent.