The evidence plane for AI agents.
LoopGrid captures and seals the evidence around consequential AI/agent decisions: agent identity, delegated authority, model/context, policy, human oversight, tool/action, observed outcome and cryptographic proof. The result is a signed, tamper-evident record that can be exported and verified independently.
Release posture: approved for controlled design-partner technical evaluation. Not Production GA. Evidence integrity can support governance, audit and dispute workflows; it is not by itself a legal compliance determination.
Agent runtimes execute. Observability explains. Control planes govern. LoopGrid proves what happened.
A consequential decision should answer:
- Which agent/version acted?
- What authority was delegated?
- Which model/context informed the decision?
- Which policy/version applied and what did it decide?
- Was human oversight required and what happened?
- Which external tool/action actually executed?
- What outcome was observed?
- Can an independent party verify the record later?
CAPTURE → SEAL → VERIFY → INVESTIGATE → REVIEW → REPLAY → PROVE
The append-only decision lifecycle includes decision_created, model_completed, policy_evaluated, human review events, tool/action evidence, outcome_observed and optional later replay/adjudication events. LoopGrid derives the current state from that history and rejects impossible consequential-event ordering.
/v1/tracesnow accepts standard OTLP/HTTP binary protobuf and JSON trace payloads.Content-Encoding: gzipis supported for OTLP/HTTP trace requests.- OTLP success responses now use the standard
ExportTraceServiceResponseencoding and match the requestContent-Type. - Decoded OTLP request bodies are bounded by
LOOPGRID_MAX_REQUEST_BODY_BYTESto limit decompression expansion. - Evidence Bundle v2 remains compatible and now supports the additive signed
loopgrid/bundle-attestation/1extension for cryptographic file-level integrity; legacy unattested Bundle v2 exports remain ledger-verifiable with an explicit warning.
- PostgreSQL-backed Docker deployment path.
- Production-mode safety guard for auth, secrets, PostgreSQL and CORS.
- Workspace-scoped API keys and human RBAC.
- SHA-256 workspace hash chains + persistent local Ed25519 signing.
- Signed workspace checkpoints.
- Portable Evidence Bundle v2 / Evidence Profile
3.0-draft. - Signer-pinned standalone verifier.
- FULL / REDACTED / PROOF-ONLY privacy modes.
- AES-256-GCM disclosure vault with erasable payloads.
- Deterministic policy provenance and human-review evidence.
- REST, Python, TypeScript/JavaScript, OpenTelemetry/OTLP (HTTP protobuf + JSON) and MCP paths.
- Optional live OpenAI/Anthropic replay/provider validation helpers.
- Optional RFC3161 timestamp and AWS KMS adapter paths.
For a no-Docker, no-account evaluation path, install the repository dependencies once and run the cross-platform quickstart:
python -m pip install -r requirements.txt
python scripts/quickstart.pyThe quickstart uses an isolated temporary SQLite database and temporary local Ed25519 signer. It creates a synthetic refund decision with policy evaluation, human approval, tool execution and observed outcome, exports a portable evidence bundle, and verifies that bundle with an out-of-band trusted public key. It does not modify an existing LoopGrid database or deployment.
Expected final output:
[OK] Decision captured: dec_...
[OK] Evidence exported: .../demo-output/evidence.zip
[OK] Evidence coverage: 100%
[OK] VERIFIED
Artifacts are written to demo-output/ and are synthetic evaluation data only.
The repository publishes a multi-platform development image from main to GitHub Container Registry:
docker pull ghcr.io/cybertechsoft/loopgrid:edge
docker run --rm -p 8000:8000 -v loopgrid_demo_data:/app/data ghcr.io/cybertechsoft/loopgrid:edgeThen open http://127.0.0.1:8000/. The edge tag tracks tested main; versioned and latest container tags are published from future GitHub releases. The default container invocation above is for local evaluation, not the production design-partner posture described below.
Requires Docker Desktop/Engine and Python 3.10+.
python scripts\generate_pilot_env.py
powershell -ExecutionPolicy Bypass -File .\validate_pilot.ps1The first command generates strong local secrets into .env without printing them. The second starts PostgreSQL + LoopGrid and runs the deployment validation gate.
Do not run docker compose down -v unless you intentionally want to destroy local pilot data.
py -3.12 -m venv .venv
.venv\Scripts\Activate.ps1
python -m pip install -r requirements.txt
python -m pytest -q
python run.pyOpen:
- UI:
http://127.0.0.1:8000/ - OpenAPI:
http://127.0.0.1:8000/docs - readiness:
http://127.0.0.1:8000/ready - trust posture:
http://127.0.0.1:8000/api/v1/system/info
pip install loopgridfrom loopgrid import LoopGrid
lg = LoopGrid(base_url="http://localhost:8000", api_key="lg_live_...")
d = lg.record_decision(
decision_type="customer_refund",
agent={"id": "support-agent", "version": "1.0"},
authority={"acting_for": "Acme", "limit_usd": 1500, "scope": ["refund:create"]},
model={"provider": "openai", "name": "gpt-5"},
context={"prompt_version": "support-v1"},
proposed_action={"tool": "stripe.refunds.create", "amount": 1000, "currency": "USD"},
)
print(d["decision_id"])See examples/refund_human_review.py for the complete policy → human approval → action → outcome lifecycle.
npm install @cybertechsoft/loopgridconst { LoopGrid } = require('@cybertechsoft/loopgrid');
const lg = new LoopGrid({baseUrl:'http://localhost:8000', apiKey:process.env.LOOPGRID_SERVICE_KEY});
const d = await lg.recordDecision({
decision_type:'customer_refund',
agent:{id:'support-agent',version:'1.0'},
authority:{acting_for:'Acme',limit_usd:1500,scope:['refund:create']},
model:{provider:'openai',name:'gpt-5'},
context:{prompt_version:'support-v1'},
proposed_action:{tool:'stripe.refunds.create',amount:1000,currency:'USD'}
});TypeScript declarations ship with the npm package.
LoopGrid evidence bundles can be verified offline without running or connecting to a LoopGrid service.
Install the canonical standalone verifier:
python -m pip install loopgrid-verify==0.1.0Verify an exported evidence bundle using an out-of-band trusted public key:
loopgrid-verify evidence.zip \
--trusted-public-key trusted-public-key.pemA valid attested bundle returns:
LOOPGRID EVIDENCE VERIFICATION
[OK] VERIFIED
[DETAIL] Bundle integrity: attested
A modified attested file causes verification to fail with exit code 2.
Signer identity can also be pinned explicitly:
loopgrid-verify evidence.zip \
--expected-key-id ed25519:...Current portable evidence identifiers:
- Evidence Bundle v2:
loopgrid/evidence-bundle/2 - Evidence Profile:
3.0-draft - Bundle attestation:
loopgrid/bundle-attestation/1 - Canonical verifier:
loopgrid-verify
Evidence Bundle v2 exports with bundle attestation cryptographically bind the exported files using SHA-256 digests and a signed bundle attestation. Modified, missing or unexpected attested files are rejected.
Older Evidence Bundle v2 exports without bundle-level file attestation remain ledger-verifiable and are reported explicitly as legacy_unattested.
Portable consistency proof and signer trust are separate concepts. An embedded public key can establish integrity under that key, but signer identity should be established out of band with --trusted-public-key or --expected-key-id when authenticity matters.
Verification confirms the integrity of the captured evidence. It does not determine whether an AI decision was correct or establish legal compliance.
- FULL — raw disclosures encrypted separately; signed ledger stores commitment/reference.
- REDACTED — selected values replaced by commitments.
- PROOF-ONLY — only commitment/proof metadata retained.
Encrypted disclosures can be erased later without rewriting the signed evidence chain.
LoopGrid accepts OTLP trace exports on the standard /v1/traces path using either:
Content-Type: application/x-protobuf(recommended/default for many OpenTelemetry SDKs)Content-Type: application/json- optional
Content-Encoding: gzipfor either encoding
Example environment configuration:
export OTEL_EXPORTER_OTLP_TRACES_ENDPOINT=http://127.0.0.1:8000/v1/traces
export OTEL_EXPORTER_OTLP_TRACES_PROTOCOL=http/protobuf
export OTEL_EXPORTER_OTLP_TRACES_HEADERS="X-LoopGrid-Key=lg_live_...,X-LoopGrid-Workspace=default"A successful OTLP export returns the standard empty ExportTraceServiceResponse. The response header X-LoopGrid-Accepted reports how many spans were mapped into LoopGrid decisions. LoopGrid's OTLP adapter preserves both current gen_ai.provider.name and the older gen_ai.system provider attribute when present.
This ingestion compatibility does not change the LoopGrid evidence bundle, hash-chain, signing or offline-verifier contracts.
Service API-key scopes:
ingestreadreviewadmin
Human roles:
owneradminreviewerviewer
In production mode v0.8 refuses startup when auth is disabled or bootstrap/platform-admin secrets are missing/placeholder values.
Validated/foundation paths include REST, Python SDK, TypeScript/JavaScript SDK, OpenAI helper, Anthropic helper, LangGraph helper, OpenTelemetry/OTLP HTTP (protobuf + JSON) and allow-listed MCP proxy/ingestion.
The canonical LoopGrid evidence schema remains provider-neutral. Do not couple your historical evidence model to a single vendor's telemetry schema.
The frozen v0.7.2 baseline passed the core regression suite, real-scenario, API-key lifecycle, human RBAC, MCP gateway, live OpenAI and RFC3161 protocol/imprint gates. On 2026-09-03 that baseline also passed the PostgreSQL/Docker full real scenario plus app restart, PostgreSQL restart, signer persistence, decision persistence and workspace chain-continuity validation.
LoopGrid v0.8 then passed its full Windows/Docker design-partner deployment gate on 2026-09-03: PostgreSQL posture, production safety, anonymous-access blocking, scoped service identity creation/revocation, complete refund decision lifecycle, workspace cryptographic verification, tamper detection, signed checkpoint/head binding, signer-pinned offline verification, disclosure-withheld export and OTLP ingestion.
Rerun the included validators in each new deployment environment before making environment-specific claims.
Do not describe LoopGrid evidence as physically “immutable”; use signed and tamper-evident.
v0.8 does not by itself claim:
- Production GA or a production SLA;
- legal or regulatory compliance/certification;
- live hardware-backed AWS KMS signing unless exercised in that deployment;
- trusted RFC3161 TSA signer certificate-chain validation unless explicitly configured/tested;
- validated multi-instance horizontal scaling.
docs/DECISION_EVIDENCE_PROFILE_3.0.mddocs/TRUST_MODEL.mddocs/DEPLOYMENT.mddocs/PILOT_SUCCESS_CRITERIA.mdDESIGN_PARTNER_GUIDE.mdSECURITY.mdCHANGELOG.md
Apache 2.0.