01 / 08
01 / 08  ·  COVER
ἀλήθεια

alethech

verifiable agent continuity protocol

230 tests· 8 mutation paths· v0.7.0· MIT
02 / 08  ·  WHAT IS ALETHECH
what is alethech

definition + the property

alethech is a Python package that provides cryptographically verifiable memory continuity for AI agents.

It lets an agent sign its memory commits with Ed25519, link them in a Merkle DAG, rotate keys without losing identity, and prove to a third party that its memory was not tampered with.

The protocol does NOT prove that the agent's claims are true — only that they were signed by the identity that claims them.

the protocol does NOT prove claims are true — only that they were signed.

03 / 08  ·  HOW IT WORKS
how it works

dag + six steps

cutoff / key rotation GENESIS key-000 C1 key-000 cutoff_head C2 key-001 post-rotation C3 key-002 rejected D key-001
provenance edge rejected ancestry cutoff_head
  1. alethech init generates an Ed25519 keypair + identity derived from public key
  2. alethech commit --content memory.json signs the content + links to DAG parent
  3. alethech verify checks signatures, DAG integrity, identity binding, reachability
  4. alethech key rotate revokes old key with cutoff_head, grants new key, both signed by root
  5. alethech export --output dir/ creates portable signed bundle
  6. alethech import --input dir/ verifies bundle + writes atomically (target untouched on failure)
04 / 08  ·  MATH + GUARANTEES
the math + the guarantees

equations, then the checklist

commit_id = sha256(JCS(object − {commit_id, signature}))

content-addressed id over the canonicalized object, with the id and signature fields removed.

signature = Ed25519_sk(JCS(object + commit_id))

deterministic Ed25519 signature over the canonical object plus its freshly computed commit_id.

agent_id = did:alethech: + b32(sha256(JCS(pk))[:16])

identity derives from the root public key — operational keys rotate, the agent_id does not.

C ∈ ancestry(cutoff_head) ⟹ VALID_HISTORICAL

a commit is valid iff its ancestry is reachable from the last pre-rotation head.

  • ✓signature verifies against declared public key
  • ✓commit_id matches SHA-256 of canonical JSON
  • ✓agent_id derives from public key (not declared)
  • ✓key rotation preserves identity (root-bound)
  • ✓revoked key commits checked against ancestry(cutoff_head)
  • ✓checkpoint head must be ancestor of current HEAD
  • ✓import is atomic (verify-then-write, target untouched on failure)
  • ✗does NOT prove content truth
  • ✗does NOT encrypt at rest
  • ✗does NOT detect rollback without external checkpoint
  • ✗does NOT delegate permissions between agents
  • ✗does NOT call any LLM
05 / 08  ·  VERDICTS · ROTATION · ROLLBACK
verdicts, rotation, rollback

three faces of one cutoff

verdict VALID_HISTORICAL C ∈ ancestry(cutoff_head)
verdict NOT_IN_PROVEN_PRE_ROTATION_HISTORY C ∉ ancestry(cutoff_head)
critical: the verifier does NOT claim to prove WHEN the commit was created — only that it is reachable from a verified head. Membership, not timing.
key-001 revoked
cutoff_head
key-002 active

agent_id derives from the root, not the operational key. Keys can be revoked and replaced; the identity they attest to does not move. Revocation is permanent and visible — a struck key still exists in the DAG as a historical signer, but no post-cutoff commit signed by it is accepted.

forward monotonic sequence — accepted:

10→ 11→ 12→ 13→ 14→ 15 [ ACCEPTED ]

stale sequence — rejected as rollback:

5 [ REJECTED — rollback ]

the system clock is NOT the authority — sequence is. Time lies; monotonic counters cannot be wound back without breaking the chain. Two commits cannot share a sequence number; the counter only moves forward.

06 / 08  ·  LIVE TERMINAL
try it — real crypto in your browser

live terminal



    

the loop, typed live when this section enters view: init → commit → rotate → verify.

alethech — interactive terminal real crypto · web crypto api · ed25519
↳ live from github.com/eddyflores100-lang/alethech
$

type 'help' or 'alethech init' to begin · arrow keys navigate history

07 / 08  ·  HONESTY + STATS
honesty + stats

what it refuses + the numbers

  • NOT · prove truth
  • NOT · rollback without checkpoint
  • NOT · encrypt at rest
  • NOT · delegate permissions
  • NOT · call any LLM
  • NOT · prove physical time
230
tests passing
8
mutation-guard paths
56
JCS conformance vectors
15
adversarial conformance vectors
9
CLI commands
4
cryptographic primitives (Ed25519, SHA-256, JCS, base32)
0
open issues
1
branch (main)
MIT
license
0.7.0
current version