VAP · veritaschain.org

VeritasChain Standards Organization (VSO)

Verifiable AI Provenance
Framework (VAP)

An open meta-framework for making the records of AI systems tamper-evident, completeness-checkable, and attributable — after the fact.

VAP v1.26 domain profiles5 IETF Internet-DraftsCC BY 4.0

Read the specification GitHub Blog

e₁e₂ ? e₄e₅ the record that was never created

Why this exists

The evidentiary gap

Legal and governance instruments across jurisdictions increasingly require logging and human oversight of AI systems. They specify the obligation — not how compliance can be independently verified after the fact. And the hardest part of that verification is not detecting records that were altered. It is detecting records that were never created.

Classical integrity technology — signatures, WORM storage, audit logs — proves things about records that exist. VAP is designed around the other problem: making the absence of a record inspectable by a third party, at a declared granularity, with disclosed limits.

Three-tier missing-data taxonomy (VAP family)
TierConditionStatus under VAP
Tier 1The event was never measured — nothing crossed the observation boundaryPermanently unrecoverable by design. VAP is silent; no mechanism reconstructs it, and no deployment may represent otherwise
Tier 2Measured, but the record was lost before anchoringBounded and disclosed — the gap itself is recorded as an anchor-gap event with its bounds
Tier 3Anchored, then omitted from what is presentedThird-party detectable via the Completeness Invariant (INT-008): omission / split-view detection

Scope, stated plainly

What VAP is — and is not

What VAP is

  • A meta-framework: a cross-domain upper layer defining structural requirements for cryptographically verifiable decision provenance. Domain profiles (VCP, CAP, CPP, MAP, OAP…) bind it to sector semantics.
  • Post-hoc forensic and evidentiary infrastructure. Its capability is precisely this: it makes AI processing records auditable and attributable.
  • Built from established primitives: SHA-256 hash chaining, Ed25519 signatures (RFC 8032), Merkle batching, and external anchoring such as RFC 3161 time-stamps.

What VAP does not do

  • It does not prevent, block, or intercept anything at runtime, and it is not real-time monitoring or control.
  • It is tamper-evident, not tamper-proof: alteration is made detectable, not impossible.
  • It cannot recover Tier 1 events. The pre-measurement boundary is a hard, permanent limit — by design.
  • It does not make any AI decision correct, fair, or safe.

“…does not warrant the correctness, fairness, or safety of the underlying AI decisions — only the integrity, completeness (at anchor granularity), and attributability of their records. VAP generates evidence; competent authorities and courts evaluate it.”

— VAP v1.2, §1.6 Legal Scope and Non-Guarantee Statement (Normative)

Mechanisms

Core mechanisms

Cryptographic sequence verifiability

Third-party-verifiable ordering and membership of recorded events — hash chaining is one admissible mechanism, not the only one.

External anchoring — mandatory

Merkle batching and external anchoring of signed roots is required at all conformance levels in v1.2, with a documented anchor-continuity plan.

Completeness Invariant (INT-008)

Any verifier holding an anchor can detect post-anchor omission and split-view presentations: each AnchorRecord binds event count, first/last event IDs, and the governing policy identifier.

Denial-symmetry

Refusals, denials, and negative decisions are recorded with the same rigor as approvals. Systems that only log successes prove nothing about what they declined.

Evidence Pack

A portable, self-verifying bundle for offline third-party verification — records, proofs, anchors, and keys, checkable without access to the producing system.

ScopeManifest & XREF

Declared observation scope up front; independent cross-referenced logging by multiple parties (XREF) so no single actor’s record stands alone.

The family

Domain profiles

VAP itself is never a protocol. Profiles bind the framework to sector semantics; the Protocol designation belongs to exactly one document — VCP.

VCPv1.2 RC1

VeritasChain Protocol

Finance / algorithmic trading — the audit-standards profile for capital-markets AI. The only document in the family carrying the Protocol designation.

CAPv1.0 Released

Content / Creative AI Profile

A verifiable evidence layer for AI workflows involving content and intellectual property — ingestion, training, generation, transformation, export — for games, film, animation, publishing, and music.

CPPv1.4 Released

Capture Provenance Profile

Provenance for media captured by a device the operator controls (first-party capture). Sibling of OAP.

MAPv0.1.2 Working Draft

Medical AI Profile

Clinical and benefits workflows: AI outputs, human review, override, and sign-off records made tamper-evident and third-party inspectable.

OAPv0.1.1 Working Draft

Observed Artifact Provenance (VAP-WEB)

Records of third-party web resources observed at a URL — material published by someone else, preserved because it may later be disputed, deleted, edited, or denied.

PAPFragment v0.2 Draft

Public Administration Profile

Credit scoring, welfare determination, immigration, recruitment AI. The Investigative-Decision Vocabulary fragment (v0.2 draft) is the first published track.

All profiles, cross-cutting capabilities, and the registry →

Standards engagement

IETF Internet-Drafts

Five active drafts socialize the framework’s constructs in the IETF RATS and SCITT areas. VSO also tracks and assesses adjacent work in ISO/IEC JTC 1/SC 42 and ITU-T SG17 under pre-registered assessment protocols.

Honest baseline

Project status

6domain profiles
2cross-cutting capabilities
5IETF Internet-Drafts
0external implementations — disclosed

As of August 2026: zero external implementations, zero paying customers, and zero Evidence Packs accepted in any proceeding. Every VSO document carries this disclosure. We publish what does not yet exist as clearly as what does — a provenance framework that overstated its own record would be self-refuting.

Specifications are open (CC BY 4.0) and developed on GitHub. Implementers and reviewers are welcome: standards@veritaschain.org.