Verifiable Agent Runtime · v2.7.0

A hash-chained, hardware-signed record of everything your AI agent actually did.

VAR records everything your AI agent does — signed inside an AWS Nitro Enclave so no one, including us, can alter the record after the fact. Any auditor can verify it independently, without access to your infrastructure.

Log seq : 1
msg "agent started — fetching TVL data"
stream a4f2c1e8d903b471…
sig 9c2e4b8f1a0d3c7e…
Compute seq : 2
fn echo
inputs_hash 3a7bd3e2f8c1049a…
stream 8f1e3c9b4d07a52e…
sig 4d7e2a1f9c803b65…
Evidence Sealed seq : 3
state d8e3f1a7c29b504d…
ECR 1.0000
result PASS ✓

The construction

Three layers. Each one independently verifiable.

A hash chain links every action. A hardware key signs it. Any auditor can check the result — no access to your enclave, no call to VAR-controlled endpoints.

Chain

Rolling SHA-256 hash chain

Every log entry and computation extends the chain: SHA-256(prev_stream ‖ new_data). Once written, nothing can be removed or reordered without breaking every subsequent hash.

Key

Ed25519 signatures from hardware

Each chain snapshot is signed by a key that lives only inside the Nitro Enclave. The enclave's attestation document ties that key to a specific, auditable binary — so a verifier knows exactly what code held the signing key.

Verify

Verification without access

Ship the record to any auditor. They run apex_verify.py against it — no access to your enclave, no call to VAR-controlled endpoints. The math either checks out or it doesn't.


Where it matters

Where "trust us" stops being enough.

Financial agents

Agents taking irreversible financial actions

AI agents are executing trades, auto-generating Suspicious Activity Reports, managing treasury — each action irreversible and potentially subject to regulatory review. When a federal auditor asks "prove your AI didn't alter this SAR after generation," there is currently no cryptographic answer. VAR gives you one.


Start in five minutes

No AWS account required.

Simulation mode activates automatically when /dev/nsm is absent — you get a real hash chain and real Ed25519 signatures, with simulated enclave measurements so you can integrate and test without AWS hardware.

# 1. Start the gateway
docker run -p 127.0.0.1:8765:8765 \
  ghcr.io/kennethkabogo/var:latest

# 2. Log an agent action
curl -X POST http://127.0.0.1:8765/log \
  -d '{"msg": "agent started"}'

# 3. Run an attested computation
curl -X POST http://127.0.0.1:8765/compute \
  -d '{"fn": "echo", "inputs": {"value": 42}}'

# 4. Seal and verify the bundle
python3 tools/apex_verify.py --self-test

Early access is open.

VAR is in active development. If you're building AI agents in financial infrastructure or agentic settlement, we want to talk.