ART12-1 · AUTOMATIC LOGS
Events recorded over the system lifetime.
$.predicate.timestamps.created — receipt emitted at decision time.
METszl.dev/GovernedAction/v1 · ed25519 over dsse
Every receipt on this page verifies in your browser, right now, with WebCrypto Ed25519 over DSSE pre-authentication encoding. No server decides anything here.
IAM says what an identity may access. a11oy proves what an AI agent was authorized to do, what it actually did, and whether the required evidence exists. A signature attests integrity and origin — never accuracy or performance.
loading demo bundle…
bundle not yet loaded
Regulation (EU) 2024/1689, Article 12 — machine-readable at
article12/conformance_profile.yaml. This is a logging conformance profile,
not a claim of EU AI Act compliance; applicability, classification, and deployer
obligations remain customer-specific. Retention floor: 180 days.
Events recorded over the system lifetime.
$.predicate.timestamps.created — receipt emitted at decision time.
METInput data and sources referenced.
Evidence items are sha256-addressed; absence ⇒ INCOMPLETE.
METNatural persons involved in verification identified (12(3)(d) via Art.14).
is_service_account pinned false for human actors; api_key cannot claim human.
METStart and end of each use recorded.
executed ≥ created; ntp_synced const true; rfc3161 for anti-backdating.
METLogs protected against alteration.
Ed25519 over DSSEv1 PAE; prev_chain_hash links every receipt.
METRetained per policy, six-month floor.
PENDING_SYNC is a visible state during outage; local durability after flock+fsync only.
METLogs accessible to authorities and auditors on request.
The bundle verifies offline, without entering the platform. This page is the proof.
METSystem version in use is recorded.
deployed_revision pinned at execution; runtime stage is never evidence of revision.
METL1Missing evidence yields INCOMPLETE, never PASS — computed in the verifier, on every run, in both Python and this page.
L2A signature attests integrity and origin, never accuracy or performance.
L3Human principals cannot be service accounts; api_key cannot claim a human (Art.12(3)(d)).
L4ntp_synced is a schema constant; unattested time cannot produce PASS.
L5Local durability is acknowledged only after flock + fsync. PENDING_SYNC stays visible during sink outage.
L6Replay is non-mutating: verification never changes the chain.