2026-10-11 18:04 UTC

TrustNotch claims its AI-agent audit logs are tamper-evident and verifiable offline, potentially allowing operators to check recorded agent activity without relying on an online verification service.

state: expiredheat: lowuncertainty: highknownscott: lowagent-audit-logs agentic-security provenanceTrustNotch

What is this?

TrustNotch presents itself as audit infrastructure for AI agents, claiming that its logs are tamper-evident and independently verifiable offline even if its service disappears. Its first-party pages describe agents submitting actions over HTTP, receiving immediate Ed25519-signed receipts, and having entries batched into RFC 6962 Merkle trees whose roots are anchored to Bitcoin via OpenTimestamps; anchoring takes hours rather than seconds. The supplied snippets establish the vendor's claims, not independent validation, and do not identify its founders or establish that the logs capture every action or prove that submitted actions actually occurred.

Why it matters to Scott

TrustNotch repeats the portable, independently checkable proof position already held in Scott’s Decision Attestation Package and Sovereign Software Assurance pages; the radar’s Traceseal signed-receipts case already tracks the closely related offline-verifiable agent-audit claim, though not TrustNotch itself. The supplied vendor claims establish neither consequential adoption nor a change to Scott’s execution-attestation requirements: signing submitted records does not establish complete capture, actual execution or authorised intent, so this remains another example rather than a reason to change what he builds or argues.
ip:concept.decision-attestation-packageip:framework.sovereign-software-assuranceip:concept.execution-attestationradar:traceseal-signed-agent-receiptsradar:agenttrust-portable-execution-recordsradar:agentgate-signed-agent-receipts
queries asked of Scott's wikis
  • agent harness audit trails tool-call capture
  • cryptographic provenance recorded evidence versus actual execution
  • offline verification vendor-independent trust
  • agent security logging completeness trust boundaries
  • signed receipts timestamping asynchronous finality

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnTrustNotch – Tamper-evident audit logs for AI agents, verifiable offlinesandrochekalov10
🟧 echo.other ⭐The first-party page describes “Cryptographically signed, Bitcoin-anchored, and verifiable offline” audit logs for AI agents, with Ed25519 rTrustNotch——

Interpretation history

Decision trace