Sealby Aqta

Sample reviewer docket

An AI system acted. What was it cleared to do?

This is the docket a reviewer receives. Every check on it runs in your browser, against Seal’s published key.

Question under review

“Did Seal sign each of these decisions exactly as shown, and are both still in its public log?”

Fixed before the evidence was opened.

Evidence supplied

2 signed decisions · 1 allowed · 1 refused

Checks

  • Signaturenot checked yet
  • Log inclusionnot checked yet
  • Continuitynot checked yet

Checking, in this browser.

What left this device?

Not checked yet.

Two records, as Seal signed them.

Each is a signed record from this pack. Change one and the same checks run again on a copy, in place. The pack itself never changes.

  • Record 01 · decision receipt

    v: 1 · 11 fields

    The call to claude-sonnet-4-6 was cleared to run.

    Authority
    budget_guardloop_guard
    Signed
    13 Aug 2026, 01:27:11 UTC · key 9Y3Eiq6V…YFdvWa4

    Checking. Ed25519, on this device.

    Checking the log proof.

    More attacks
    All signed fields and the raw record
    outcome

    ALLOWED

    the signed outcome

    policy_applied

    budget_guard, loop_guard

    the rules it was checked against

    model

    claude-sonnet-4-6

    the model that was asked for

    request_hash

    577f7a94d8985770…

    the prompt, hashed, never the prompt

    timestamp

    2026-08-13T01:27:11.840747+00:00 (13 Aug 2026, 01:27:11 UTC)

    the issuer’s clock, signed

    public_key

    9Y3Eiq6V…YFdvWa4

    Seal’s published key

    signature

    65rPtNi4…FeXmWBg

    stops matching if anything changes

    The bytes the signature covers, in canonical order. Change one and it fails.

    {"attestation_id":"520a3601-0d94-4b32-9619-a512ca853a94","cost_prevented_eur":0,"model":"claude-sonnet-4-6","org_id":"ab451951-318a-4527-be74-7420f9c4356c","outcome":"ALLOWED","policy_applied":["budget_guard","loop_guard"],"public_key":"9Y3Eiq6V8QjRDUM5nPqSwKIOPQaoEU4SbagfYFdvWa4","request_hash":"577f7a94d8985770f5e559de72b75dfe3f7a54c00dc07aa299946ac381586cf9","timestamp":"2026-08-13T01:27:11.840747+00:00","trace_id":"c2a3e22f-5753-4291-881a-533a86b14679","v":1}
How these checks worked

What this proves, and what it does not.

What this proves

  • The issuer signed exactly these fields
  • Nobody has altered them since
  • Which rules Seal checked each call against, and what it decided
  • Which model was requested
  • These records, refusals included, were in the issuer’s public log when its head was signed

What it does not

  • That those rules were the whole policy in force across the operator’s systems
  • Which model actually executed
  • That every decision was recorded
  • That the records you were not shown were irrelevant

For reviewers: the full technical scope →

The question, and the verdict.

The question put to the reviewer

“Did Seal sign each of these decisions exactly as shown, and are both still in its public log?”

Fixed before the evidence was opened, so it cannot be adjusted to fit the answer.

The evidence answers the question, for the purpose it was asked.

Consistent, but it does not reach the question. A real answer, and a different fix.

The evidence does not support an affirmative answer.

disabled on this published sample. a verdict recorded here would be attributed to someone who never made it

Check it on your own machine.

The published verifier runs the same Ed25519 check offline, against the key you pin. Change one byte of the file and it fails.

curl -sO https://app.aqta.ai/samples/sample-receipt.json
npx aqta-verify-receipt sample-receipt.json \
  --key 9Y3Eiq6V8QjRDUM5nPqSwKIOPQaoEU4SbagfYFdvWa4
the original verifies. an edited copy fails

Now taking pilots.

Thirty days, fixed scope. One workflow, one review path, one evidence pack.

not ready? break the record first ↑