Don't trust us. Check the source.
The product's thesis is verify, don't trust. We hold ourselves to it. Every credential below is one click from the authority that owns it, the public docket, the patent register, the package index, not a screenshot or a summary.
The official artifacts, and how to check each one
Everything we publish, in one table: the canonical URL, the account that publishes it, and the authenticity check you can run yourself. The account mapping, stated plainly: the npm publisher account “attestedgovernance” publishes the scope @attested-intelligence; the GitHub org is “attestedintelligence”; the PyPI account is “attested-intelligence”. Each check below was executed between 2026-07-01 and 2026-07-03; attestation state can change, so run the checks yourself.
| Artifact | Canonical URL | Publishing account | Authenticity check |
|---|---|---|---|
| This site | attestedintelligence.com | Attested Intelligence Holdings LLC; deployed from the company GitHub org “attestedintelligence” | HTTPS on the canonical domain. Artifacts it asks you to trust are pinned by SHA-256 where offered (see the vectors row below). |
| VerifyBundle | verifybundle.com | Attested Intelligence Holdings LLC (same publisher, separate product surface) | Its /standard page pins the offline verifier, spec, and conformance vectors by SHA-256. Recompute after downloading and compare. |
| npm: @attested-intelligence/aga-mcp-server | www.npmjs.com/package/@attested-intelligence/aga-mcp-server | npm publisher account “attestedgovernance” publishes the scope “@attested-intelligence” | npm audit signatures. Registry signatures verify, and 3.3.3 carries SLSA provenance attestations (checked 2026-07-02). |
| npm: @attested-intelligence/aga-verify | www.npmjs.com/package/@attested-intelligence/aga-verify | npm publisher account “attestedgovernance” publishes the scope “@attested-intelligence” | npm audit signatures. Registry signatures verify, and 2.1.1 carries SLSA provenance attestations (checked 2026-07-02). |
| PyPI: aga-governance | pypi.org/project/aga-governance/ | PyPI account “attested-intelligence” | PyPI JSON version check: fetch pypi.org/pypi/aga-governance/json and compare the listed sha256 digests to your download. Latest 0.2.6; no PEP 740 attestations yet (checked 2026-07-06). |
| Gateway demo endpoint | aga-mcp-gateway.attested-intelligence.workers.dev/bundle | Cloudflare Workers deployment (attested-intelligence.workers.dev) | HTTPS plus the pinned verifier. curl the /bundle endpoint and verify the result offline against the demo gateway signing key (c21d3d2def30…63584d0c, published in full on /verify and from the gateway /pubkey endpoint): aga-verify bundle.json --pubkey <key> emits a canonical evidence bundle that passes all checks (checked 2026-07-03). This key signs the live endpoint and is distinct from the sample-bundle key. The bundle is also persisted and retrievable by content hash at /bundle/{merkle_root}. |
| Conformance vectors download | attestedintelligence.com/downloads/aga-conformance-vectors.zip | Company-authored, published on this site; same corpus as the GitHub org “attestedintelligence” repository | Recompute the SHA-256 and compare to the trust root pinned on /spec (fd125d70a1b4…149dc, 32,169 bytes). The corpus covers the classical Ed25519 profile; the post-quantum composite is cross-verified in the reference implementation. |
Regulatory and standards engagement
Submissions to public dockets you can read in full at the source, in their original filed text.
NIST RFI public comment
Our comment on AI agent security, filed to the official federal docket. Read the exact text there.
regulations.gov · Comment NIST-2025-0035-0211
NIST docket NIST-2025-0035
The full public docket the comment was filed to, holding every submission from every responding party.
regulations.gov · Docket NIST-2025-0035
CoSAI WS4 contribution
Our MCP security contribution to the OASIS Coalition for Secure AI workstream 4, in the open repository.
github.com · cosai-oasis/ws4
NCCoE AI Agent Identity response
Our response to the NIST NCCoE call for AI agent identity, with the submitted PDF on file.
attestedintelligence.com/diligence
Patent and entity, on the public registers
First-party filings whose existence and status you can confirm on the issuing authority's own system.
USPTO patent application 19/433,835
Patent pending on the inseparable seal, capture, and prove architecture. Filing details on /patent.
USPTO App. No. 19/433,835 · Patent Pending
Wordmark, USPTO TSDR
The Attested Intelligence wordmark on the USPTO Trademark Status and Document Retrieval system, by serial number.
tsdr.uspto.gov · Serial No. 99677085
Illinois entity
Attested Intelligence Holdings LLC, on the Illinois Secretary of State business register (File No. 17233815).
ilsos.gov · File No. 17233815
The reference implementation, published
Install it and produce your own evidence, then verify that evidence with the same in-browser verifier the site uses.
npm: aga-mcp-server
The published reference MCP server: public, versioned, and installable from the npm registry today.
npmjs.com · @attested-intelligence/aga-mcp-server
PyPI: aga-governance
The Python distribution of the same governance tooling, published on the public PyPI index.
pypi.org · aga-governance
The in-browser verifier
Drag a bundle in, watch six cryptographic checks run client-side, then flip a byte: PASS turns FAIL.
attestedintelligence.com/verify
VerifyBundle
A public tool for hybrid post-quantum records: seal a file, then verify it offline and independently.
verifybundle.com
The argument, written down
The Attested Governance paper
The full architecture and threat model, in long form, with the inseparability argument and the failure-mode analysis.
attestedintelligence.com/diligence
Standards and schema
The 15-field receipt schema, the JSON canonicalization (JCS-lineage) rules, and the verification algorithm: six checks, seven with a pinned issuer key.
attestedintelligence.com/standards
Trust scope
What the public artifacts prove, and the five things they do NOT prove, named honestly with the irreducible residuals.
attestedintelligence.com/trust