
Self-hosted evidence gateway for AI systems: fail-closed policy, WAF, egress controls, signed durable MMR proofs, and offline verification across LLM providers.
AI Governance and Cryptographic Evidence Gateway
Aegis Latent Core commits signed, hash-linked evidence of every governed AI call — before the response reaches the caller — and issues a portable proof that a third party verifies without trusting the gateway, us, or you.
Every load-bearing claim in this file carries a locator and a stated boundary; the gates that enforce that discipline run in CI.
Current release:
v5.0.1— the latest published release (the checked-out source isv5.0.2, an Apache-2.0 source target that is not published), published 2026-09-24 on every surface (PyPIaegis-latent-core5.0.1followed on 2026-09-26), read back the same day (Release Status §1.0a). The Sigstore-signed tag passesgitsign verify-tag; the GitHub Release carries 31 assets and all 15 files listed in itsSHA256SUMSre-hash to their digests; PyPIaegis-latent-sdk5.0.1and npmaegis-latent-sdk5.0.1are byte-identical to the release assets of the same name; and the GHCR gateway and dashboard images passcosign verifyand their build-provenance attestations verify, each against the exact publishing workflow identity. The gateway distributionaegis-latent-corereached PyPI at5.0.1on 2026-09-26 (run36224961909ofpublish_pypi_gateway.yml, read back 2026-09-29, Release Status §1.0b);pip install aegis-latent-coreresolves to5.0.1, and its wheel and sdist match the release assets byte for byte. The GHCR images and the Release assets remain available. The previous release,v5.0.0, was published 2026-09-16 on the same surfaces (§1.0). There is no4.2.0; the number was skipped.First published version with the gateway on PyPI:
v4.1.2, read back on 2026-09-04 — signed annotated tag, GitHub Release with 31 assets, PyPIaegis-latent-core4.1.2, PyPIaegis-latent-sdk4.1.2, npmaegis-latent-sdk4.1.2, and GHCR gateway and dashboard images.4.1.2is the first version installable from PyPI asaegis-latent-core; before it the gateway came from source or GHCR only. The npm version list skips4.1.1, whose publish step failed. Av4.1.0release object also exists but was created outside the pipeline and carries no assets; ignore it. The two4.1.2PyPI gateway artifacts are byte-different from the release assets of the same name — same content, different build host — soSHA256SUMSdoes not cover those downloads; the5.0.1PyPI gateway artifacts match it. See Release Status for provenance and readback.
Your AI decisions are logged to a database your administrators can edit. When someone asks what the model was told six months ago, you answer from records the interested party could have changed.
In a regulated industry that is not a paperwork problem — it is an existential one. The regulator, the court and the auditor each ask the same question, and "our logs are probably fine" is not an answer they accept:
verify_integrity() detects tampering on read; tampering is detected, not prevented — see the boundaries below.CLM-039 is LEGAL-REVIEW-REQUIRED).→ Prove it yourself — twelve lines of Python, no call to our servers, three cases of which two must fail.
pip install aegis-latent-sdk aegis-latent-core # verifier + gateway, both 5.0.1 on PyPI python tools/sales/prove_it/prove_it.py --demo # accepts one record, rejects two forgeries python -m examples.demo # gateway + mock upstream, tamper detectedBoth commands run from a checkout of this repository; what each one shows and does not show.
caller ──────────► Aegis gateway ──────────────────────────► upstream provider
│ admission: auth · scope · bounds
│ WAF · rate limiting · session checks
│
│ (policy passed) forward
│ ◄─────────────── response ─────────
│
│ redact → hash → sign → WAL append + fsync → MMR leaf
│ (refused requests: the refusal is committed to the
│ same signed chain before the error returns)
│
caller ◄────────── response + X-Aegis-Evidence-Status
+ X-Aegis-Request-ID + X-Aegis-MMR-* proof headers
Non-streaming. The evidence record is committed before the response is observable by the caller.
Streaming. Sanitized events are emitted incrementally through a bounded, byte-accounted queue while evidence status reads pending-terminal. One exact-byte terminal summary is committed, and only then is the terminal marker emitted. If that commit fails, the marker is withheld.