diff --git a/data/research.json b/data/research.json index 013f96b..4cb74c0 100644 --- a/data/research.json +++ b/data/research.json @@ -17,18 +17,35 @@ "The missing-runtime fixture passes at Level 0 in the saved results. The cMCP fixture fails at all three levels. Those outcomes limit what the historical conformance checks establish.", "A signature proves integrity and signing-key possession. Hardware origin requires verified attestation and key binding; inclusion in a log does not prove that every event was recorded." ], - "changes": "Clarifies the signature and hardware-evidence boundary, corrects the description of saved conformance outcomes, and preserves the historical measurements.", + "origin": "Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.", "spec": "https://trace.agentrust-io.com/", "code": "https://github.com/agentrust-io/trace-spec", "patent_pending": false, - "doi": "10.5281/zenodo.23001692", - "date": "2026-09-27", "abstract": "TRACE (Trust, Runtime Attestation, and Compliance Evidence) proposes a portable record for claims about AI agent runtimes: workload identity, model, policy, data class, tool transcript, build provenance, and appraisal. It composes RATS/EAT, signatures, and transparency evidence into a format that a relying party can evaluate against its own trust policy. A valid signature establishes integrity and possession of the signing key; hardware origin additionally requires verified attestation and a binding from that evidence to the key. This technical report describes the original design and preserves the recorded software evaluation of agentrust-trace 0.2.0 and trace-tests 0.2.0. The evaluation measures canonicalization, Ed25519 signing and verification, record size, and fixture outcomes. It does not measure silicon certificate-chain appraisal or establish that the recorded runtime claims are true. The current normative specification and its implementation limits are maintained separately.", - "pages": 15, - "sha256": { - "paper.pdf": "40034a6d7dd62f0e066798bcc746b5fc7b6fa723078f52e4a3c4c919bd821ded", - "source.zip": "b31c13247c98c3f83a44a25dfdf6862f89b6d2f38fc95133ef45340138f383f9" - } + "versions": [ + { + "version": 1, + "date": "2026-09-27", + "pages": 15, + "changes": "Clarifies the signature and hardware-evidence boundary, corrects the description of saved conformance outcomes, and preserves the historical measurements.", + "sha256": { + "paper.pdf": "40034a6d7dd62f0e066798bcc746b5fc7b6fa723078f52e4a3c4c919bd821ded", + "source.zip": "b31c13247c98c3f83a44a25dfdf6862f89b6d2f38fc95133ef45340138f383f9" + }, + "doi": "10.5281/zenodo.23001692" + }, + { + "version": 2, + "date": "2026-09-28", + "pages": 15, + "changes": "Corrects the related-work statement that transparency-log registration makes omitted events detectable, which contradicted the conclusion, and removes three en dashes. Results unchanged.", + "doi": "10.5281/zenodo.23024103", + "sha256": { + "paper.pdf": "e4b75dc0b2627486f2d8692193705ddf7db0fe7de225d4b1b8010fcac9382bdd", + "source.zip": "3f9b16068aaa22cf7280eba5b8d8a1a9a1e332ca6d5a3c81b92c08bf35577aef" + } + } + ] }, { "slug": "cmcp", @@ -48,6 +65,7 @@ "Replay and omission detection depend on trusted keys, freshness checks, and an expected session or log boundary. Gateway records alone do not establish complete information flow." ], "changes": "Narrows the abstract to the measured software behavior, corrects the false-discovery terminology, and adds the publication scope and patent notice.", + "origin": "Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.", "spec": "https://cmcp.agentrust-io.com/", "code": "https://github.com/agentrust-io/cmcp", "patent_pending": true, @@ -77,6 +95,7 @@ "The saved environment does not identify the exact SDK commit. It supports inspection of the recorded results, but not a claim of fully pinned independent reproduction." ], "changes": "Separates signed-baseline checks from proof of runtime use, states evaluation limits, and adds the publication scope and patent notice.", + "origin": "Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.", "spec": "https://manifest.agentrust-io.com/", "code": "https://github.com/agentrust-io/agent-manifest", "patent_pending": true, @@ -105,6 +124,8 @@ "The measured Azure SEV-SNP platform does not enable ciphertext hiding, so the cryptographic-custody claim does not hold there against a hypervisor-privileged operator. Against an operator who physically owns the machine, WCM claims accountability, not custody." ], "changes": "Adds a post-evaluation findings section, corrects the descriptions of the three skipped tests and of the memory-sweep receipt, fixes two citations, and records a software rerun at the evaluated commit.", + "origin": "Revises a manuscript dated September 3, 2026.", + "evidence_note": "The software results were rerun at the evaluated commit for this edition; the hardware runs were not repeated. No independent replication is claimed.", "spec": "https://wcm.agentrust-io.com/", "code": "https://github.com/agentrust-io/weight-custody-manifest", "patent_pending": true, @@ -135,9 +156,12 @@ "The results do not show that a peer's key is confined to attested code. Provenance checks on unsigned records establish structural consistency only; authenticity rests on signed records." ], "changes": "Narrows claims to what the code validates, reruns the experiments on ca2a 0.3.1, corrects three citations, and adds a post-evaluation findings section.", + "origin": "Revises a draft dated July 2026.", + "evidence_note": "The software experiments were rerun against ca2a 0.3.1 for this edition; no hardware run was repeated. No independent replication is claimed.", "spec": "https://ca2a.agentrust-io.com/", "code": "https://github.com/agentrust-io/ca2a", "patent_pending": true, + "doi": "10.5281/zenodo.23022872", "date": "2026-09-27", "abstract": "The Agent2Agent (A2A) protocol moves tasks between agents, and its Signed Agent Card lets a client check that a domain owner issued a card. The card does not bound the authority a delegating agent passes on, establish what code a peer runs, keep a task payload from the peer's host, or leave an offline record of who delegated what to whom. This technical report describes cA2A (Confidential A2A), a trust profile layered on A2A rather than a new transport. It composes four mechanisms: signed delegation credentials whose scope can only narrow at each hop, appraisal of a peer's attestation evidence before a task is sent, a payload sealed to the channel key that evidence vouches for, and a signed per-hop provenance record linked to its parent. Attenuated delegation and provenance binding are covered by prior capability-token work and IETF drafts; the contribution here is their composition on A2A with an open implementation. We state six properties and report software experiments rerun against ca2a 0.3.1: attenuation checks over 5,400 generated chains, rejection of in-chain replay and cross-chain splicing, intersection of delegated scope with local policy, sealed-payload behavior at the cryptographic layer, structural checks on linked provenance records, and a cross-operator attestation protocol exercised with synthetic evidence. Chain verification cost about 0.22 ms per hop in this environment. These results do not show that a peer's key is confined to attested code or that attestation works across independent operators. Recorded hardware runs cover one-directional appraisal of an Intel TDX peer by an AMD SEV-SNP peer in another cloud and a same-operator mutual SEV-SNP diagnostic; mutual attestation between independent operators has not been demonstrated.", "pages": 21, @@ -162,9 +186,12 @@ "A defect found after the evaluation let an edited evidence snapshot be signed at the evaluated release; it was fixed later and is reported beside the results." ], "changes": "Aligns claims with the evaluated code, positions the contract against prior governance telemetry work, and adds a post-evaluation findings section.", + "origin": "Revises a manuscript dated September 3, 2026.", + "evidence_note": "The Python results were rerun at the evaluated commit for this edition; the TypeScript suite was not rerun. No independent replication is claimed.", "spec": "https://agentrust-io.com/telemetry/", "code": "https://github.com/agentrust-io/agentrust-telemetry", "patent_pending": false, + "doi": "10.5281/zenodo.23022882", "date": "2026-09-27", "abstract": "Agent observability conventions describe model, tool, and agent operations, but governance facts are commonly fragmented across policy engines, approval stores, cost modules, and audit systems. Copying those facts into ordinary traces creates two hazards: sensitive payload capture and the false inference that sampled operational telemetry is complete audit evidence. This technical report describes AgenTrust Telemetry, a backend-neutral contract for six governance event families: policy decisions, approval lifecycles, usage, classified data flows, action execution, and evidence lifecycle. The contract correlates with W3C Trace Context and OpenTelemetry without installing a provider, exporter, or competing tracing model. A metadata-only profile rejects prompts, outputs, source code, tool arguments and results, credentials, and authorization tokens by key. Durable run and action identifiers survive process and asynchronous handoffs; propagated metadata remains untrusted and does not confer identity or authority. An optional accumulator accepts events before lossy export and can be finalized into a separately verifiable TRACE record. Its completeness status is a producer assertion that the accumulator records but does not measure. The evaluated release, 0.1.0-alpha.2, ships Python and TypeScript reference SDKs over shared schemas and a portable conformance set of six valid and seven invalid fixtures. At that commit 111 Python unit tests pass and all 13 fixtures produce their expected verdicts, on September 3, 2026 and again when rerun for this edition. A defect found after the evaluation let an edited evidence snapshot be signed; it is reported beside the results it qualifies. The contribution is not another agent tracing convention; it is a narrow semantic boundary between operational observation and governance evidence whose completeness must be stated rather than inferred.", "pages": 6, @@ -189,9 +216,12 @@ "Hardware acceptance and independently operated peers are future work. Raw hardware diagnostic captures are not published." ], "changes": "Reframes the draft as a bounded software edition, records the rerun, updates dependency status and corrects two references.", + "origin": "Revises a discussion draft dated September 19, 2026.", + "evidence_note": "The composed software experiment was rerun for this edition; no hardware run was repeated. No independent replication is claimed.", "spec": "https://wcm.agentrust-io.com/", "code": "https://github.com/agentrust-io/weight-custody-manifest/tree/main/python/composed", "patent_pending": true, + "doi": "10.5281/zenodo.23022884", "date": "2026-09-27", "abstract": "This paper states conditions under which tool calls and agent handoffs preserve an authorized plaintext-holder boundary. This requires a protected channel bound to an appraised workload, restricted authority, enforceable downstream information-flow rules, and control over every other plaintext sink. A signature on an execution record or a valid hardware quote alone cannot establish these conditions. If a recipient cannot satisfy them, the sender must withhold the data or obtain authorization for a precisely described disclosure. This paper develops a conditional composition argument, a proposed handoff contract, and component experiments that expose failures of appraisal, supervision, and outcome inference. A composed software harness joins provisioning, diagnostic model computation, a confined agent, a mediated tool, delegated peer authentication, and exact-output disclosure. Its paired mutations expose earlier leaks despite successful final delivery; a rerun on September 27, 2026 reproduced all 36 recorded observations. All results are software results with synthetic attestation and a single operator. AgenTrust supplies relevant identity, key-release, gateway, delegation, and evidence primitives, but its present components do not demonstrate the complete property. The distinction matters most at remote tools, CPU-GPU transfers, operator-controlled key brokers, runtime changes, and audit systems.", "pages": 13, diff --git a/research/agentrust-telemetry/index.html b/research/agentrust-telemetry/index.html index e7f1ee2..82f0232 100644 --- a/research/agentrust-telemetry/index.html +++ b/research/agentrust-telemetry/index.html @@ -21,7 +21,8 @@ - + + @@ -67,10 +68,10 @@

From Agent Observability to Governance Evidence: A Privacy-Constrained Telem
September 27, 2026Not peer reviewed

Abstract

Agent observability conventions describe model, tool, and agent operations, but governance facts are commonly fragmented across policy engines, approval stores, cost modules, and audit systems. Copying those facts into ordinary traces creates two hazards: sensitive payload capture and the false inference that sampled operational telemetry is complete audit evidence. This technical report describes AgenTrust Telemetry, a backend-neutral contract for six governance event families: policy decisions, approval lifecycles, usage, classified data flows, action execution, and evidence lifecycle. The contract correlates with W3C Trace Context and OpenTelemetry without installing a provider, exporter, or competing tracing model. A metadata-only profile rejects prompts, outputs, source code, tool arguments and results, credentials, and authorization tokens by key. Durable run and action identifiers survive process and asynchronous handoffs; propagated metadata remains untrusted and does not confer identity or authority. An optional accumulator accepts events before lossy export and can be finalized into a separately verifiable TRACE record. Its completeness status is a producer assertion that the accumulator records but does not measure. The evaluated release, 0.1.0-alpha.2, ships Python and TypeScript reference SDKs over shared schemas and a portable conformance set of six valid and seven invalid fixtures. At that commit 111 Python unit tests pass and all 13 fixtures produce their expected verdicts, on September 3, 2026 and again when rerun for this edition. A defect found after the evaluation let an edited evidence snapshot be signed; it is reported beside the results it qualifies. The contribution is not another agent tracing convention; it is a narrow semantic boundary between operational observation and governance evidence whose completeness must be stated rather than inferred.

- +

What this report contributes

A backend-neutral contract for six governance event families that keeps lossy operational telemetry separate from evidence whose completeness is stated.

Evidence and limits

-

The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.

+

The source package preserves the recorded inputs and results. The Python results were rerun at the evaluated commit for this edition; the TypeScript suite was not rerun. No independent replication is claimed.

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

Cite this report

Imran Siddique. From Agent Observability to Governance Evidence: A Privacy-Constrained Telemetry Contract. AgenTrust technical report, version 1, 2026.

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026agentrusttelemetry,
@@ -80,11 +81,12 @@ 

From Agent Observability to Governance Evidence: A Privacy-Constrained Telem year = {2026}, type = {Technical report}, note = {Version 1; not peer reviewed}, + doi = {10.5281/zenodo.23022882}, url = {https://agentrust-io.com/research/agentrust-telemetry/v1/} }

Version history

Version 1, September 27, 2026: Aligns claims with the evaluated code, positions the contract against prior governance telemetry work, and adds a post-evaluation findings section.

-

Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.

+

Revises a manuscript dated September 3, 2026.

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.

diff --git a/research/agentrust-telemetry/v1/CITATION.cff b/research/agentrust-telemetry/v1/CITATION.cff index 5173de9..c171f99 100644 --- a/research/agentrust-telemetry/v1/CITATION.cff +++ b/research/agentrust-telemetry/v1/CITATION.cff @@ -13,6 +13,7 @@ ], "url": "https://agentrust-io.com/research/agentrust-telemetry/v1/", "license": "CC-BY-4.0", + "doi": "10.5281/zenodo.23022882", "preferred-citation": { "type": "report", "title": "From Agent Observability to Governance Evidence: A Privacy-Constrained Telemetry Contract", diff --git a/research/agentrust-telemetry/v1/citation.bib b/research/agentrust-telemetry/v1/citation.bib index db622c3..483526e 100644 --- a/research/agentrust-telemetry/v1/citation.bib +++ b/research/agentrust-telemetry/v1/citation.bib @@ -5,5 +5,6 @@ @techreport{agentrust2026agentrusttelemetry year = {2026}, type = {Technical report}, note = {Version 1; not peer reviewed}, + doi = {10.5281/zenodo.23022882}, url = {https://agentrust-io.com/research/agentrust-telemetry/v1/} } diff --git a/research/agentrust-telemetry/v1/index.html b/research/agentrust-telemetry/v1/index.html index c161523..627323e 100644 --- a/research/agentrust-telemetry/v1/index.html +++ b/research/agentrust-telemetry/v1/index.html @@ -21,7 +21,8 @@ - + + @@ -67,10 +68,10 @@

From Agent Observability to Governance Evidence: A Privacy-Constrained Telem
September 27, 2026Not peer reviewed

Abstract

Agent observability conventions describe model, tool, and agent operations, but governance facts are commonly fragmented across policy engines, approval stores, cost modules, and audit systems. Copying those facts into ordinary traces creates two hazards: sensitive payload capture and the false inference that sampled operational telemetry is complete audit evidence. This technical report describes AgenTrust Telemetry, a backend-neutral contract for six governance event families: policy decisions, approval lifecycles, usage, classified data flows, action execution, and evidence lifecycle. The contract correlates with W3C Trace Context and OpenTelemetry without installing a provider, exporter, or competing tracing model. A metadata-only profile rejects prompts, outputs, source code, tool arguments and results, credentials, and authorization tokens by key. Durable run and action identifiers survive process and asynchronous handoffs; propagated metadata remains untrusted and does not confer identity or authority. An optional accumulator accepts events before lossy export and can be finalized into a separately verifiable TRACE record. Its completeness status is a producer assertion that the accumulator records but does not measure. The evaluated release, 0.1.0-alpha.2, ships Python and TypeScript reference SDKs over shared schemas and a portable conformance set of six valid and seven invalid fixtures. At that commit 111 Python unit tests pass and all 13 fixtures produce their expected verdicts, on September 3, 2026 and again when rerun for this edition. A defect found after the evaluation let an edited evidence snapshot be signed; it is reported beside the results it qualifies. The contribution is not another agent tracing convention; it is a narrow semantic boundary between operational observation and governance evidence whose completeness must be stated rather than inferred.

- +

What this report contributes

A backend-neutral contract for six governance event families that keeps lossy operational telemetry separate from evidence whose completeness is stated.

Evidence and limits

-

The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.

+

The source package preserves the recorded inputs and results. The Python results were rerun at the evaluated commit for this edition; the TypeScript suite was not rerun. No independent replication is claimed.

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

Cite this report

Imran Siddique. From Agent Observability to Governance Evidence: A Privacy-Constrained Telemetry Contract. AgenTrust technical report, version 1, 2026.

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026agentrusttelemetry,
@@ -80,11 +81,12 @@ 

From Agent Observability to Governance Evidence: A Privacy-Constrained Telem year = {2026}, type = {Technical report}, note = {Version 1; not peer reviewed}, + doi = {10.5281/zenodo.23022882}, url = {https://agentrust-io.com/research/agentrust-telemetry/v1/} }

Version history

Version 1, September 27, 2026: Aligns claims with the evaluated code, positions the contract against prior governance telemetry work, and adds a post-evaluation findings section.

-

Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.

+

Revises a manuscript dated September 3, 2026.

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.

diff --git a/research/ca2a/index.html b/research/ca2a/index.html index b131312..ae8f893 100644 --- a/research/ca2a/index.html +++ b/research/ca2a/index.html @@ -23,7 +23,8 @@ - + + @@ -69,10 +70,10 @@

cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A

September 27, 2026Not peer reviewedPatent Pending

Abstract

The Agent2Agent (A2A) protocol moves tasks between agents, and its Signed Agent Card lets a client check that a domain owner issued a card. The card does not bound the authority a delegating agent passes on, establish what code a peer runs, keep a task payload from the peer's host, or leave an offline record of who delegated what to whom. This technical report describes cA2A (Confidential A2A), a trust profile layered on A2A rather than a new transport. It composes four mechanisms: signed delegation credentials whose scope can only narrow at each hop, appraisal of a peer's attestation evidence before a task is sent, a payload sealed to the channel key that evidence vouches for, and a signed per-hop provenance record linked to its parent. Attenuated delegation and provenance binding are covered by prior capability-token work and IETF drafts; the contribution here is their composition on A2A with an open implementation. We state six properties and report software experiments rerun against ca2a 0.3.1: attenuation checks over 5,400 generated chains, rejection of in-chain replay and cross-chain splicing, intersection of delegated scope with local policy, sealed-payload behavior at the cryptographic layer, structural checks on linked provenance records, and a cross-operator attestation protocol exercised with synthetic evidence. Chain verification cost about 0.22 ms per hop in this environment. These results do not show that a peer's key is confined to attested code or that attestation works across independent operators. Recorded hardware runs cover one-directional appraisal of an Intel TDX peer by an AMD SEV-SNP peer in another cloud and a same-operator mutual SEV-SNP diagnostic; mutual attestation between independent operators has not been demonstrated.

- +

What this report contributes

A trust profile on A2A composing narrowing delegation credentials, peer attestation appraisal, sealed payloads and linked per-hop provenance records.

Evidence and limits

-

The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.

+

The source package preserves the recorded inputs and results. The software experiments were rerun against ca2a 0.3.1 for this edition; no hardware run was repeated. No independent replication is claimed.

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

Cite this report

Rishabh Poddar; Aaron Fulkerson; Imran Siddique. cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A. AgenTrust technical report, version 1, 2026.

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026ca2a,
@@ -82,11 +83,12 @@ 

cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A

year = {2026}, type = {Technical report}, note = {Version 1; not peer reviewed}, + doi = {10.5281/zenodo.23022872}, url = {https://agentrust-io.com/research/ca2a/v1/} }

Version history

Version 1, September 27, 2026: Narrows claims to what the code validates, reruns the experiments on ca2a 0.3.1, corrects three citations, and adds a post-evaluation findings section.

-

Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.

+

Revises a draft dated July 2026.

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.

diff --git a/research/ca2a/v1/CITATION.cff b/research/ca2a/v1/CITATION.cff index 45acbfa..310e01c 100644 --- a/research/ca2a/v1/CITATION.cff +++ b/research/ca2a/v1/CITATION.cff @@ -21,6 +21,7 @@ ], "url": "https://agentrust-io.com/research/ca2a/v1/", "license": "CC-BY-4.0", + "doi": "10.5281/zenodo.23022872", "preferred-citation": { "type": "report", "title": "cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A", diff --git a/research/ca2a/v1/citation.bib b/research/ca2a/v1/citation.bib index cdfdd7c..f855f6a 100644 --- a/research/ca2a/v1/citation.bib +++ b/research/ca2a/v1/citation.bib @@ -5,5 +5,6 @@ @techreport{agentrust2026ca2a year = {2026}, type = {Technical report}, note = {Version 1; not peer reviewed}, + doi = {10.5281/zenodo.23022872}, url = {https://agentrust-io.com/research/ca2a/v1/} } diff --git a/research/ca2a/v1/index.html b/research/ca2a/v1/index.html index b1e06eb..1591ca5 100644 --- a/research/ca2a/v1/index.html +++ b/research/ca2a/v1/index.html @@ -23,7 +23,8 @@ - + + @@ -69,10 +70,10 @@

cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A

September 27, 2026Not peer reviewedPatent Pending

Abstract

The Agent2Agent (A2A) protocol moves tasks between agents, and its Signed Agent Card lets a client check that a domain owner issued a card. The card does not bound the authority a delegating agent passes on, establish what code a peer runs, keep a task payload from the peer's host, or leave an offline record of who delegated what to whom. This technical report describes cA2A (Confidential A2A), a trust profile layered on A2A rather than a new transport. It composes four mechanisms: signed delegation credentials whose scope can only narrow at each hop, appraisal of a peer's attestation evidence before a task is sent, a payload sealed to the channel key that evidence vouches for, and a signed per-hop provenance record linked to its parent. Attenuated delegation and provenance binding are covered by prior capability-token work and IETF drafts; the contribution here is their composition on A2A with an open implementation. We state six properties and report software experiments rerun against ca2a 0.3.1: attenuation checks over 5,400 generated chains, rejection of in-chain replay and cross-chain splicing, intersection of delegated scope with local policy, sealed-payload behavior at the cryptographic layer, structural checks on linked provenance records, and a cross-operator attestation protocol exercised with synthetic evidence. Chain verification cost about 0.22 ms per hop in this environment. These results do not show that a peer's key is confined to attested code or that attestation works across independent operators. Recorded hardware runs cover one-directional appraisal of an Intel TDX peer by an AMD SEV-SNP peer in another cloud and a same-operator mutual SEV-SNP diagnostic; mutual attestation between independent operators has not been demonstrated.

- +

What this report contributes

A trust profile on A2A composing narrowing delegation credentials, peer attestation appraisal, sealed payloads and linked per-hop provenance records.

Evidence and limits

-

The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.

+

The source package preserves the recorded inputs and results. The software experiments were rerun against ca2a 0.3.1 for this edition; no hardware run was repeated. No independent replication is claimed.

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

Cite this report

Rishabh Poddar; Aaron Fulkerson; Imran Siddique. cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A. AgenTrust technical report, version 1, 2026.

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026ca2a,
@@ -82,11 +83,12 @@ 

cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A

year = {2026}, type = {Technical report}, note = {Version 1; not peer reviewed}, + doi = {10.5281/zenodo.23022872}, url = {https://agentrust-io.com/research/ca2a/v1/} }

Version history

Version 1, September 27, 2026: Narrows claims to what the code validates, reruns the experiments on ca2a 0.3.1, corrects three citations, and adds a post-evaluation findings section.

-

Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.

+

Revises a draft dated July 2026.

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.

diff --git a/research/confidential-handoffs/index.html b/research/confidential-handoffs/index.html index 2150412..e78b2d5 100644 --- a/research/confidential-handoffs/index.html +++ b/research/confidential-handoffs/index.html @@ -21,7 +21,8 @@ - + + @@ -67,10 +68,10 @@

Confidentiality Across Agent Handoffs: Conditions for preserving an inferenc
September 27, 2026Not peer reviewedPatent Pending

Abstract

This paper states conditions under which tool calls and agent handoffs preserve an authorized plaintext-holder boundary. This requires a protected channel bound to an appraised workload, restricted authority, enforceable downstream information-flow rules, and control over every other plaintext sink. A signature on an execution record or a valid hardware quote alone cannot establish these conditions. If a recipient cannot satisfy them, the sender must withhold the data or obtain authorization for a precisely described disclosure. This paper develops a conditional composition argument, a proposed handoff contract, and component experiments that expose failures of appraisal, supervision, and outcome inference. A composed software harness joins provisioning, diagnostic model computation, a confined agent, a mediated tool, delegated peer authentication, and exact-output disclosure. Its paired mutations expose earlier leaks despite successful final delivery; a rerun on September 27, 2026 reproduced all 36 recorded observations. All results are software results with synthetic attestation and a single operator. AgenTrust supplies relevant identity, key-release, gateway, delegation, and evidence primitives, but its present components do not demonstrate the complete property. The distinction matters most at remote tools, CPU-GPU transfers, operator-controlled key brokers, runtime changes, and audit systems.

- +

What this report contributes

A conditional composition argument and proposed handoff contract for when tool calls and delegations preserve an authorized plaintext-holder boundary.

Evidence and limits

-

The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.

+

The source package preserves the recorded inputs and results. The composed software experiment was rerun for this edition; no hardware run was repeated. No independent replication is claimed.

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

Cite this report

Imran Siddique. Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation. AgenTrust technical report, version 1, 2026.

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026confidentialhandoffs,
@@ -80,11 +81,12 @@ 

Confidentiality Across Agent Handoffs: Conditions for preserving an inferenc year = {2026}, type = {Technical report}, note = {Version 1; not peer reviewed}, + doi = {10.5281/zenodo.23022884}, url = {https://agentrust-io.com/research/confidential-handoffs/v1/} }

Version history

Version 1, September 27, 2026: Reframes the draft as a bounded software edition, records the rerun, updates dependency status and corrects two references.

-

Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.

+

Revises a discussion draft dated September 19, 2026.

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.

diff --git a/research/confidential-handoffs/v1/CITATION.cff b/research/confidential-handoffs/v1/CITATION.cff index e1207c3..e75359e 100644 --- a/research/confidential-handoffs/v1/CITATION.cff +++ b/research/confidential-handoffs/v1/CITATION.cff @@ -13,6 +13,7 @@ ], "url": "https://agentrust-io.com/research/confidential-handoffs/v1/", "license": "CC-BY-4.0", + "doi": "10.5281/zenodo.23022884", "preferred-citation": { "type": "report", "title": "Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation", diff --git a/research/confidential-handoffs/v1/citation.bib b/research/confidential-handoffs/v1/citation.bib index 6c08001..11fde1c 100644 --- a/research/confidential-handoffs/v1/citation.bib +++ b/research/confidential-handoffs/v1/citation.bib @@ -5,5 +5,6 @@ @techreport{agentrust2026confidentialhandoffs year = {2026}, type = {Technical report}, note = {Version 1; not peer reviewed}, + doi = {10.5281/zenodo.23022884}, url = {https://agentrust-io.com/research/confidential-handoffs/v1/} } diff --git a/research/confidential-handoffs/v1/index.html b/research/confidential-handoffs/v1/index.html index 896d2cd..2f28195 100644 --- a/research/confidential-handoffs/v1/index.html +++ b/research/confidential-handoffs/v1/index.html @@ -21,7 +21,8 @@ - + + @@ -67,10 +68,10 @@

Confidentiality Across Agent Handoffs: Conditions for preserving an inferenc
September 27, 2026Not peer reviewedPatent Pending

Abstract

This paper states conditions under which tool calls and agent handoffs preserve an authorized plaintext-holder boundary. This requires a protected channel bound to an appraised workload, restricted authority, enforceable downstream information-flow rules, and control over every other plaintext sink. A signature on an execution record or a valid hardware quote alone cannot establish these conditions. If a recipient cannot satisfy them, the sender must withhold the data or obtain authorization for a precisely described disclosure. This paper develops a conditional composition argument, a proposed handoff contract, and component experiments that expose failures of appraisal, supervision, and outcome inference. A composed software harness joins provisioning, diagnostic model computation, a confined agent, a mediated tool, delegated peer authentication, and exact-output disclosure. Its paired mutations expose earlier leaks despite successful final delivery; a rerun on September 27, 2026 reproduced all 36 recorded observations. All results are software results with synthetic attestation and a single operator. AgenTrust supplies relevant identity, key-release, gateway, delegation, and evidence primitives, but its present components do not demonstrate the complete property. The distinction matters most at remote tools, CPU-GPU transfers, operator-controlled key brokers, runtime changes, and audit systems.

- +

What this report contributes

A conditional composition argument and proposed handoff contract for when tool calls and delegations preserve an authorized plaintext-holder boundary.

Evidence and limits

-

The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.

+

The source package preserves the recorded inputs and results. The composed software experiment was rerun for this edition; no hardware run was repeated. No independent replication is claimed.

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

Cite this report

Imran Siddique. Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation. AgenTrust technical report, version 1, 2026.

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026confidentialhandoffs,
@@ -80,11 +81,12 @@ 

Confidentiality Across Agent Handoffs: Conditions for preserving an inferenc year = {2026}, type = {Technical report}, note = {Version 1; not peer reviewed}, + doi = {10.5281/zenodo.23022884}, url = {https://agentrust-io.com/research/confidential-handoffs/v1/} }

Version history

Version 1, September 27, 2026: Reframes the draft as a bounded software edition, records the rerun, updates dependency status and corrects two references.

-

Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.

+

Revises a discussion draft dated September 19, 2026.

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.

diff --git a/research/index.html b/research/index.html index 6de3a5c..102aaf2 100644 --- a/research/index.html +++ b/research/index.html @@ -58,7 +58,7 @@

AgenTrust Research

Identity, enforcement,
and evidence for AI agents.

Technical reports with open source, recorded experiments, and explicit limits. Read the work, inspect the evidence, and cite a specific version.

-
Research collection7 reports / Not peer reviewed
+
Research collection7 reports / Not peer reviewed

Read the evidence with the claim

These reports preserve historical designs and software evaluations. A signature, an attestation result, and an execution-completeness claim establish different properties. Each paper page identifies the evidence evaluated and the limits that remain.

For implementation, follow the current project specifications linked from each report. Paper text is available under CC BY 4.0; code retains its project license.

diff --git a/research/trace/index.html b/research/trace/index.html index 9aa1a3f..647276a 100644 --- a/research/trace/index.html +++ b/research/trace/index.html @@ -18,13 +18,13 @@ - - + + - - + + @@ -64,32 +64,33 @@
-

Technical report / Version 1

+

Technical report / Version 2

TRACE: Trust, Runtime Attestation, and Compliance Evidence (A Portable Attestation Format for AI Agent Runtime Governance)

Rishabh Poddar, Aaron Fulkerson, Imran Siddique

OPAQUE Systems

-
September 27, 2026Not peer reviewed
+
September 28, 2026Not peer reviewed

Abstract

TRACE (Trust, Runtime Attestation, and Compliance Evidence) proposes a portable record for claims about AI agent runtimes: workload identity, model, policy, data class, tool transcript, build provenance, and appraisal. It composes RATS/EAT, signatures, and transparency evidence into a format that a relying party can evaluate against its own trust policy. A valid signature establishes integrity and possession of the signing key; hardware origin additionally requires verified attestation and a binding from that evidence to the key. This technical report describes the original design and preserves the recorded software evaluation of agentrust-trace 0.2.0 and trace-tests 0.2.0. The evaluation measures canonicalization, Ed25519 signing and verification, record size, and fixture outcomes. It does not measure silicon certificate-chain appraisal or establish that the recorded runtime claims are true. The current normative specification and its implementation limits are maintained separately.

- +

What this report contributes

A portable format for runtime claims, with recorded measurements of signing, verification, record size, and conformance fixtures.

Evidence and limits

  • The recorded run used agentrust-trace 0.2.0 and trace-tests 0.2.0 on July 1, 2026. It did not measure silicon certificate-chain appraisal.
  • The missing-runtime fixture passes at Level 0 in the saved results. The cMCP fixture fails at all three levels. Those outcomes limit what the historical conformance checks establish.
  • A signature proves integrity and signing-key possession. Hardware origin requires verified attestation and key binding; inclusion in a log does not prove that every event was recorded.

The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

-

Cite this report

Rishabh Poddar; Aaron Fulkerson; Imran Siddique. TRACE: Trust, Runtime Attestation, and Compliance Evidence (A Portable Attestation Format for AI Agent Runtime Governance). AgenTrust technical report, version 1, 2026.

-

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026trace,
+

Cite this report

Rishabh Poddar; Aaron Fulkerson; Imran Siddique. TRACE: Trust, Runtime Attestation, and Compliance Evidence (A Portable Attestation Format for AI Agent Runtime Governance). AgenTrust technical report, version 2, 2026.

+

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026trace,
   title = {TRACE: Trust, Runtime Attestation, and Compliance Evidence (A Portable Attestation Format for AI Agent Runtime Governance)},
   author = {Rishabh Poddar and Aaron Fulkerson and Imran Siddique},
   institution = {AgenTrust},
   year = {2026},
   type = {Technical report},
-  note = {Version 1; not peer reviewed},
-  doi = {10.5281/zenodo.23001692},
-  url = {https://agentrust-io.com/research/trace/v1/}
+  note = {Version 2; not peer reviewed},
+  doi = {10.5281/zenodo.23024103},
+  url = {https://agentrust-io.com/research/trace/v2/}
 }
 
-

Version history

Version 1, September 27, 2026: Clarifies the signature and hardware-evidence boundary, corrects the description of saved conformance outcomes, and preserves the historical measurements.

+

Version history

Version 2, September 28, 2026: Corrects the related-work statement that transparency-log registration makes omitted events detectable, which contradicted the conclusion, and removes three en dashes. Results unchanged.

+

Version 1, September 27, 2026: Clarifies the signature and hardware-evidence boundary, corrects the description of saved conformance outcomes, and preserves the historical measurements.

Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.

-

File checksums. Published version files are retained; substantive revisions receive a new version.

+

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.

diff --git a/research/trace/v1/index.html b/research/trace/v1/index.html index 38e8240..c8cc582 100644 --- a/research/trace/v1/index.html +++ b/research/trace/v1/index.html @@ -87,7 +87,8 @@

TRACE: Trust, Runtime Attestation, and Compliance Evidence (A Portable Attes url = {https://agentrust-io.com/research/trace/v1/} } -

Version history

Version 1, September 27, 2026: Clarifies the signature and hardware-evidence boundary, corrects the description of saved conformance outcomes, and preserves the historical measurements.

+

Version history

Version 2, September 28, 2026: Corrects the related-work statement that transparency-log registration makes omitted events detectable, which contradicted the conclusion, and removes three en dashes. Results unchanged.

+

Version 1, September 27, 2026: Clarifies the signature and hardware-evidence boundary, corrects the description of saved conformance outcomes, and preserves the historical measurements.

Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.

diff --git a/research/trace/v2/CITATION.cff b/research/trace/v2/CITATION.cff new file mode 100644 index 0000000..09d677f --- /dev/null +++ b/research/trace/v2/CITATION.cff @@ -0,0 +1,45 @@ +{ + "cff-version": "1.2.0", + "message": "Cite the versioned technical report. It has not been peer reviewed.", + "type": "dataset", + "title": "TRACE: Trust, Runtime Attestation, and Compliance Evidence (A Portable Attestation Format for AI Agent Runtime Governance)", + "version": "2", + "date-released": "2026-09-28", + "authors": [ + { + "given-names": "Rishabh", + "family-names": "Poddar" + }, + { + "given-names": "Aaron", + "family-names": "Fulkerson" + }, + { + "given-names": "Imran", + "family-names": "Siddique" + } + ], + "url": "https://agentrust-io.com/research/trace/v2/", + "license": "CC-BY-4.0", + "doi": "10.5281/zenodo.23024103", + "preferred-citation": { + "type": "report", + "title": "TRACE: Trust, Runtime Attestation, and Compliance Evidence (A Portable Attestation Format for AI Agent Runtime Governance)", + "authors": [ + { + "given-names": "Rishabh", + "family-names": "Poddar" + }, + { + "given-names": "Aaron", + "family-names": "Fulkerson" + }, + { + "given-names": "Imran", + "family-names": "Siddique" + } + ], + "year": 2026, + "url": "https://agentrust-io.com/research/trace/v2/" + } +} diff --git a/research/trace/v2/SHA256SUMS b/research/trace/v2/SHA256SUMS new file mode 100644 index 0000000..a50bcf7 --- /dev/null +++ b/research/trace/v2/SHA256SUMS @@ -0,0 +1,2 @@ +e4b75dc0b2627486f2d8692193705ddf7db0fe7de225d4b1b8010fcac9382bdd paper.pdf +3f9b16068aaa22cf7280eba5b8d8a1a9a1e332ca6d5a3c81b92c08bf35577aef source.zip diff --git a/research/trace/v2/citation.bib b/research/trace/v2/citation.bib new file mode 100644 index 0000000..c5df385 --- /dev/null +++ b/research/trace/v2/citation.bib @@ -0,0 +1,10 @@ +@techreport{agentrust2026trace, + title = {TRACE: Trust, Runtime Attestation, and Compliance Evidence (A Portable Attestation Format for AI Agent Runtime Governance)}, + author = {Rishabh Poddar and Aaron Fulkerson and Imran Siddique}, + institution = {AgenTrust}, + year = {2026}, + type = {Technical report}, + note = {Version 2; not peer reviewed}, + doi = {10.5281/zenodo.23024103}, + url = {https://agentrust-io.com/research/trace/v2/} +} diff --git a/research/trace/v2/index.html b/research/trace/v2/index.html new file mode 100644 index 0000000..2070614 --- /dev/null +++ b/research/trace/v2/index.html @@ -0,0 +1,97 @@ + + + +TRACE: Trust, Runtime Attestation, and Compliance Evidence (A Portable Attestation Format for AI Agent Runtime Governance) (version 2) | AgenTrust + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +
+ + +
+

Technical report / Version 2

+

TRACE: Trust, Runtime Attestation, and Compliance Evidence (A Portable Attestation Format for AI Agent Runtime Governance)

+

Rishabh Poddar, Aaron Fulkerson, Imran Siddique

OPAQUE Systems

+
September 28, 2026Not peer reviewed
+
+

Abstract

TRACE (Trust, Runtime Attestation, and Compliance Evidence) proposes a portable record for claims about AI agent runtimes: workload identity, model, policy, data class, tool transcript, build provenance, and appraisal. It composes RATS/EAT, signatures, and transparency evidence into a format that a relying party can evaluate against its own trust policy. A valid signature establishes integrity and possession of the signing key; hardware origin additionally requires verified attestation and a binding from that evidence to the key. This technical report describes the original design and preserves the recorded software evaluation of agentrust-trace 0.2.0 and trace-tests 0.2.0. The evaluation measures canonicalization, Ed25519 signing and verification, record size, and fixture outcomes. It does not measure silicon certificate-chain appraisal or establish that the recorded runtime claims are true. The current normative specification and its implementation limits are maintained separately.

+ +

What this report contributes

A portable format for runtime claims, with recorded measurements of signing, verification, record size, and conformance fixtures.

+

Evidence and limits

  • The recorded run used agentrust-trace 0.2.0 and trace-tests 0.2.0 on July 1, 2026. It did not measure silicon certificate-chain appraisal.
  • The missing-runtime fixture passes at Level 0 in the saved results. The cMCP fixture fails at all three levels. Those outcomes limit what the historical conformance checks establish.
  • A signature proves integrity and signing-key possession. Hardware origin requires verified attestation and key binding; inclusion in a log does not prove that every event was recorded.
+

The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.

+

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

+

Cite this report

Rishabh Poddar; Aaron Fulkerson; Imran Siddique. TRACE: Trust, Runtime Attestation, and Compliance Evidence (A Portable Attestation Format for AI Agent Runtime Governance). AgenTrust technical report, version 2, 2026.

+

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026trace,
+  title = {TRACE: Trust, Runtime Attestation, and Compliance Evidence (A Portable Attestation Format for AI Agent Runtime Governance)},
+  author = {Rishabh Poddar and Aaron Fulkerson and Imran Siddique},
+  institution = {AgenTrust},
+  year = {2026},
+  type = {Technical report},
+  note = {Version 2; not peer reviewed},
+  doi = {10.5281/zenodo.23024103},
+  url = {https://agentrust-io.com/research/trace/v2/}
+}
+
+

Version history

Version 2, September 28, 2026: Corrects the related-work statement that transparency-log registration makes omitted events detectable, which contradicted the conclusion, and removes three en dashes. Results unchanged.

+

Version 1, September 27, 2026: Clarifies the signature and hardware-evidence boundary, corrects the description of saved conformance outcomes, and preserves the historical measurements.

+

Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.

+

File checksums. Published version files are retained; substantive revisions receive a new version.

+

Questions and corrections

Open an issue in the project repository and identify the report version and section.

+ + + diff --git a/research/trace/v2/paper.pdf b/research/trace/v2/paper.pdf new file mode 100644 index 0000000..3721b58 Binary files /dev/null and b/research/trace/v2/paper.pdf differ diff --git a/research/trace/v2/source.zip b/research/trace/v2/source.zip new file mode 100644 index 0000000..6dc1cb6 Binary files /dev/null and b/research/trace/v2/source.zip differ diff --git a/research/weight-custody-manifest/index.html b/research/weight-custody-manifest/index.html index c001a1f..576062f 100644 --- a/research/weight-custody-manifest/index.html +++ b/research/weight-custody-manifest/index.html @@ -71,7 +71,7 @@

Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary

What this report contributes

A portable custody contract binding exact weights, measured workload, fresh channel-bound release, renewable authority, terminal evidence and derivative lineage.

Evidence and limits

  • The evaluated version is WCM 0.28.0 (commit 2acedfa). Its software results were rerun on September 27, 2026 with the same counts: 618 passed, 3 skipped, 91 of 91 conformance vectors. The SEV-SNP hardware runs were not repeated.
  • Advisory GHSA-j665-99rh-w85h affects the evaluated version: the key broker did not require GPU confidential-compute mode before release. The fail-closed result does not cover GPU mode.
  • The measured Azure SEV-SNP platform does not enable ciphertext hiding, so the cryptographic-custody claim does not hold there against a hypervisor-privileged operator. Against an operator who physically owns the machine, WCM claims accountability, not custody.
-

The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.

+

The source package preserves the recorded inputs and results. The software results were rerun at the evaluated commit for this edition; the hardware runs were not repeated. No independent replication is claimed.

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

Cite this report

Imran Siddique. Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary Model Weights. AgenTrust technical report, version 1, 2026.

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026weightcustodymanifest,
@@ -86,7 +86,7 @@ 

Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary }

Version history

Version 1, September 27, 2026: Adds a post-evaluation findings section, corrects the descriptions of the three skipped tests and of the memory-sweep receipt, fixes two citations, and records a software rerun at the evaluated commit.

-

Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.

+

Revises a manuscript dated September 3, 2026.

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.

diff --git a/research/weight-custody-manifest/v1/index.html b/research/weight-custody-manifest/v1/index.html index 6881172..666e237 100644 --- a/research/weight-custody-manifest/v1/index.html +++ b/research/weight-custody-manifest/v1/index.html @@ -71,7 +71,7 @@

Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary

What this report contributes

A portable custody contract binding exact weights, measured workload, fresh channel-bound release, renewable authority, terminal evidence and derivative lineage.

Evidence and limits

  • The evaluated version is WCM 0.28.0 (commit 2acedfa). Its software results were rerun on September 27, 2026 with the same counts: 618 passed, 3 skipped, 91 of 91 conformance vectors. The SEV-SNP hardware runs were not repeated.
  • Advisory GHSA-j665-99rh-w85h affects the evaluated version: the key broker did not require GPU confidential-compute mode before release. The fail-closed result does not cover GPU mode.
  • The measured Azure SEV-SNP platform does not enable ciphertext hiding, so the cryptographic-custody claim does not hold there against a hypervisor-privileged operator. Against an operator who physically owns the machine, WCM claims accountability, not custody.
-

The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.

+

The source package preserves the recorded inputs and results. The software results were rerun at the evaluated commit for this edition; the hardware runs were not repeated. No independent replication is claimed.

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

Cite this report

Imran Siddique. Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary Model Weights. AgenTrust technical report, version 1, 2026.

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026weightcustodymanifest,
@@ -86,7 +86,7 @@ 

Weight Custody Manifest: Portable, Attestation-Gated Custody for Proprietary }

Version history

Version 1, September 27, 2026: Adds a post-evaluation findings section, corrects the descriptions of the three skipped tests and of the memory-sweep receipt, fixes two citations, and records a software rerun at the evaluated commit.

-

Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.

+

Revises a manuscript dated September 3, 2026.

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.

diff --git a/sitemap.xml b/sitemap.xml index 498296c..b82665f 100644 --- a/sitemap.xml +++ b/sitemap.xml @@ -22,6 +22,7 @@ https://agentrust-io.com/research/confidential-handoffs/v1/ https://agentrust-io.com/research/trace/ https://agentrust-io.com/research/trace/v1/ + https://agentrust-io.com/research/trace/v2/ https://agentrust-io.com/research/weight-custody-manifest/ https://agentrust-io.com/research/weight-custody-manifest/v1/ https://agentrust-io.com/telemetry/ diff --git a/tools/build-research.py b/tools/build-research.py index da5ef72..d9c03c3 100644 --- a/tools/build-research.py +++ b/tools/build-research.py @@ -1,5 +1,6 @@ """Build the research library from reviewed metadata and frozen paper artifacts.""" import argparse +import datetime import hashlib from html import escape as esc import json @@ -20,7 +21,7 @@ def shell(title, description, path, body, scholarly=None): if scholarly: p = scholarly tags = [('citation_title', p['title']), ('citation_publication_date', p['date'].replace('-', '/')), - ('citation_pdf_url', BASE + f'/research/{p["slug"]}/v1/paper.pdf')] + ('citation_pdf_url', BASE + f'/research/{p["slug"]}/v{p["version"]}/paper.pdf')] tags += [('citation_author', author) for author in p['authors']] if p.get('doi'): tags.append(('citation_doi', p['doi'])) @@ -28,11 +29,11 @@ def shell(title, description, path, body, scholarly=None): structured = {'@context': 'https://schema.org', '@type': 'ScholarlyArticle', 'headline': p['title'], 'abstract': p['abstract'], 'url': BASE + path, 'author': [{'@type': 'Person', 'name': a} for a in p['authors']], - 'datePublished': p['date'], 'version': '1', + 'datePublished': p['date'], 'version': str(p['version']), 'creativeWorkStatus': 'Technical report; not peer reviewed', 'license': 'https://creativecommons.org/licenses/by/4.0/', 'encoding': {'@type': 'MediaObject', 'encodingFormat': 'application/pdf', - 'contentUrl': BASE + f'/research/{p["slug"]}/v1/paper.pdf'}} + 'contentUrl': BASE + f'/research/{p["slug"]}/v{p["version"]}/paper.pdf'}} if p.get('doi'): structured['identifier'] = 'https://doi.org/' + p['doi'] return f''' @@ -75,64 +76,95 @@ def citation(p): f' title = {{{p["title"]}}},\n' f' author = {{{" and ".join(p["authors"])}}},\n' ' institution = {AgenTrust},\n year = {2026},\n' - ' type = {Technical report},\n note = {Version 1; not peer reviewed},\n' - + doi + f' url = {{{BASE}/research/{p["slug"]}/v1/}}\n' + '}\n') - - -def paper_page(p, version=False): - slug=p['slug'] - path=f'/research/{slug}/' + ('v1/' if version else '') - artifact=f'/research/{slug}/v1/' - patent = 'Patent Pending' if p['patent_pending'] else '' - archive = f'Archive and DOI' if p.get('doi') else '' - body=f''' -

Technical report / Version 1

-

{esc(p['title'])}

-

{esc(', '.join(p['authors']))}

OPAQUE Systems

-
September 27, 2026Not peer reviewed{patent}
+ f' type = {{Technical report}},\n note = {{Version {p["version"]}; not peer reviewed}},\n' + + doi + f' url = {{{BASE}/research/{p["slug"]}/v{p["version"]}/}}\n' + '}\n') + + +def human_date(iso): + d=datetime.date.fromisoformat(iso) + return f'{d.strftime("%B")} {d.day}, {d.year}' + + +def versions(p): + """Published versions, oldest first. An entry without a list is a single version 1.""" + if p.get('versions'): + return p['versions'] + v={'version':1,'date':p['date'],'pages':p['pages'],'changes':p['changes'],'sha256':p['sha256']} + if p.get('doi'): + v['doi']=p['doi'] + return [v] + + +def at(p, v): + """The paper's metadata as of one published version.""" + q={k:val for k,val in p.items() if k not in ('doi','date','pages','changes','sha256','versions')} + q.update(v) + return q + + +def paper_page(p, v=None): + history=versions(p) + q=at(p, v or history[-1]) + slug=q['slug'] + n=q['version'] + path=f'/research/{slug}/' + (f'v{n}/' if v else '') + artifact=f'/research/{slug}/v{n}/' + patent = 'Patent Pending' if q['patent_pending'] else '' + archive = f'Archive and DOI' if q.get('doi') else '' + origin = f'

{esc(q["origin"])}

\n' if q.get('origin') else '' + evidence = q.get('evidence_note', 'No new experiment run or independent replication is claimed for this edition.') + rows=''.join(f'

Version {h["version"]}, {human_date(h["date"])}: {esc(h["changes"])}

\n' for h in reversed(history)) + body=f''' +

Technical report / Version {n}

+

{esc(q['title'])}

+

{esc(', '.join(q['authors']))}

OPAQUE Systems

+
{human_date(q['date'])}Not peer reviewed{patent}
-

Abstract

{esc(p['abstract'])}

- -

What this report contributes

{esc(p['contribution'])}

-

Evidence and limits

    {''.join('
  • '+esc(item)+'
  • ' for item in p['limits'])}
-

The source package preserves the recorded inputs and results. No new experiment run or independent replication is claimed for this edition.

-

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

-

Cite this report

{esc('; '.join(p['authors']))}. {esc(p['title'])}. AgenTrust technical report, version 1, 2026.

-

Download BibTeX / Download CITATION.cff

{esc(citation(p))}
-

Version history

Version 1, September 27, 2026: {esc(p['changes'])}

-

Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.

-

File checksums. Published version files are retained; substantive revisions receive a new version.

-

Questions and corrections

Open an issue in the project repository and identify the report version and section.

''' - title=p['title'] + (' (version 1)' if version else '') - return shell(title,p['description'],path,body,p) +

Abstract

{esc(q['abstract'])}

+ +

What this report contributes

{esc(q['contribution'])}

+

Evidence and limits

    {''.join('
  • '+esc(item)+'
  • ' for item in q['limits'])}
+

The source package preserves the recorded inputs and results. {esc(evidence)}

+

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

+

Cite this report

{esc('; '.join(q['authors']))}. {esc(q['title'])}. AgenTrust technical report, version {n}, 2026.

+

Download BibTeX / Download CITATION.cff

{esc(citation(q))}
+

Version history

{rows}{origin}

File checksums. Published version files are retained; substantive revisions receive a new version.

+

Questions and corrections

Open an issue in the project repository and identify the report version and section.

''' + title=q['title'] + (f' (version {n})' if v else '') + return shell(title,q['description'],path,body,q) def generate(): papers=json.loads((ROOT/'data/research.json').read_text(encoding='utf-8'))['papers'] outputs={} for p in papers: - folder=ROOT/'research'/p['slug']/'v1' - for filename in ('paper.pdf','source.zip'): - file=folder/filename - if not file.is_file(): - raise ValueError(f'Missing release artifact: {file}') - if hashlib.sha256(file.read_bytes()).hexdigest() != p['sha256'][filename]: - raise ValueError(f'Frozen artifact changed: {file}. Create a new version instead.') + for v in versions(p): + q=at(p, v) + folder=ROOT/'research'/p['slug']/f'v{v["version"]}' + for filename in ('paper.pdf','source.zip'): + file=folder/filename + if not file.is_file(): + raise ValueError(f'Missing release artifact: {file}') + if hashlib.sha256(file.read_bytes()).hexdigest() != v['sha256'][filename]: + raise ValueError(f'Frozen artifact changed: {file}. Create a new version instead.') + outputs[folder/'index.html']=paper_page(p,v) + outputs[folder/'citation.bib']=citation(q) + cff={'cff-version':'1.2.0','message':'Cite the versioned technical report. It has not been peer reviewed.', + 'type':'dataset','title':q['title'],'version':str(v['version']),'date-released':v['date'], + 'authors':[{'given-names':' '.join(a.split()[:-1]),'family-names':a.split()[-1]} for a in q['authors']], + 'url':BASE+f'/research/{p["slug"]}/v{v["version"]}/','license':'CC-BY-4.0'} + if v.get('doi'): + cff['doi']=v['doi'] + # JSON is also valid YAML; the preferred citation identifies the document type. + cff['preferred-citation']={'type':'report','title':q['title'],'authors':cff['authors'], + 'year':2026,'url':cff['url']} + outputs[folder/'CITATION.cff']=json.dumps(cff,indent=2)+'\n' + outputs[folder/'SHA256SUMS']=''.join(v['sha256'][f]+' '+f+'\n' for f in ('paper.pdf','source.zip')) outputs[ROOT/'research'/p['slug']/'index.html']=paper_page(p) - outputs[folder/'index.html']=paper_page(p,True) - outputs[folder/'citation.bib']=citation(p) - cff={'cff-version':'1.2.0','message':'Cite the versioned technical report. It has not been peer reviewed.', - 'type':'dataset','title':p['title'],'version':'1','date-released':p['date'], - 'authors':[{'given-names':' '.join(a.split()[:-1]),'family-names':a.split()[-1]} for a in p['authors']], - 'url':BASE+f'/research/{p["slug"]}/v1/','license':'CC-BY-4.0'} - if p.get('doi'): - cff['doi']=p['doi'] - # JSON is also valid YAML; the preferred citation identifies the document type. - cff['preferred-citation']={'type':'report','title':p['title'],'authors':cff['authors'], - 'year':2026,'url':cff['url']} - outputs[folder/'CITATION.cff']=json.dumps(cff,indent=2)+'\n' - outputs[folder/'SHA256SUMS']=''.join(p['sha256'][f]+' '+f+'\n' for f in ('paper.pdf','source.zip')) - cards=''.join(f'''''' for p in papers) + def card(p): + latest=versions(p)[-1] + return f'''

{esc(p['topic'])}

{esc(p['title'])}

{esc(p['contribution'])}

{esc(', '.join(p['authors']))}

Version {latest['version']} / {human_date(latest['date'])} / Technical report

Read the report
''' + cards=''.join(card(p) for p in papers) body=f'''

AgenTrust Research

Identity, enforcement,
and evidence for AI agents.

Technical reports with open source, recorded experiments, and explicit limits. Read the work, inspect the evidence, and cite a specific version.

Research collection{len(papers)} reports / Not peer reviewed
{cards}

Read the evidence with the claim

These reports preserve historical designs and software evaluations. A signature, an attestation result, and an execution-completeness claim establish different properties. Each paper page identifies the evidence evaluated and the limits that remain.

For implementation, follow the current project specifications linked from each report. Paper text is available under CC BY 4.0; code retains its project license.

'''