2026-10-11 16:38 UTC

TrustNotch claims its agent audit logs can be verified without trusting the provider, potentially giving operators an independently checkable record of agent activity.

state: seedheat: lowuncertainty: highknownscott: lowagent-auditability agentic-security provenanceTrustNotchsandrochekalov

What is this?

TrustNotch presents itself as audit infrastructure for AI agents, claiming to provide tamper-evident records through Ed25519-signed submission receipts, Merkle inclusion proofs, Bitcoin anchoring, and an open-source offline verifier. Its site offers HTTP submission and an MCP server, and says proofs remain verifiable even if TrustNotch disappears. These are provider claims, not independently validated findings in the supplied snippets; the material does not establish that all agent actions are captured or that logged claims reflect actual execution. The snippets do not identify the team or establish sandrochekalov’s relationship to the product.

Why it matters to Scott

The radar already tracks this same claim in radar:trustnotch-offline-agent-audit-logs; this case adds no demonstrated capability or independent validation. It matches Scott’s Agent Receipts and Cryptographic Trust concepts, but does not establish the binding to actual execution required by Execution Attestation, so it supplies no new reason to change what he builds or argues.
ip:concept.agent-receiptsip:concept.cryptographic-trustip:concept.execution-attestationradar:trustnotch-offline-agent-audit-logs
queries asked of Scott's wikis
  • agent harness tool-call logging execution receipts
  • independent verification provider trust cryptographic provenance
  • audit trail completeness versus tamper evidence
  • agent accountability policy checkpoints evidence capture
  • MCP observability audit infrastructure

Measured heat

now 0 pts/hpeak 4 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 745h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-10 15:48 (minted)⭐ origin echo-reconstructedThe linked product is described as 'Audit logs for AI agents you can verify without trusting provider.'
TrustNotch on blog (echo) · attributed from hn.story.49644365 · published time unknown
—
09-10 14:30first on hacker news · published · lag ?TrustNotch – Audit logs for AI agents you can verify without trusting provider
sandrochekalov
—
09-10 14:30amplified on hacker news 👑hn.story.49644365
sandrochekalov
peak 2 · 0 comments · 65% of case engagement
09-29 20:07amplified on hacker newshn.story.49899577
adrianoutlaw
peak 1 · 0 comments · 35% of case engagement
09-10 15:22our radar first saw it · lag ?discovery anchor: hn.story.49644365—
pace: p28 vs 519 stories at the 720h mark (now 745h old) — ahead of aafp-commons-signed-agent-notebook (2.0x), behind agentgate-signed-agent-receipts (0.7x)

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnTrustNotch – Audit logs for AI agents you can verify without trusting providersandrochekalov20
🟧 echo.blog ⭐The linked product is described as 'Audit logs for AI agents you can verify without trusting provider.'TrustNotch——
🟧 hnThe Record Does Not Change: what a verifiable record of AI-agent work costsadrianoutlaw10

Interpretation history

Decision trace