TrustNotch claims its AI-agent audit logs are tamper-evident and verifiable offline, potentially allowing operators to check recorded agent activity without relying on an online verification service.
state: expiredheat: lowuncertainty: highknownscott: lowagent-audit-logs agentic-security provenanceTrustNotch
What is this?
TrustNotch presents itself as audit infrastructure for AI agents, claiming that its logs are tamper-evident and independently verifiable offline even if its service disappears. Its first-party pages describe agents submitting actions over HTTP, receiving immediate Ed25519-signed receipts, and having entries batched into RFC 6962 Merkle trees whose roots are anchored to Bitcoin via OpenTimestamps; anchoring takes hours rather than seconds. The supplied snippets establish the vendor's claims, not independent validation, and do not identify its founders or establish that the logs capture every action or prove that submitted actions actually occurred.
Why it matters to Scott
TrustNotch repeats the portable, independently checkable proof position already held in Scott’s Decision Attestation Package and Sovereign Software Assurance pages; the radar’s Traceseal signed-receipts case already tracks the closely related offline-verifiable agent-audit claim, though not TrustNotch itself. The supplied vendor claims establish neither consequential adoption nor a change to Scott’s execution-attestation requirements: signing submitted records does not establish complete capture, actual execution or authorised intent, so this remains another example rather than a reason to change what he builds or argues.
ip:concept.decision-attestation-packageip:framework.sovereign-software-assuranceip:concept.execution-attestationradar:traceseal-signed-agent-receiptsradar:agenttrust-portable-execution-recordsradar:agentgate-signed-agent-receipts
queries asked of Scott's wikis
- agent harness audit trails tool-call capture
- cryptographic provenance recorded evidence versus actual execution
- offline verification vendor-independent trust
- agent security logging completeness trust boundaries
- signed receipts timestamping asynchronous finality
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-09-10T07:37:20Z
No new evidence since last look beyond staleness timeout; remains an unvalidated vendor claim duplicating known offline-verification pattern already tracked elsewhere. Nothing new expected within horizon.
2026-09-08T07:33:16Z
No substantive delta changes the interpretation: TrustNotch remains a vendor-reported offline-verification implementation, not independently validated agent execution attestation. The reconstructed source and link submission provide no independent corroboration or new reason to change Scott’s tooling decisions.
2026-09-08T07:31:35Z
grounded: known/low — TrustNotch repeats the portable, independently checkable proof position already held in Scott’s Decision Attestation Package and Sovereign Software Assurance pa
2026-09-08T07:29:16Z
origin walked (codex/luna, conf 0.94): anchor hn.story.49606202 -> echo.other.bfd42f44c0 by TrustNotch
2026-09-08T07:27:19Z
case created — The product announcement makes a bounded offline-verification claim distinct from existing security cases, although implementation and logging guarantees remain unsubstantiated.
Decision trace
- 09-10 17:37expireNo new evidence since last look beyond staleness timeout; remains an unvalidated vendor claim duplicating known offline-verification pattern already tracked elsewhere. Nothing new expected within hori
- 09-10 17:37alert_silentNo release, adoption, or verification delta since last check; purely a staleness trigger with no consequential new fact.
- 09-10 17:37alert_routeNo release, adoption, or verification delta since last check; purely a staleness trigger with no consequential new fact.
- 09-08 17:33repriceNo substantive delta changes the interpretation: TrustNotch remains a vendor-reported offline-verification implementation, not independently validated agent execution attestation. The reconstructed so
- 09-08 17:33alert_silentThis recheck adds no release, access change, adoption, or verification result. The offering can remain a reference for a future briefing; there is no consequential new event to surface today.
- 09-08 17:33alert_routeThis recheck adds no release, access change, adoption, or verification result. The offering can remain a reference for a future briefing; there is no consequential new event to surface today.
- 09-08 17:32alert_silentThe supplied first-party page establishes TrustNotch's offering and its signed-receipt, Merkle-batching and offline-verification claims, not their validated performance. Public verifier artifacts
- 09-08 17:32alert_routeThe supplied first-party page establishes TrustNotch's offering and its signed-receipt, Merkle-batching and offline-verification claims, not their validated performance. Public verifier artifacts
- 09-08 17:31groundTrustNotch repeats the portable, independently checkable proof position already held in Scott’s Decision Attestation Package and Sovereign Software Assurance pages; the radar’s Traceseal signed-receip
- 09-08 17:29promote_anchororigin walk conf 0.94
- 09-08 17:27createThe product announcement makes a bounded offline-verification claim distinct from existing security cases, although implementation and logging guarantees remain unsubstantiated.