Palimpsests / Verify without reading
Key-free verification · PALA-1Verify an AI audit log without reading it
PALA-1 separates the right to verify a log from the right to read it. Anyone can check that no record was altered, removed or reordered — with no decryption key, and without opening a single record body.
How it works
Every record's header carries a SHA-256 digest of its body, and names the hash of the record before it. Verification walks the headers — one hash per record — and checks each body against the digest bound into its header. Bodies are never decrypted, so the key that protects their content is never needed, and never handed over.
Three questions, answered separately
| Question | From the file alone | Needs |
|---|---|---|
| Was any record altered, removed or reordered? | yes or no, with the first bad record named | nothing |
| Is this the whole chain, or was the end cut off? | only with an anchor | the latest head, kept outside the file |
| Did this history exist before a certain time? | only with a witness | a signed statement from someone else |
A question that was not checked is reported as not checked — never as passed.
Try it
pip install palimpsests
palimpsests demo # writes and verifies a small audited run
palimpsests pala verify palimpsests-demo.pala # the auditor's check — no key needed
Exit codes: 0 verified · 1 tampered · 2 partial — intact, but no anchor was supplied, so a cut-off end would not have been detected · 3 unreadable.
Limits, stated
Tamper-evident means a change is detectable, not impossible. An attacker who holds both the encryption key and write access to wherever the anchor is kept can forge the chain and its anchor together. Catching that needs a commitment outside the host — a hardware token or an external transparency service; see anchors without a network.