The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Crovia — verifiable silence (TACET) and Crovia Seal listing page.
Live log · Specification & Internet-Draft · PNX Action · Whitepaper · LACUNA candidates · Canon
countersign — Witness protocol and home of TACET (verifiable map,
epoch sheets, silence proofs), the PNX profile, the tacet-pnx CLI and the canon that
every Crovia surface follows. Specification and Internet-Draft:
croviatrust.com/registry/tacet/spec/.
Transparency logs prove that something was published. TACET is a transparency log whose product is the opposite: a portable, offline-verifiable proof that, for a given AI model, no training-data disclosure was found on its public surfaces in any of these hours — each hour opened by a public randomness beacon and closed by a Bitcoin block.
It runs in production. Every hour since 2026-09-19T18:00Z, Crovia's operator fetches
the model cards of the systems under watch, runs a public predicate over the bytes,
signs what it saw, commits the verdicts to one sparse Merkle map, and anchors the
epoch in Bitcoin. When a lab stays silent, the silence stops being an opinion.
In the browser, nothing to install, including the Bitcoin anchors:
croviatrust.com/registry/seal/verify/?url=…Qwen__Qwen3-32B.seal.json
— site/registry/seal/verify/tacet-verify.js + ots-verify.js are a second, independent
implementation of SPEC §8.5–8.6 in plain JS on WebCrypto. With network checks on, the page
parses every OpenTimestamps proof itself and compares its merkle root with the Bitcoin
block header from a public explorer. No Bitcoin node, no ots client, no Crovia server
trusted.
On the command line, same checks, pure Python, standard library only for the anchors:
(Output from the first three hours of the log, all three confirmed in Bitcoin blocks
967736 and 967740. silence_days is truncated, never rounded: 10 800 s is 0.12.)
The verifier recomputes every map root from the empty tree, checks the chain of
sheets, verifies the observer signature on every negative snapshot and its Merkle
inclusion in the hour, and recomputes the silence figure — all from the file. The
two time bounds are external facts: for each drand round it checks chain and
schedule from the sheet and, over the network, that the round's bytes are what the
drand relays serve (it does not verify the BLS signature itself); for each anchor
it parses the OpenTimestamps proof and matches its merkle root to the Bitcoin
block header. With --offline, or when a relay or explorer is unreachable, those
items come back as named warnings, never as passes. Run a node? Pass your own
header source to tacet.ots.verify_sheet_anchor; the explorer is only the default.
A silence proof for one model over epochs [a, b] is the delta-encoded chain of
non-inclusion paths for its slot, plus one negative snapshot per counted hour, wrapped
in a crovia.seal.v1. Three strengths:
| Level | Name | Proves |
|---|---|---|
| 1 | map-silence | the slot was empty in the map in every epoch — says nothing about the world |
| 2 | surface-silence | + a negative, beacon-bound, signed snapshot exists for every counted, anchored epoch |
| 3 | witnessed-silence (k/n) | + every epoch sheet carries ≥ k countersignatures from independent witnesses |
Monotonicity rule. silence_days is the sum of anchored epochs that hold a negative
snapshot. Hours nobody looked, hours not yet in Bitcoin, and operator downtime add
nothing. Silence cannot grow while observation is paused, and any verifier can
recompute it from the proof alone.
Nothing about intent ("hid", "refused" never appear). Nothing about surfaces that were
not listed. Nothing about hours in which nobody looked. Nothing about quality: the
predicate is deliberately permissive — a datasets: tag counts as disclosure. A
level-2 proof is a proof about what was served to the observer; level 3 (independent
witnesses) is the next milestone.
Providers are protected too: a model can commit-then-reveal its training-data summary (SPEC §11). A committed slot can never yield a silence proof.
TACET proves what a public surface did not contain. PNX — Proof of
Non-Exfiltration (tacet/PNX.md, profile crovia.pnx.v1) proves what an AI
agent did not send out. An egress witness fingerprints every outbound body
(salted 32-byte k-grams, winnowed with window 16), commits the fingerprints to
the same sparse Merkle map and signs a run sheet; the operator then proves, per
protected asset, non-inclusion against the run root. Any shared substring of
47 bytes or more is always detected; shorter assets are reported as partial
or undetectable and never counted as clean. The run root is committed into a
TACET epoch, so it inherits the drand opening and the Bitcoin closing.
The auditor sees neither the traffic nor the secrets and verifies offline:
Status: reference + tests shipped; conformance vectors, browser verifier and a
one-command tacet-egress proxy are next (see GROWTH.md).
Everything the operator produces is public, CC-BY-4.0, browsable and CORS-open under
/registry/data/tacet/:
| File | Contents |
|---|---|
latest.json | latest epoch sheet summary; totals since genesis |
targets.json | per model: last verdict, negative and anchored-negative epochs |
trust_root.json | operator / observer / issuer keys, map id, genesis, drand chain |
sheets/<e>.json, snapshots/<e>/…, ots/<e>.ots | every sheet, every signed snapshot, every Bitcoin proof |
proofs/index.json | featured level-2 silence proofs, rebuilt daily |
The operator is a plain Python package. tacet-operator run-epoch --targets targets.txt
opens an epoch, observes, commits, signs and stamps; refresh-anchors closes epochs
once Bitcoin confirms; publish writes the discovery files; prove builds a proof for
any target and range. A second observer for the same target and epoch strengthens a
level-2 proof; a witness countersigning epoch sheets is what turns it into level 3 —
open an issue if you want to run one.
| Live operator | croviatrust.com, hourly, since 2026-09-19 18:00 UTC |
| Predicate | crovia.pred.hf-card-training-data 1.0.0 (Hugging Face model cards) |
| Anchoring | OpenTimestamps → Bitcoin; refreshed every 2 h; verifiable without a node (SPEC §8.6) |
| Proof strength in production | 2 (level 3 needs independent witnesses — planned) |
| Seal format | crovia.seal.v1, IETF draft-crovia-seal, unmodified |
Crovia Trust. TACET: Verifiable Silence for AI Training Disclosure, v0.1-draft, 2026. https://github.com/croviatrust/countersign/blob/main/tacet/SPEC.md
See CITATION.cff. Contact: info@croviatrust.com · security: see SECURITY.md.
Code Apache-2.0. Specification texts CC0. Public data CC-BY-4.0. All commits are authored by Crovia Trust.