Skip to main content

Provenance

Check the source.
Know its limits.

Find the official artifacts, publishing accounts and records behind our public claims. A reachable URL is not proof of authenticity, a registry attestation is not a security audit, and our own statement is not independent confirmation.

Artifact map

Where each artifact comes from.

These are dated observations, not live monitoring. Each entry separates its publishing account, authenticity check and recorded HTTP result. HTTP 403 means the script was refused; it does not confirm what a browser will see. Registry and attestation state can change after the date shown.

This site

attestedintelligence.com

Publishing account
Attested Intelligence Holdings LLC; deployed from the company GitHub account “attestedintelligence”
Check and scope
HTTPS on the canonical domain. Artifacts it asks you to trust are pinned by SHA-256 where offered (see the vectors row below).
Recorded HTTP result
200 · 2026-09-25

VerifyBundle

verifybundle.com

Publishing account
Attested Intelligence Holdings LLC (same publisher, separate product surface)
Check and scope
Its /standard page pins the current offline verifier, specification and vectors by SHA-256 and retains the previous verifier bytes. The September 30 parser and trust-input release passed 548 isolated tests, 48 public layouts and 27 public synthetic worker controls. Those checks do not qualify production time-service operations or physical iPhone behavior. Recompute hashes after downloading.
Recorded HTTP result
200 · 2026-09-25

npm: @attested-intelligence/aga-mcp-server

www.npmjs.com/package/@attested-intelligence/aga-mcp-server

Publishing account
npm publisher account “attestedgovernance” publishes the scope “@attested-intelligence”
Check and scope
October 3 release readback: current version 3.6.6 matches both isolated Node 22 and Node 24 archives (SHA-256 3cb8782e08fa9def5f3dcecbe0454a69c284995024d68a5995de2d6d2ffdb980). Its SLSA provenance statement names source commit fec28431ca1561bab80cd37114dd8b0d1c7be5c4 with a matching archive digest. npm 11.21.0 audit signatures verified the registry signature and provenance attestation in a disposable consumer install; the verified subject and source match this release. The September 30 provenance observations for 3.6.5 and 3.6.4 remain historical; manually published 3.6.3 has no SLSA attestation. Build provenance does not establish runtime safety.
Recorded HTTP result
200 · 2026-09-25

npm: @attested-intelligence/aga-verify

www.npmjs.com/package/@attested-intelligence/aga-verify

Publishing account
npm publisher account “attestedgovernance” publishes the scope “@attested-intelligence”
Check and scope
Current version 2.2.3 was manually published September 30, 2026. The downloaded archive is byte-identical to the inspected release tarball (SHA-256 f7174a66426f236e483383798db27d87dbb582e5d6b49d6e65c6d46f6973e642); its public source commit is 48ca8f4245e0147aea4a2586d3003ea2274b0792. No SLSA provenance attestation is exposed for 2.2.3. npm audit signatures verified the registry signature of this release on September 30. The prior verifier’s SLSA provenance observation is dated September 25 and does not transfer to this manual publication.
Recorded HTTP result
200 · 2026-09-25

GitHub: aga-mcp-server (the canonical public repository)

github.com/attestedintelligence/aga-mcp-server

Publishing account
GitHub account “attestedintelligence”; the only public repository under it. The AGA monorepo is private and nothing on this site links to it.
Check and scope
The commit that built a release is named by its npm provenance attestation, not by a tag: the September 25 inventory found attestations for 15 of the 27 versions then published. Version 3.6.3 has none; the September 30 readback found matching source and archive subjects for 3.6.4 and 3.6.5, and REPRODUCIBILITY.md records the version-specific history. Read it with curl -s https://registry.npmjs.org/-/npm/v1/attestations/@attested-intelligence%2f<name>@<version> and decode the SLSA statement’s resolvedDependencies[].digest.gitCommit, as REPRODUCIBILITY.md in the repository explains; tags are a convenience and do not cover every version. 3.6.0’s attestation names 315d5c6, which the tag v3.6.0 also names; that commit’s CI run reports 428 tests across 47 files (recomputed 2026-09-21) and is marked failed only because its post-publish attestation gate timed out, after the publish succeeded.
Recorded HTTP result
200 · 2026-09-25

PyPI: aga-governance

pypi.org/project/aga-governance/

Publishing account
PyPI account “attested-intelligence”
Check and scope
PyPI JSON version check: fetch pypi.org/pypi/aga-governance/json and compare the listed sha256 digests to your download. Latest 0.3.2, published by GitHub Actions trusted publishing from a private repository, which its PEP 740 attestations name; the sdist carries the complete library source under Apache-2.0. Read the attestations at pypi.org/integrity/aga-governance/0.3.2/<filename>/provenance (0.3.0 and 0.2.6 are yanked; 0.2.6 and earlier have no attestations; attestations checked September 23, 2026, yank status September 28, 2026).
Recorded HTTP result
200 · 2026-09-25

Gateway demo endpoint

https://aga-mcp-gateway.attested-intelligence.workers.dev/bundle

Publishing account
Cloudflare Workers deployment (attested-intelligence.workers.dev)
Check and scope
Historical observation, September 21, 2026: /bundle returned HTTP 200, /pubkey matched the pinned demo key (c21d3d2def30…63584d0c, published in full on /verify), and aga-verify reported VERIFIED with provenance. The live endpoint creates and persists a bundle, with retrieval by content hash at /bundle/{merkle_root}; it is not a read-only status probe. Use the static sample below for evaluation. The live signing key differs from the sample key, and this hyphenated host is the only official gateway. This record does not establish current availability or independent issuer identity.
Recorded HTTP result
200 · 2026-09-25

Sample evidence bundle

attestedintelligence.com/sample-bundle.json

Publishing account
Company-authored, published on this site; signed under the sample-bundle signing key (b900a315…8ebe) shown on /verify
Check and scope
Recompute the SHA-256 and compare: 83b2cb8d22fa…9263c3c0 (6,460 bytes; the full value is printed on /verify, under the Upload Bundle tab). Verify it in the browser at /verify or offline with aga-verify.
Recorded HTTP result
200 · 2026-09-25

Conformance vectors download

attestedintelligence.com/downloads/aga-conformance-vectors.zip

Publishing account
Company-authored, published on this site: a 2026-07-31 snapshot of the receipt specification's conformance files. Its vectors and harness are byte-identical to the aga-receipt-spec folder of the aga-mcp-server repository at v3.6.0 (unchanged at v3.6.2); its reference verifier, schemas and construction document are earlier versions, and its LICENSE was replaced on 2026-09-25 with the Apache-2.0 text (details on /spec)
Check and scope
Recompute the SHA-256 and compare to the trust root pinned on /spec (5e1fa147e5bc…07bfd, 32,575 bytes). The corpus covers the classical Ed25519 profile; the post-quantum composite is cross-verified in the reference implementation.
Recorded HTTP result
200 · 2026-09-25

Public Record

Regulatory and standards engagement

Our filed comments and our own analysis. The NIST comment is on the federal docket in its filed text; the CoSAI analysis and the NCCoE response are published on this site.

NIST RFI public comment

Our comment on AI agent security, filed to the official federal docket. Read the exact text there.

regulations.gov · Comment NIST-2025-0035-0211

NIST docket NIST-2025-0035

The full public docket the comment was filed to, holding every submission from every responding party.

regulations.gov · Docket NIST-2025-0035

CoSAI WS4 threat analysis

Our March 2026 analysis of the MCP threat taxonomy in the OASIS Coalition for Secure AI workstream 4 white paper (approved 8 January 2026). It is our own document, not a CoSAI publication, and the white paper does not credit us.

attestedintelligence.com/diligence

NCCoE AI Agent Identity response

Our public comment on the NIST NCCoE concept paper on software and AI agent identity and authorization, with the submitted PDF on file.

attestedintelligence.com/diligence

Intellectual Property

Patent, wordmark and entity

First-party filings. The wordmark and the entity can be confirmed on the issuing authority's own system. A patent application appears on the USPTO's public systems only once it is published, so this one's filing details are on our own /patent page.

USPTO patent application 19/433,835

Patent pending. The application number, filing date and status are on /patent.

USPTO App. No. 19/433,835 · Patent Pending

Wordmark, USPTO TSDR

The Attested Intelligence wordmark on the USPTO Trademark Status and Document Retrieval system, by serial number.

tsdr.uspto.gov · Serial No. 99677085

Illinois entity

Attested Intelligence Holdings LLC, on the Illinois Secretary of State business register (File No. 17233815).

ilsos.gov · File No. 17233815

Runnable Code

The reference implementation, published

Start with the static sample and verifier. Runtime evaluation is a separate task: it needs an approved isolated environment and review of the known implementation limits on /security. A public package is not a production-readiness assurance.

npm: aga-mcp-server

The published reference MCP server: public, versioned, and installable from the npm registry today.

npmjs.com · @attested-intelligence/aga-mcp-server

PyPI: aga-governance

The Python verifier and in-process recorder (no policy evaluation), published on the public PyPI index.

pypi.org · aga-governance

The in-browser verifier

Drag a bundle in, watch six cryptographic checks run client-side, then change a signed field: PASS turns FAIL.

attestedintelligence.com/verify

VerifyBundle

A separate file-sealing product with a hybrid signature profile, its own record format and an offline verifier. It is not an AGA bundle viewer.

verifybundle.com

The Work

The argument, written down

The Attested Governance paper

A dated record, kept as published: the full architecture and threat model in long form, with the inseparability argument and the failure-mode analysis. The current statement of what ships is on /trust.

attestedintelligence.com/diligence

Standards and schema

The 15-field receipt schema, the JSON canonicalization (JCS-lineage) rules, and the verification algorithm: six checks, seven with a pinned issuer key.

attestedintelligence.com/spec#receipt-spec

Trust scope

What the public artifacts prove, what they do not prove, and the irreducible residuals.

attestedintelligence.com/trust