Seal Transparency · public log
Every record this gateway signs, committed to a log anyone can watch.
An append-only commitment log: one tree over every receipt and every agent-action record the Seal gateway has signed, refusals included, in the order they were recorded. Each leaf commits a record by hash, so the public log reveals size and order, not the decision content itself.
A signature lets you detect whether a signed record has changed. This log makes it harder to hide that a signed record existed. Pin the head today, come back later, and verify it grew from that head without rewriting its history. The checks below run in your browser against the published key.
Current signed tree head
Checking
Is a receipt in the log?
Paste the attestation_id from a receipt. The proof is recomputed here up to the signed root.
Has the log only grown?
Pin the current head first. The pin stays in this browser only.
No pin yet
Watched from outside
A pin in your browser protects you. A witness protects everyone. Several times a day, a public repository outside this infrastructure fetches the head, checks its signature, proves it extends the last head it recorded, and countersigns the record into Sigstore's public log. A log that shrank or forked would fail that job in public.
Reading the witness status
Aqta-ai/seal-log-witness holds every head, every proof and every Sigstore bundle; node scripts/check.mjs re-verifies the whole chain offline. Fork it and run your own.
A public, append-only log of signed AI decisions
Seal signs a record at the moment an AI decision is cleared or refused, and commits that record to one public append-only log. This page recomputes the log in your browser. It does not ask you to take our word for the result, and it does not contact us to produce it.
What you can check here
- A signed tree head. The current root of the log, signed with the published issuer key. Pin it and come back later.
- An inclusion proof. Evidence that one record is committed to the log, recomputed from the leaf and its audit path under RFC 6962.
- A consistency proof. Evidence that the log grew from a head you pinned earlier without rewriting anything behind it.
What it holds, and what it does not
Leaves are hashes. No prompt, no response and no decision content is published here. Both model-call decisions and agent tool actions enter the same tree, refusals included, because a blocked action is evidence that a control operated.
The log shows that a record it holds has not changed and has not been removed. It cannot show that a decision which never entered Seal took place. That is the omission bound, it is open, and no signature scheme closes it.
An outside repository records this log’s head several times a day and countersigns it, so a rewrite would have to fool a party that is not us.
Without this page
The gateway serves the same objects unauthenticated. Hashing is RFC 6962: leaf = SHA-256(0x00 || entry), node = SHA-256(0x01 || left || right). The head is signed over aqta-sth-public-v1|size|root bytes|timestamp.
curl https://api.aqta.ai/v1/public/transparency/sth curl https://api.aqta.ai/v1/public/transparency/proof/<attestation_id or action_id> curl "https://api.aqta.ai/v1/public/transparency/consistency?old_size=<pinned size>"
What this log does not prove: that a decision which was never signed exists. A head commits to what was issued. That limit is published in the threat model. The proof checkers are published, so the claim is exercisable by a stranger: aqta-verify-proof ships in the same package as the receipt verifier.
Log history
27 August 2026, 10:40 UTC
The log was anchored at size 153, root 6107375227dcd804…5510f8196a. Earlier that day, receipts recorded without a sequence number were being sorted to the front of the tree instead of appended. Heads pinned before this correction therefore do not chain to the current log. We fixed the gateway, changed inserts to take the sequence explicitly, backfilled by appending, and added regression tests. This history is permanent. A log that rewrote itself once and did not say so would be worth nothing.
4 September 2026
Agent action records joined the log. Every record of a tool action, refusals included, now enters the same tree as the model-call receipts, under its own entry tag. The 20 action records issued before that day were appended after the existing leaves, so the log grew from 196 to 216 and the root at size 196 did not change.
6 September 2026
An outside witness started. A public repository, Aqta-ai/seal-log-witness, records the signed head several times a day, proves each head extends the one before, and countersigns it into Sigstore’s public log. Its chain starts at size 196.
Now taking pilots.
Two weeks, fixed scope. One workflow, one review path, one evidence pack, judged against your reviewer’s own criteria.