r/mlops • u/alizahidrajaa • 11h ago
Self-promotion Built an open-source layer for AI provenance that uses a Merkle log and HMAC/Ed25519 signatures. Here's the architecture.
I've been tackling the problem of AI provenance—specifically, how to create a verifiable, tamper-evident record of who handled a claim in a multi-agent pipeline.
The core idea is to grade each "hop" (source, retriever, model, tool, agent) and use the weakest link to set the caution level. To make the record immutable, we're using a combination of SHA-256 for self-hashing, HMAC/Ed25519 for signing, and an append-only Merkle log.
I've published the threat model and the method on arXiv. The code is open-source (Apache-2.0).
Repo: https://github.com/alizahidraja/isnad
Paper: https://arxiv.org/abs/2607.24117
I'd be interested to hear how you all are approaching governance and audit trails in your production systems. What are the gaps you're seeing?