Metadata-Version: 2.5
Name: pramana-verify
Version: 0.0.3
Summary: Independently verify a Pramana evidence bundle — offline, with no Pramana account.
Project-URL: Homepage, https://www.reliai.in
Project-URL: Documentation, https://www.reliai.in/docs/
Author-email: Sahil Pandey <sahil@reliai.in>
License-Expression: Apache-2.0
Keywords: ai-agents,audit,compliance,ed25519,evidence,merkle
Classifier: Development Status :: 4 - Beta
Classifier: Intended Audience :: Developers
Classifier: Intended Audience :: Legal Industry
Classifier: Programming Language :: Python :: 3.9
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Topic :: Security :: Cryptography
Classifier: Topic :: Software Development :: Testing
Requires-Python: >=3.9
Requires-Dist: cryptography>=42
Description-Content-Type: text/markdown

# pramana-verify

Independently check that a Pramana evidence bundle has not been altered.

Pramana records what an AI agent did. Every recorded event is fingerprinted with SHA-256 and
chained to the one before it, the chain is summarised into a Merkle root, and that root is signed
with Ed25519. This tool checks all of that, **on your machine, with no network access and no
Pramana account.**

It exists so that you do not have to trust Pramana, or the company whose agent produced the
bundle, in order to believe the bundle.

## Install

```bash
pip install pramana-verify
```

One dependency (`cryptography`). Nothing else from the Pramana platform is required or installed.

## Use

```bash
pramana-verify bundle.json --pubkey <hex>
```

`--pubkey` takes either the public key as hex, or a path to a file containing it.

**A passing bundle:**

```
OK — 428 event(s), merkle_root=3f9c1a...
```

**A bundle that has been altered:**

```
TAMPERED / INVALID:
  - event 17 (ev-8c21): hash chain broken — prev_hash does not match event 16
```

Exit code is `0` when the bundle verifies and `1` when it does not, so this can be wired into an
automated compliance check.

## Getting the public key

**Obtain the public key out of band** — from Pramana directly, from your own records, or from
whoever you are auditing, through a channel separate from the bundle itself.

This tool will never read a key from inside the bundle, deliberately. A bundle carrying its own
verification key proves nothing: anyone who altered the contents could re-sign them with a key of
their own and embed that instead.

## What a passing result proves

- **Nothing in the bundle has been changed since it was signed.** Not one character of a prompt, a
  response, a tool argument, a timestamp or an ordering. Any edit breaks the hash chain, and the
  tool names the event where it broke.
- **The bundle was signed by the holder of the private key** matching the public key you supplied.

## What it does not prove

- **That the recording was complete or honest at the moment it was made.** Cryptography proves
  nothing has been altered *since signing*. It cannot prove that what was captured was everything
  that happened.
- **That the agent behaved correctly.** This is a proof of record, not a judgement of conduct.

Those two limits are inherent to any signed audit record, and stating them is part of using one
properly.

## Offline by design

This tool makes no network calls of any kind. You can verify a bundle on an air-gapped machine,
and you can verify a bundle years after it was produced, without Pramana existing.

---

More about the platform that produces these bundles: https://www.reliai.in
