# Vaara > Tamper-evident runtime evidence layer for AI agents. Covers EU AI Act compliance and any case where you need to prove what an agent actually did. Open source, no SaaS, no telemetry. Vaara intercepts agent tool calls, scores each one with a conformal risk interval, and writes a hash-chained audit record. Online learning across five expert signals via Multiplicative Weight Update. Distribution-free conformal coverage on the score. An external auditor can verify these properties without trusting your stack. Position: tamper-evident runtime evidence and enforcement layer. Signed attestation plus execution receipts pair each MCP tool call to the policy that allowed it. ## Who builds it Vaara is built and maintained by Henri Sirkkavaara, an independent developer in Finland, working on how an autonomous action can be proved to a party that has no reason to trust the operator. He is the sole author and copyright holder. The following are records held by other parties, not claims made on this site. Each is checkable at the link: - [draft-sirkkavaara-vaara-receipt](https://datatracker.ietf.org/doc/draft-sirkkavaara-vaara-receipt/): IETF Internet-Draft, "The Vaara Receipt: A Recomputable Receipt Format for Decisions About Autonomous Actions". An active Internet-Draft, not an RFC and not an adopted standard. - [OpenSSF Best Practices project 12612](https://www.bestpractices.dev/projects/12612): passing badge, externally assessed project practices. - [GitHub Marketplace: Vaara Policy Check](https://github.com/marketplace/actions/vaara-policy-check): published action listing. - [PyPI](https://pypi.org/project/vaara/) and [npm](https://www.npmjs.com/package/@vaara/client): release history under his name. - Participant on the IETF scitt, agentproto and rats mailing lists, where the receipt format is discussed publicly by other participants. Participation in a working group discussion is not authorship of a standard. - Contributor to the European Commission's Apply AI Alliance community on Futurium, writing on EU AI Act Article 12 and Article 14. A community contributor, not a Commission official or appointee. - Vaara appears in the industry acknowledgements of Singapore IMDA's Model AI Governance Framework for Agentic AI v1.5 (20 May 2026). An acknowledgement of the project, not an advisory role. - Subject of an AMD AI Developer Program testimonial (May 2026). A testimonial about his work. He is not and has never been employed by AMD. ## Conformance results Vaara publishes a results register: every conformance suite, its verdict, and every party other than the maintainer who ran the checkers and reported the outcome in public. Each suite ships an independent checker that imports no Vaara code and recomputes its verdicts from the bytes of its own case files, so a stranger can disagree with an expected result and show their work. - [Conformance results](https://vaara.io/conformance.html): the register as a page, generated from the runner's own report - [conformance.json](https://vaara.io/conformance.json): the same register as one machine-readable file - [Row request form](https://github.com/vaaraio/vaara/issues/new?template=conformance-row.yml): open to anyone who ran the checkers, free, no approval step - Concept DOI for the corpus: [10.5281/zenodo.22027975](https://doi.org/10.5281/zenodo.22027975) What a row is, stated exactly. It records that a named party ran the checkers at a commit on a date and said so somewhere public. It is not a certification, it does not say Vaara is compliant with anything, and it does not say the party endorses Vaara. The vectors are Vaara's own and no ratification body stands behind them, which is a real limit on any neutrality claim. Rows are permanent and chained, and each published head is recorded in a public transparency log the maintainer does not operate. Every row names what kind of run it was, because what a run establishes is a property of who wrote the verifier and who wrote the vectors rather than of how well the run went. A reproduction is the author's checkers over the author's vectors. An independent implementation from the text, run against the author's vectors, establishes something about the text. An independent implementation run against independently constructed vectors establishes something about both. A row that does not name its kind reads as the first, the weakest of the three. Listed reproductions, 7 to date. Every claim below is the party's own, quoted as they scoped it, and the runs are recorded somewhere public by someone other than Vaara: ### Row 1: babyblueviper1 (invinoveritas) - Ran on 2026-08-19, at commit cc5df5d2938cb9a26e820c1b8b5ac3b7d398ab1e - Kind of run: Not stated. An unstated kind reads as a reproduction, the weakest of the three. - Result they reported: 40 passed, 0 failed, 3 skipped, 49 cases - Their own public record: https://github.com/crewAIInc/crewAI/issues/4877#issuecomment-5339555715 - This row: https://vaara.io/conformance.html#row-1 - The row as bytes: https://vaara.io/badge/babyblueviper1-invinoveritas.json ### Row 2: Nenad Vasic / Elara Protocol - Affiliation, as the party stated it: Elara Protocol — AI-agent-maintained (disclosed), independent of Vaara - Ran on 2026-08-21, at commit a209864e11fc14f0ac3466dd33d668d9c156208f - Kind of run: Not stated. An unstated kind reads as a reproduction, the weakest of the three. - Result they reported: 45 passed, 0 failed, 1 skipped, 75 cases. Runner exit 0. The skip is `article12_fold_v0` (checker wants a bundle zip argument rather than a bare case directory — structural, not environmental). An earlier same-day run at f0dbf4d8 gave 44/45, 65 cases, 0 failures, before the corpus grew. - Their own public record: https://mailarchive.ietf.org/arch/msg/scitt/HOKZT8J06zB3JaNxOfAEasNty1Q/ - This row: https://vaara.io/conformance.html#row-2 - The row as bytes: https://vaara.io/badge/nenad-vasic-elara-protocol.json ### Row 3: Emek Can Doğru - Affiliation, as the party stated it: VERAX TEKNOLOJİ LİMİTED ŞİRKETİ — independent of Vaara - Ran on 2026-08-24, at commit a209864e11fc14f0ac3466dd33d668d9c156208f - Kind of run: Reproduction: the author's checkers over the author's vectors - Result they reported: 45 passed, 0 failed, 1 skipped, 75 cases. Runner exit 0. The skip is `article12_fold_v0`, whose checker validates a passed-in bundle zip rather than a bare case directory — structural, not environmental. - Their own public record: https://mailarchive.ietf.org/arch/msg/scitt/wZDSwS77Bb46AZNZ197XkHedNAg/ - This row: https://vaara.io/conformance.html#row-3 - The row as bytes: https://vaara.io/badge/emek-can-dogru.json ### Row 4: Council of AI - Affiliation, as the party stated it: Independent AI measurement body — councilof.ai (CSOAI) - Ran on 2026-08-25, at commit 9fefe51a61f16dc13cd64ca8ca4b8792e48fb64b - Kind of run: Reproduction: the author's checkers over the author's vectors - Result they reported: 43 passed, 0 failed, 3 skipped, 75 cases - Their own public record: https://github.com/CSOAI-ORG/councilof-ai/blob/conformance-runs/docs/conformance-runs/vaara-sep2828-2026-08-25.md - This row: https://vaara.io/conformance.html#row-4 - The row as bytes: https://vaara.io/badge/council-of-ai.json ### Row 5: Iman Schrock - Affiliation, as the party stated it: EMILIA Protocol - Ran on 2026-08-25, at commit 62a7080b7c854173c7d6b8ee51ce4dd724d59227 - Kind of run: Reproduction: the author's checkers over the author's vectors - Result they reported: 41 passed, 0 failed, 3 skipped, 57 cases. Skips: `article12_fold_v0` (bundle zip required), `pq_hybrid_v0` (optional `dilithium_py` missing), and `qualified_time_v0` (optional `asn1crypto` missing). `release_condition_v0` passed 8/8. - Their own public record: https://mailarchive.ietf.org/arch/msg/scitt/I5mdtYRinS-wjrnbwCnyXwwvrjU/ - This row: https://vaara.io/conformance.html#row-5 - The row as bytes: https://vaara.io/badge/iman-schrock.json ### Row 6: YuTao Peng - Affiliation, as the party stated it: Insight (oracleinsight.xyz) - Ran on 2026-08-26, at commit 54a69b38e28c3a8d3d9ced6b61b217ea5eb03334 - Kind of run: Reproduction: the author's checkers over the author's vectors - Result they reported: 43 passed, 0 failed, 3 skipped, 75 cases - Their own public record: https://github.com/imokokok/vaara-conformance - This row: https://vaara.io/conformance.html#row-6 - The row as bytes: https://vaara.io/badge/yutao-peng.json ### Row 7: Ali Toygar Abak - Affiliation, as the party stated it: Phionyx - Ran on 2026-09-13, at commit d44b8b0de4f5f3e4e5c0248ad1e6fbbc3972b317 - Kind of run: Reproduction: the author's checkers over the author's vectors - Result they reported: 2 suites passed, 0 failed, 0 skipped; both selected suites matched their published expected verdicts. No declared case count is exposed by this pinned corpus layout; see record. - Their own public record: https://github.com/halvrenofviryel/ai-runtime-evidence-protocol/blob/9114f4f365369cab133e857e08bb59ff6fb5e24d/interop/vaara/2026-09-13/conformance-reproduction/README.md - This row: https://vaara.io/conformance.html#row-7 - The row as bytes: https://vaara.io/badge/ali-toygar-abak.json ## Repo and packages - [GitHub source](https://github.com/vaaraio/vaara): code, releases, issue tracker - [PyPI](https://pypi.org/project/vaara/): `pip install vaara` - [npm @vaara/client](https://www.npmjs.com/package/@vaara/client): TypeScript HTTP client ## Docs - [README](https://github.com/vaaraio/vaara/blob/main/README.md): install, quick start, evidence specimen, integrations - [AGENTS.md](https://github.com/vaaraio/vaara/blob/main/AGENTS.md): instructions for coding agents integrating or contributing to Vaara - [Prove it yourself](https://github.com/vaaraio/vaara/tree/main/examples/prove-it-yourself): one runnable file; produce a signed hash-chained trail, verify it offline, watch a forged byte get caught - [How to prove what an AI agent did](https://github.com/vaaraio/vaara/blob/main/docs/prove-what-an-ai-agent-did.md): the four properties a provable record needs and how verification works - [Logs vs evidence](https://github.com/vaaraio/vaara/blob/main/docs/logs-vs-evidence.md): why logs persuade only people who already trust you, and what evidence is instead - [EU AI Act Article 12](https://github.com/vaaraio/vaara/blob/main/docs/eu-ai-act-article-12.md): what record-keeping requires (automatic logging, six-month retention under Art. 19 and 26(6)) and what it does not (hash chains) - [EU AI Act on 2 August 2026](https://github.com/vaaraio/vaara/blob/main/docs/eu-ai-act-august-2026.md): what actually applies (Article 50 transparency, GPAI enforcement) after Omnibus VII moved high-risk to Dec 2027 / Aug 2028, and the evidence question disclosure raises - [Tamper-evident audit trail for AI agents](https://github.com/vaaraio/vaara/blob/main/docs/tamper-evident-audit-trail.md): mechanics, honest limits, cost - [Vaara vs observability vs GRC](https://github.com/vaaraio/vaara/blob/main/docs/vaara-vs-observability-vs-grc.md): three different questions; comparison table and how they stack - [Our marketing runs under the gate](https://github.com/vaaraio/vaara/tree/main/docs/dogfood): the signed trail of Vaara's own marketing pipeline, with the policy and public key to verify it offline - [COMPLIANCE.md](https://github.com/vaaraio/vaara/blob/main/docs/COMPLIANCE.md): EU AI Act (Art. 9, 11 to 15, 61) and DORA (Art. 10, 12, 13) article-level mapping - [Formal specification](https://github.com/vaaraio/vaara/blob/main/docs/formal_specification.md): MWU regret bound O(sqrt(T log N)), conformal coverage, security properties - [vaara-bench-v1](https://github.com/vaaraio/vaara/blob/main/bench/vaara-bench-v1.md): 77-trace synthetic benchmark, frozen methodology - [CHANGELOG](https://github.com/vaaraio/vaara/blob/main/CHANGELOG.md): version-by-version evolution - [HTTP API contract](https://github.com/vaaraio/vaara/blob/main/docs/openapi.yaml): /v1/score and operator endpoints - [Signing keys](https://github.com/vaaraio/vaara/blob/main/docs/signing-keys.md): release verification ## Integrations - Framework adapters: LangChain, CrewAI, OpenAI Agents SDK, MCP server - Cloud guardrail adapters: AWS Bedrock Guardrails, Azure AI Content Safety, GCP Model Armor (article-tagged findings into Vaara's audit trail and OVERT envelope) - OVERT 1.0 emitter, verifier CLI, S3P (MEA-2) emitter with Clopper-Pearson intervals, experimental AMD SEV-SNP TEE attestation hook ## Numbers - 12,155-entry adversarial corpus (250 hand-curated + 11,905 LLM-generated), 70/15/15 split stratified by (category, source) - Classifier v9 (236 hand-features + 384-dim MiniLM embeddings) at calibrated threshold 0.9150: held-out TEST recall 84.7% [82.4, 86.7] at FPR 4.1% [2.9, 5.7], n=1,827 - Cross-model held-out recall 66.8% [64.9, 68.7] over n=2,277 with no eval-set attacker model in TRAIN; weakest sub-cell (data_exfil, closed-weight) 38.9% [35.3, 42.5] - BIPIA-pressure FPR on benign tool calls 1.2% [0.4, 3.6] across four agent backends - Multi-attacker PAIR ASR 0/25 per attacker across Qwen2.5-32B, Qwen2.5-72B, Llama-3.3-70B at identical seeds - 140 µs mean / 210 µs p99 for the hot-path rule scorer, commodity CPU; the MiniLM classifier is opt-in (`vaara[ml]`) and not in that path ## Optional - [Article 14 runtime](https://futurium.ec.europa.eu/ga/apply-ai-alliance/community-content/article-14-runtime-why-oversight-agentic-ai-has-be-evidenced-action-not-model): position post on EU Apply AI Alliance Futurium - [OVERT 1.0 spec](https://overt.is/): open runtime-trust standard Vaara implements as Arbiter - [Microsoft Agent Governance Toolkit](https://github.com/microsoft/agent-governance-toolkit): broader agent-governance reference (zero-trust identity, capability-based access control)