For auditors · Compliance officers · Risk officers
Verify AI decisions without trusting the system
Most AI systems produce logs. Logs say "this happened." They don't let you verify that the right decision was made. We publish a receipt format that does. Any governance system can produce it. Any auditor can verify it. The verifier is open source. The spec is open. You do not need to trust us.
The problem with logs
When a regulator asks "why did the system allow this transaction?" a log can tell you the action was taken. It cannot tell you that the action was within the risk limit, that the counterparty was not on the sanctions list, and that the dosage was within the safe range. A log is a narrative. It is not proof.
A receipt is different. It contains the policy that was evaluated, the input that was evaluated (PII stripped), the decision, and the exact inputs needed to replay the evaluation. You can run the same policy against the same input and confirm the result yourself. You don't trust the system — you verify it.
The audit procedure
7 steps. No trust required. Open-source verifier. Reproducible on any machine.
Retrieve the receipt
Every governance decision produces a PSR-001 receipt. Pull it from your SIEM — it's a JSON document with a defined schema. The receipt contains the policy hash, the input hash, the decision, and the replay inputs.
Retrieve the policy script
The receipt contains policy.script_source — a URL or path to the policy that was evaluated. Download it. Verify that SHA-256(script) matches policy.script_hash. If it doesn't, the policy was changed after the decision.
Reconstruct the input
The receipt contains evidence.replay_inputs — the exact inputs the gate evaluated. Reconstruct them. Verify that SHA-256(sanitized_input) matches input.input_hash. PII is already stripped — you're working with sanitized values.
Run the verifier
Execute the policy script against the reconstructed input using the open-source verifier. The ONLY Lang WASM verifier runs in any browser. The CLI verifier runs on any platform with Rust. No signup, no cloud, no dependency on PrimeSwarm.
Compare the result
The verifier's output must match gate_state, evidence.residual, evidence.indices_healed, and evidence.reason_codes. If it matches, the decision is verified. If it doesn't, the system has been tampered with.
Verify the hash and signature
Recompute the receipt_hash per the spec. It must match. If a signature is present, verify the Ed25519 signature over the receipt_hash using the public key in the receipt. If both pass, the receipt is authentic and the decision is verified.
Sign the audit
You did not trust the system. You verified it. Sign off on the audit with your own attestation — the receipt, the replay result, and your signature are the evidence.
The auditor bundle
Everything you need to verify AI governance decisions. All open source. No signup, no license, no vendor lock-in.
PSR-001 Receipt Format Spec
The formal specification. Field reference, hash computation, replay procedure, framework compatibility, JSON Schema.
PSR-001 JSON Schema
Machine-readable JSON Schema for validating receipts. Use it to verify that a receipt is structurally conforming before parsing.
DGV Verifier (CLI)
The command-line verifier. Run all 89 test cards and produce signed receipts. Builds on Linux, macOS, and WSL.
ONLY Lang WASM verifier
The browser-side verifier. Embed it in your audit tool. 162KB. No server, no cloud, no dependencies.
89 DGV test cards (JSON)
All 89 test card definitions in machine-readable JSON. Each card specifies a script, an input, and an expected result. Run them against any governance system.
DGV Registry (browsable)
Browse all 89 cards online. Each card shows the script, the input, the expected result, and the governance layer it tests.
Download the desktop app
Prefer to work offline? The DGV Auditor Toolkit desktop app runs all 89 test cards, verifies receipts, and generates reports — without a browser, without internet, without a server. Windows is available now; macOS and Linux coming soon.
The desktop app bundles the WASM verifier (35 cards) and the CLI verifier binary (34 CLI-only cards). All 89 cards run offline. Receipts are PSR-001 compliant.
Quickstart: verify a receipt in 5 minutes
# 1. Get the verifier git clone https://github.com/vdmo/only-dgv-verifier.git cd only-dgv-verifier cargo build --release # 2. Run all 89 test cards — each produces a PSR-001 receipt python3 dgv_runner.py --all # 3. Verify a specific receipt by replaying it python3 verify_receipt.py --receipt evidence/DGV-TC-001.receipt.json # 4. Validate a receipt against the JSON Schema python3 validate_receipt.py --schema ../specs/psr-001-schema.json \ --receipt evidence/DGV-TC-069.receipt.json # 5. Query all DENY decisions from your SIEM (Splunk example) # index=ai_governance event_type="primeswarm.receipt" gate_state="DENY" # | stats count by reason_codes
What you can verify
The decision was correct
Replay the policy against the input. The result must match the receipt.
The policy was not changed
SHA-256 of the policy script must match the receipt's script_hash.
The input was not tampered
SHA-256 of the sanitized input must match the receipt's input_hash.
The receipt is authentic
Recompute the receipt_hash. If present, verify the Ed25519 signature.
The decision is non-repudiable
The hash binds the decision to the policy and input. No party can deny it.
The audit is complete
Every decision produces a receipt — not just the interesting ones. Full population, not a sample.
Framework-agnostic
PSR-001 receipts can be produced by any governance system, not just PrimeSwarm. The spec includes mappings for:
| System | Policy language | Replay support |
|---|---|---|
| PrimeSwarm | only-lang | Full — residual, healing, replay |
| Microsoft AGT | yaml | Adapter needed — add script_hash, input_hash, replay_inputs |
| NVIDIA NeMoClaw | custom | Adapter needed — map network policy decisions |
| Custom | rego, cedar, python, custom | Any deterministic system can produce conforming receipts |