Palimpsests / Verify without reading

Key-free verification · PALA-1

Verify an AI audit log without reading it

PALA-1 separates the right to verify a log from the right to read it. Anyone can check that no record was altered, removed or reordered — with no decryption key, and without opening a single record body.

How it works

Every record's header carries a SHA-256 digest of its body, and names the hash of the record before it. Verification walks the headers — one hash per record — and checks each body against the digest bound into its header. Bodies are never decrypted, so the key that protects their content is never needed, and never handed over.

Three questions, answered separately

QuestionFrom the file aloneNeeds
Was any record altered, removed or reordered?yes or no, with the first bad record namednothing
Is this the whole chain, or was the end cut off?only with an anchorthe latest head, kept outside the file
Did this history exist before a certain time?only with a witnessa signed statement from someone else

A question that was not checked is reported as not checked — never as passed.

Try it

pip install palimpsests
palimpsests demo                                # writes and verifies a small audited run
palimpsests pala verify palimpsests-demo.pala   # the auditor's check — no key needed

Exit codes: 0 verified · 1 tampered · 2 partial — intact, but no anchor was supplied, so a cut-off end would not have been detected · 3 unreadable.

Limits, stated

Tamper-evident means a change is detectable, not impossible. An attacker who holds both the encryption key and write access to wherever the anchor is kept can forge the chain and its anchor together. Catching that needs a commitment outside the host — a hardware token or an external transparency service; see anchors without a network.