On this page

Docs / Trust chain

Trust chain

Check which source a running agent identifies, whether that source was reviewed, and which evidence supports each result.

What a check means

A passing open check means the endpoint answered a fresh challenge with a key tied to the source you expected and an attested loader the SDK trusts. It does not query Base. A sealed runtime check also verifies the key's on-chain image registration. A certified check also requires a current credential for that code.

source→identity→runtime⊢attested

The check does not judge the agent's answers or promise it stays up. It tells you what code is running and what evidence stands behind it.

The links

The architecture page draws each of these.

  1. 01 / code

    The code gets one hash

    The CLI hashes the code you submit. Change one byte and the hash changes.

  2. 02 / review

    The review is a separate step

    A sealed deployment sends the code for review first. A pass produces a credential. An open deployment skips this, and epoche certify can add a review later.

  3. 03 / build

    The plan decides what gets built

    Sealed: a builder enclave turns the reviewed code into a Docker image and signs a record tying the two together. Open: the loader runs your public code as it is and labels it uncertified.

  4. 04 / admission

    A sealed image is recorded before it can run

    Base records a sealed image only when the review, the build record, and the proof all match. Only then does the loader get the key to run it. Open images skip this.

  5. 05 / runtime

    The running agent proves it holds the key

    The agent signs a fresh challenge with a key made inside the enclave. Sealed: Base ties that key to the recorded image. Open: the key is checked against the approved loader and the agent's signed source statement.

Checking an open deployment

verifyOpenRuntimeAttestationreads the agent's signed source and runtime statements, checks its attestation against the loader the SDK trusts, and challenges the signing key. You pass in the hash of the code you expect.

TypeScript
import { verifyOpenRuntimeAttestation } from "@epoche/agent-sdk";

const verified = await verifyOpenRuntimeAttestation({
  endpoint: "https://agent.example.com",
  sourceFingerprint: "0x1111111111111111111111111111111111111111111111111111111111111111",
});

Anything missing, stale, or mismatched fails the check. Certified checks also read current state from Base through at least two RPCs.

Where trust remains

A

The hardware

AMD SEV-SNP and Microsoft's attestation service.

B

Epoche's release key

It approves reviewer, builder, loader, and policy releases. Approvals and revocations are public. Moving this to a DAO is planned; see the DAO page.

C

The review policy

A pass covers what the policy checks and nothing else. An open deployment makes no review claim at all.

When it fails

Verification fails closed. A bad signature, a mismatched hash, or an unapproved loader stops the check. When a check requires on-chain records and a current credential, a missing record on Base, a revoked credential, or RPCs that disagree also stop it.

Each claim needs its own evidence.

A copied credential cannot answer a live challenge, and cannot be attached to a different image.