Protocol for verifiable computational experiments
K-Veritas records what an experiment or an AI agent did as signed evidence, so any reviewer can independently check what ran and who did it.
Core principles
Passivity
Observers monitor execution without mutating original experiment logic.
Data boundaries
Captured evidence focuses on metadata and telemetry, not proprietary datasets.
Environment integrity
Dependencies and runtime fingerprints are recorded to detect drift.
Integrity
Any change to a signed report makes it fail verification.
Data models
Experiment UUID, machine fingerprint, attestation token, project root
Command, duration, exit status, stdout and stderr hashes, run digest
Canonical data hash, RSA-PSS signature, nonce, timestamp
Cryptographic Signing
payload = "{data_hash}:{nonce}:{signed_at}"
signature = RSA-PSS-SHA256(payload, salt=MAX, key=4096)The DataHash is a SHA-256 digest of the captured run. The seal also binds a visual PDF hash and a source-code hash, and the server refuses to seal if the code changed after the runs, or if any run differs from the digest it received when that run ended. Verification re-hashes the report and checks the signature offline, then confirms it was signed with the K-Veritas key. A report signed with any other key is self-attested: valid, but of unconfirmed origin.
Metric Capture
K-Veritas reads metrics from your script's output as it runs. Each one stays tied to the run that produced it.
KVERITAS_METRIC name=<id> value=<float> [step=<label>]Example (Python): print(f"KVERITAS_METRIC name=accuracy value={acc}")
Example (Bash): echo "KVERITAS_METRIC name=loss value=0.24"
Standard Workflow
init
Client registers with the server using a machine fingerprint.
run
Experiment executes while outputs are hashed. Its digest goes to the server when it ends.
seal
Session is finalized and cryptographically signed.
verify
Independent audit of the embedded signature and metrics.
Agent Session Protocol
For AI agents, K-Veritas keeps a hash-chained log, so no one can later deny or change what an agent did. The server signs a first entry that fixes which actions get recorded. Every such action is logged before it runs, and each entry links to the one before it.
genesis = sign(designation_policy)
entry[i].hash = SHA-256(entry[i] : entry[i-1].hash)
head = sign(entry[n].hash)Each entry records who acted, the action's inputs and outputs, and its place in order, giving three guarantees: existence, content, and order. The server signs the final head, and verification rebuilds the chain to pinpoint any change to the exact entry. It handles multiple agents and non-sequential flows, attributing every action to the right agent.