Tamper-evident audit trails for AI agents — Ed25519-signed, hash-chained, EU AI Act ready.
io.github.sundsoffice-tech/ai-audit-trail — MCP Server
This MCP server provides tamper-evident audit trails for AI agents. The project description specifies Ed25519-signed, hash-chained records intended for AI compliance contexts, with topics covering cryptography, governance, and privacy-related handling such as PII redaction.
🛠️ Key Features
Ed25519-signed audit trails
Hash-chained tamper evidence
Compliance-oriented audit record design
Topics include Merkle tree, ISO 42001, and NIST AI RMF
Mentions decision receipts and agent audit
🚀 Use Cases
AI agent auditing for compliance and governance
Creating decision receipts for ML/MLOps workflows
Supporting EU AI Act readiness
Audit logging aligned with GDPR-related concerns
⚡ Developer Benefits
Cryptography-focused primitives for audit integrity (ed25519, hash-chain)
Compliance-aligned frameworks referenced via topics (EU AI Act, ISO 42001, NIST AI RMF)
Python ecosystem tagging in topics for implementation alignment
⚠️ Limitations
No MCP tool names or concrete interface details are provided in the available data
The readme excerpt is truncated, so exact server capabilities cannot be fully verified here
Prove what your AI did, why, and that nobody changed the record.
Tamper-evident Decision Receipts with Ed25519 signatures, SHA-256 hash-chains,
and formal compliance mappings. No blockchain, no SaaS, no lock-in.
Self-hosted, offline-verifiable, Python-native.
Why this exists
The EU AI Act becomes mandatory for high-risk AI systems in August 2026. It requires tamper-evident logs proving every decision was made correctly (Art. 12). Most teams are solving this with normal logging — which is neither tamper-evident nor legally defensible in an audit.
ai-audit-trail closes this gap with cryptographic receipts that any auditor can verify offline, without accessing your systems. Same principle as a blockchain — without the blockchain overhead, the SaaS dependency, or the vendor lock-in.
Who is this for
Regulated AI teams (FinTech, HealthTech, LegalTech, InsurTech) who must prove compliance
Enterprise platform teams deploying LLM agents with tool access
Security and compliance officers who need audit-ready evidence packages
Developers who want pip install and 3 lines of code, not a platform migration
What this library provides
ai-audit-trail provides the technical building blocks that support EU AI Act, ISO 42001, and NIST AI RMF compliance. It does not, by itself, guarantee regulatory compliance — compliance is an organizational obligation that extends beyond any single software component. See our Shared Responsibility Model below.
Track WHERE every piece of information came from — proves a decision was not influenced by prompt injection.
python
from ai_audit.provenance import ProvenanceChain, ProvenanceRecord, SourceType
chain = ProvenanceChain(receipt_id="r1", tenant_id="acme")
chain.add(ProvenanceRecord(source_type=SourceType.SYSTEM, source_id="prompt", trust_level=1.0, content_hash="..."))
chain.add(ProvenanceRecord(source_type=SourceType.DOCUMENT, source_id="doc-123", trust_level=0.8, content_hash="..."))
chain.add(ProvenanceRecord(source_type=SourceType.UNKNOWN, source_id="???", trust_level=0.0, content_hash="..."))
summary = chain.trust_summary()
print(summary.system_grounded) # True — has SYSTEM sourceprint(summary.potentially_injected) # True — has UNKNOWN sourceprint(summary.min_trust) # 0.0 — weakest link
High-Throughput Architecture
Merkle-Tree Batch Sealing (RFC 6962)
Chain-of-Roots instead of chain-of-receipts — O(log N) verification per batch.
python
from ai_audit.batch import MerkleBatcher
batcher = MerkleBatcher(tenant_id="acme", private_key=key, max_batch_size=2048)
for receipt in receipts:
seal = batcher.add(receipt.receipt_id, receipt.seal_payload())
if seal: # Auto-flushed at 2048 receiptsprint(f"Batch sealed: {seal.merkle_root[:16]}...")
assert batcher.verify_chain_of_roots(key.verify_key)
Chain Epochs / Rollover
Prevent unbounded chain growth. Old epochs can be archived or deleted.
python
from ai_audit.epochs import EpochManager
mgr = EpochManager(tenant_id="acme", private_key=key, max_epoch_size=10_000)
for receipt in receipts:
seal = mgr.add_receipt(receipt) # Auto-seals at 10k
mgr.seal_epoch() # Or explicit rolloverassert mgr.verify_epoch_chain(key.verify_key)
Ring-Buffer with Backpressure
Bounded buffer for high-throughput ingestion — fail-closed, no silent data loss.
python
from ai_audit.buffer import AuditBuffer, AuditBufferFullError
buffer = AuditBuffer(maxsize=50_000) # ~5 seconds at 10k req/stry:
buffer.put(receipt)
except AuditBufferFullError:
# Backpressure — reject the request rather than lose audit datapass
batch = buffer.drain(max_items=2048)
Storage Backend ABCs
Pluggable persistence — bring your own database.
python
from ai_audit.storage import StorageBackend, InMemoryBackend
# Use the reference implementation for dev/test
backend = InMemoryBackend(max_receipts=50_000)
# Or implement your own:classPostgresBackend(StorageBackend):
defwrite_receipt(self, receipt): ...
defread_receipt(self, receipt_id): ...
defquery_by_tenant(self, tenant_id, limit=100): ...
defhealthcheck(self) -> bool: ...
OpenTelemetry Instrumentation
Native metrics for SRE dashboards — graceful no-op without OTel SDK.