TrustNotch claims its agent audit logs can be verified without trusting the provider, potentially giving operators an independently checkable record of agent activity.
state: seedheat: lowuncertainty: highknownscott: lowagent-auditability agentic-security provenanceTrustNotchsandrochekalov
What is this?
TrustNotch presents itself as audit infrastructure for AI agents, claiming to provide tamper-evident records through Ed25519-signed submission receipts, Merkle inclusion proofs, Bitcoin anchoring, and an open-source offline verifier. Its site offers HTTP submission and an MCP server, and says proofs remain verifiable even if TrustNotch disappears. These are provider claims, not independently validated findings in the supplied snippets; the material does not establish that all agent actions are captured or that logged claims reflect actual execution. The snippets do not identify the team or establish sandrochekalov’s relationship to the product.
Why it matters to Scott
The radar already tracks this same claim in radar:trustnotch-offline-agent-audit-logs; this case adds no demonstrated capability or independent validation. It matches Scott’s Agent Receipts and Cryptographic Trust concepts, but does not establish the binding to actual execution required by Execution Attestation, so it supplies no new reason to change what he builds or argues.
ip:concept.agent-receiptsip:concept.cryptographic-trustip:concept.execution-attestationradar:trustnotch-offline-agent-audit-logs
queries asked of Scott's wikis
- agent harness tool-call logging execution receipts
- independent verification provider trust cryptographic provenance
- audit trail completeness versus tamper evidence
- agent accountability policy checkpoints evidence capture
- MCP observability audit infrastructure
Measured heat
now 0 pts/hpeak 4 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 745h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion
How the heat travelled
pace: p28 vs 519 stories at the 720h mark (now 745h old) — ahead of aafp-commons-signed-agent-notebook (2.0x), behind agentgate-signed-agent-receipts (0.7x)
Evidence (3) — ⭐ canonical anchor
Interpretation history
2026-09-29T23:22:20Z
The newly attached cost analysis ('The Record Does Not Change') broadens the case from a pure provider claim toward adoption economics for verifiable agent-work records, but it neither validates nor extends TrustNotch's assertion and drew no traction. The claim remains an uncorroborated seed already covered by the sibling radar case, with nothing yet on log completeness or binding to actual execution.
2026-09-29T20:53:13Z
evidence attached: hn.story.49899577 — A cost analysis of verifiable agent-work records bears on whether provider-independent audit logging is practically adoptable.
2026-09-10T16:41:08Z
This recheck adds no substantive evidence: the submission and echo repeat one product claim, not independent corroboration. The claimed cryptographic mechanisms concern record integrity, while completeness and binding to actual agent execution remain unestablished; the existing sibling case already covers this proposition.
2026-09-10T15:50:56Z
grounded: known/low — The radar already tracks this same claim in radar:trustnotch-offline-agent-audit-logs; this case adds no demonstrated capability or independent validation. It m
2026-09-10T15:48:48Z
case created — The linked product makes a bounded auditability claim, although no implementation details or verification results are supplied.
Decision trace
- 10-09 03:05review_dormant28 days without material information; scheduled checks stopped
- 10-04 04:56drop_targetsquiet through full ladder or over cap 8
- 09-30 09:22repriceThe newly attached cost analysis ('The Record Does Not Change') broadens the case from a pure provider claim toward adoption economics for verifiable agent-work records, but it neither valid
- 09-30 06:53attachA cost analysis of verifiable agent-work records bears on whether provider-independent audit logging is practically adoptable.
- 09-30 06:52propose_attachA cost analysis of verifiable agent-work records bears on whether provider-independent audit logging is practically adoptable.
- 09-11 02:41repriceThis recheck adds no substantive evidence: the submission and echo repeat one product claim, not independent corroboration. The claimed cryptographic mechanisms concern record integrity, while complet
- 09-11 02:41alert_silentThere is no new release, verification result, or consequential implementation to surface today. The provider claim remains covered by existing tracking and can wait for a briefing or substantive evide
- 09-11 02:41alert_routeThere is no new release, verification result, or consequential implementation to surface today. The provider claim remains covered by existing tracking and can wait for a briefing or substantive evide
- 09-11 01:54alert_silentThe supplied evidence repeats TrustNotch’s provider-independent verification claim without a concrete new release, access change, verification mechanism, or engineering result. It is relevant to agent
- 09-11 01:54alert_routeThe supplied evidence repeats TrustNotch’s provider-independent verification claim without a concrete new release, access change, verification mechanism, or engineering result. It is relevant to agent
- 09-11 01:50groundThe radar already tracks this same claim in radar:trustnotch-offline-agent-audit-logs; this case adds no demonstrated capability or independent validation. It matches Scott’s Agent Receipts and Crypto
- 09-11 01:48createThe linked product makes a bounded auditability claim, although no implementation details or verification results are supplied.