Arcaeon

Arcaeon · verify

Verify us before you talk to us.

Most of the field will send you a case study, a logo wall, or a promise to "walk you through it on a call." We'd rather send you a file. Below is a real, downloadable evidence bundle — produced by our own libraries, pinned to a public commit anyone can check, in a repository we operate, with a daily Bitcoin anchor that is the part we do not control — plus the exact commands to check every piece of it on your own machine. Nothing here is a mockup; every output quoted is what actually printed when we ran it.

The bundle

real run · pinned live · seq 1

arcaeon-verify-bundle

An 8-row demo agent action log, hash-chained by the ledger that is now inside the arcaeon package, with an authority block on every row and one artefact binding to https://example.com, plus a compaction receipt sealed into the same chain as row 9. The resulting head (chain=9650e32f…, rows=9) is pinned to Arcaeon's hosted witness under namespace velouria-demo, recorded as a public commit anyone can check, in a repository we operate; the daily Bitcoin anchor is the part we do not control.

Check it yourself

Install the real package

pip install arcaeon

The base install has zero dependencies: it runs on the Python standard library, and it is readable in full on PyPI before you run anything. The VERIFY.md inside the bundle was written before the merge and uses the old package names; the commands on this page are the current ones, and the old names keep working (the map).

Verify the hash chain

arcaeon verify demo_agent_log.jsonl

What that printed on our machine, unedited:

{
 "verdict": "VERIFIED",
 "ok": true,
 "rows": 9,
 "chained": 9,
 "prechain": 0,
 "first_break": null,
 "breaks": 0,
 "verified_scope": "full",
 "declared_breaks": 0,
 "declared": []
}

Then break it on purpose — flip one byte in row 2's content (leave chain alone) and re-verify. Ours came back:

{
 "verdict": "BROKEN",
 "ok": false,
 "rows": 9,
 "chained": 9,
 "prechain": 0,
 "first_break": "line 2: chain mismatch",
 "breaks": 1,
 "verified_scope": "full",
 "declared_breaks": 0,
 "declared": []
}

It names the exact row, and breaks tells you how many there were in total — first_break is only the first, and one named fault does not mean one fault.

Read ok as three-valued, not a boolean. true only when every row was checked. false when a break was found. null when the scan was bounded and therefore cannot vouch for everything: an empty file (verified_scope: "empty"), or unchained rows skipped before the first chained one ("bounded_prechain_skipped"). null is falsy, and it is not a green — the CLI exits 0, 1 and 3 to match, so a CI gate that treats only exit 0 as passing fails loud on the bounded case. In the words the rest of this site uses, true reads VERIFIED, false reads BROKEN, and null reads COULD NOT LOOK; /proves defines all three.

Full copy-pasteable script in VERIFY.md § 1. Note the bundle itself was generated by ledger 0.5.1 (see manifest.json), which predates the breaks and verified_scope fields, and the merged package adds the verdict word first: its quoted output shows five keys, current output shows ten. The chain values it pins are unaffected.

Verify the artefact binding

Row 2 binds a digest of https://example.com as it was actually fetched. Re-fetch it yourself and recompute:

self-consistency: {'digest_ok': True, 'recipe': 'sha256:raw-bytes:v1', 'refetch': 'skipped', 'notes': []}
with refetch:      {'digest_ok': True, 'recipe': 'sha256:raw-bytes:v1', 'refetch': 'match', 'notes': []}

refetch: 'match' means the bytes we hashed are the bytes the page serves right now — checked against the live page, not our say-so. Honest limit: a 'mismatch' here would mean changed-or-tampered, indeterminate, never proof by itself.

Verify the compaction receipt

from arcaeon.prove.compact import verify_receipt
print(verify_receipt(row))
{'ok': True, 'self_consistent': True, 'content': 'skipped', 'schema': 'v1', 'understatement_check': 'truncation-only', 'verified_scope': 'bounded_no_content+v1_lower_bound', 'notes': ['bounded scan: no content supplied, so nothing was recomputed -- this is self-consistency only, ...', 'bounded scan: v1 row claiming an introduction -- post.bytes is only a lower bound, ...']}

Confirms the receipt's arithmetic reconciles and it hasn't been altered since it was sealed. The two notes, cut short above, say what it could not check: with no content supplied this is self-consistency only, and because this receipt was sealed in the older v1 format its dropped-byte count is only a lower bound. Hand it the original and surviving content and it recomputes the rest. Does not prove the compaction was a wise summary; the library has no opinion on salience, and neither does this page.

Verify the live witness pin

curl "https://witness.arcaeon.io/api/latest?ns=velouria-demo"

At build time, and reproducible now:

{
  "ok": true,
  "pin": {
    "namespace": "velouria-demo",
    "rows": 9,
    "chain": "9650e32f0feae20f37dbcb6dd9b68826",
    "pinned_at": "2026-08-14T16:05:44.491Z",
    "seq": 1
  },
  "source": "github-contents-api"
}

Don't trust our API for this either — read the public record directly:

curl "https://raw.githubusercontent.com/dan8433-user/arcaeon-witness-pins/main/pins/velouria-demo/00000001.json"

Same JSON, no API in the loop. History: github.com/dan8433-user/arcaeon-witness-pins. The witness is monotonic — it refuses a lower or equal rows for a namespace — so we cannot quietly reissue this bundle with a different history that still "verifies clean."

Honest limit, from the library itself: the witness proves no-truncation and no-rewrite relative to what it saw, only as recent as the last pin. The max gap between pins is the real security parameter — one pin is a demo of the mechanism, not a production cadence.

One label for the steps you cannot redo. Everything above you can rerun yourself. Writing a new pin into the velouria-demo namespace is different: it takes a key only we hold, so that step is reproducible by us, not yet by you. You can read and check every pin we write; you cannot yet write one there.

Verify the witness repo itself wasn't rewritten

The pin store is a public git history — itself rewritable by anyone with write access — so it counter-anchors its own HEAD daily with OpenTimestamps (a Bitcoin-blockchain timestamp):

pip install opentimestamps-client
git clone https://github.com/dan8433-user/arcaeon-witness-pins
ots info anchors/<UTC-date>-head.txt.ots

info rather than verify on purpose: ots verify needs a local Bitcoin node and exits with "Could not connect to Bitcoin node" without one, which is most machines. ots info needs no node and no network and prints the Bitcoin block heights the proof asserts; any public explorer turns a height into a time. Use verify if you run a node.

A fresh anchor reads "pending confirmation in Bitcoin blockchain" until the next day's run collects its block attestation. Measured 2026-09-01, that is the following day, up to roughly 34 hours, not a few hours. Normal, not a failure. As of that date, 18 of the 19 daily proofs carry Bitcoin block attestations, unbroken from 2026-08-14 through 2026-08-31; the 19th is the current day's, pending by design.

What this proves, and what it doesn't

Proves:

  • The 9 rows were not edited, deleted, or reordered after being written.
  • Row 2's claim about example.com is bound to a specific, re-fetchable digest you can check against the live page.
  • The compaction receipt is internally consistent and unaltered since sealing.
  • This exact (rows, chain) was recorded at a specific time, in a commit anchored daily to a public Bitcoin chain anyone can check, so a quiet swap to a different history would show.

Does not prove:

  • That any row's content is true rather than fabricated by the agent that wrote it — a hash chain notarizes whatever was written, hallucination or fact, with equal fidelity. The artefact binding is the one place in this bundle where a claim is independently checkable; that's why it's there.
  • That dropping the 10 compacted items was editorially wise — the receipt has no opinion on salience.
  • Authorship in the cryptographic-signature sense — authority blocks are tamper-evident data, not signatures. What a re-minter cannot do is also advance the witness pin above.
  • Anything about the other parts of the package (audit, meter and the rest): this bundle exercises the ledger and a compaction receipt only.

That list isn't fine print. It's reproduced from the libraries' own module docstrings — the non-proofs are the product as much as the proofs are. Full walkthrough with every command: VERIFY.md.

Talk to us — after you've checked

Agents: @nora on The Colony, nora_cyan on Moltbook — reviews and cross-verification exchanges answered in public, receipts-first. Everyone else: hello@arcaeon.io, or call (855) 301-1717. The number is a recorded menu that answers the common questions, and you can leave a message any time.

More: the agent side · home · /llms.txt · /.well-known/offers.json

Holding a receipt from a training class rather than this bundle? Check it here — free, no account, and it never leaves your browser. If you run the class rather than sit it, this is what we do for a roster.