Når AI får handlekraft, trenger vi bevis
Vi skal ikke måtte stole på agenten for å kunne stole på resultatet. Tilliten må ligge i grensene som er satt på forhånd, kontrollene som kjører, og beviset som fanges underveis.
Field notes on cryptographic timestamping, advanced electronic seals, AI evidence, and the regulations driving them.
Vi skal ikke måtte stole på agenten for å kunne stole på resultatet. Tilliten må ligge i grensene som er satt på forhånd, kontrollene som kjører, og beviset som fanges underveis.
NSMs kryptografiske anbefalinger handler om mer enn valg av algoritmer: nøkkelbeskyttelse, evnen til å bytte kryptografi, og forberedelsene på det som kommer etter dagens løsninger. Vi har sett på hvordan Sigill står seg.
SDK v0.3.0 seals PDFs with an embedded PAdES seal — up to the archival B-LTA level, with qualified timestamps — while transmitting only a 32-byte digest. The PDF stays in your environment, the guarantee is enforced in code, and the code is open source. Validated against the EU's reference validator.
JSON is what AI systems and APIs actually produce — and it now has a first-class seal format on sigill.ai. Detached JAdES seals per ETSI TS 119 182-1, hash-only by default, with optional qualified timestamps and a post-quantum ML-DSA-87 hybrid signature. Available in the API and both SDKs today.
A Manifest V3 browser extension that automatically creates RFC 3161 timestamps for every Claude, ChatGPT, and Gemini conversation turn — without sending a single word of your conversation to Sigill.
Proof only works if it exists before it is questioned. We are making Sigill's independent cryptographic evidence layer public today.
Paid tenants can now connect an existing RFC 3161 timestamping authority to Sigill, keep their provider policy intact, and use Sigill for routing, evidence, sealing, and verification.
Sigill's API is now available as a remote MCP server. Claude can timestamp a document, verify a TSR, look up a hash, seal a PDF, verify a sealed document, and check your plan quota without leaving the conversation — using the same API key you already have.
The Sigill SDKs are not just for production AI calls. This post shows how a small Claude Code Stop hook can use sigill-python to turn local AI coding sessions into sealed, verifiable evidence envelopes.
Two open-source SDKs for building, sealing, and verifying AI evidence envelopes — Apache-2.0, byte-compatible across languages, with the canonical-JSON, hash-binding, and RFC 3161 plumbing already done. The pattern from earlier posts, now installable from PyPI and NuGet.
The simple agent timestamps every turn. That's necessary but not sufficient. This post is about what makes the difference between a log that timestamps things and a record an adversarial reader can't unwind.
Stamp every artifact your CI produces with an RFC 3161 timestamp before it leaves the build runner — so a year from now you can prove what shipped, and when, without trusting your own logs.
A working ~150-line Python agent that cryptographically timestamps every prompt and every model response, producing tamper-evident records you can verify with one openssl command. For teams whose AI systems will eventually face an auditor, regulator, or counterparty asking 'prove what your model said on day X' — this is the minimal pattern that answers the question.