{"_id":"@ariada-org/haes","name":"@ariada-org/haes","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@ariada-org/haes","version":"0.1.0","description":"Hash-anchored Evidence Stream — tamper-evident append-only ledger for AI-artifact transparency under EU Regulation 2024/1689 Article 50. Schema + reference client + Merkle anchor primitives. Open source under EUPL-1.2.","license":"EUPL-1.2","type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"dependencies":{},"devDependencies":{"@types/node":"^22.10.0","rimraf":"^6.0.1","typescript":"^5.7.2","vitest":"^4.1.0","eslint":"^9.17.0","@vitest/coverage-v8":"^2.1.8"},"engines":{"node":">=22"},"keywords":["ai-transparency","eu-ai-act","article-50","hash-chain","merkle-tree","tamper-evident","ed25519","evidence","audit-log","regulatory-tech","eupl"],"homepage":"https://ariada.org/packages/haes","repository":{"type":"git","url":"git+https://github.com/ariada-org/ariada.git","directory":"packages/ariada-haes"},"bugs":{"url":"https://github.com/ariada-org/ariada/issues"},"author":{"name":"Alekszandr Bricskin","email":"git@ariada.org","url":"Agonist Development AB"},"publishConfig":{"access":"public","provenance":true},"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test":"vitest run","test:watch":"vitest","test:coverage":"vitest run --coverage","clean":"rimraf dist coverage","lint":"eslint src tests"},"_id":"@ariada-org/haes@0.1.0","_integrity":"sha512-sZniF2o+N7wfyNyJ4Nu2+benDMd30Wu9Jk1nxhBjiOwdPT/au4SqK0jJW96AIoNmoAyQSYO4SbGzKGL0szJCow==","_resolved":"/tmp/a5e49a0a9fbff7cdc5eaceb7eadaf5ed/ariada-org-haes-0.1.0.tgz","_from":"file:ariada-org-haes-0.1.0.tgz","_nodeVersion":"22.22.3","_npmVersion":"10.9.8","dist":{"integrity":"sha512-sZniF2o+N7wfyNyJ4Nu2+benDMd30Wu9Jk1nxhBjiOwdPT/au4SqK0jJW96AIoNmoAyQSYO4SbGzKGL0szJCow==","shasum":"80db06f301cce3ce388124fdb05d14c3b8058517","tarball":"https://registry.npmjs.org/@ariada-org/haes/-/haes-0.1.0.tgz","fileCount":44,"unpackedSize":98387,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ariada-org%2fhaes@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIAeRfMZt0jRocW6JDGLcZgscnUADRRB8oiI+IR8WGf7+AiEA+hqfNKY+IQ6dyFVkZtyW8i+ohNYBugpIn3jB2E/HWrs="}]},"_npmUser":{"name":"agonist","email":"ab@agonist.ai"},"directories":{},"maintainers":[{"name":"agonist","email":"ab@agonist.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/haes_0.1.0_1781536547056_0.8940030939696804"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-15T15:15:46.857Z","0.1.0":"2026-06-15T15:15:47.208Z","modified":"2026-06-15T15:15:47.654Z"},"maintainers":[{"name":"agonist","email":"ab@agonist.ai"}],"description":"Hash-anchored Evidence Stream — tamper-evident append-only ledger for AI-artifact transparency under EU Regulation 2024/1689 Article 50. Schema + reference client + Merkle anchor primitives. Open source under EUPL-1.2.","homepage":"https://ariada.org/packages/haes","keywords":["ai-transparency","eu-ai-act","article-50","hash-chain","merkle-tree","tamper-evident","ed25519","evidence","audit-log","regulatory-tech","eupl"],"repository":{"type":"git","url":"git+https://github.com/ariada-org/ariada.git","directory":"packages/ariada-haes"},"author":{"name":"Alekszandr Bricskin","email":"git@ariada.org","url":"Agonist Development AB"},"bugs":{"url":"https://github.com/ariada-org/ariada/issues"},"license":"EUPL-1.2","readme":"# @ariada-org/haes\n\nHash-anchored Evidence Stream — a tamper-evident append-only ledger for\nAI-artifact transparency under EU Regulation 2024/1689 (the EU AI Act)\nArticle 50.\n\nOpen source under [EUPL-1.2](./LICENSE). Zero runtime dependencies.\nNode 22 LTS or newer.\n\n## What this package does\n\nEvery AI artifact a regulated product emits — a chatbot reply, an\nAI-generated UI string, an AI-suggested code patch, an AI-rendered\nimage — gets written as an entry that records the model id, the prompt\ntemplate fingerprint, the input redaction profile, the output checksum,\nthe deployer's decision (shipped / rewritten / blocked), an Ed25519\nsignature, and a SHA-256 link to the previous entry. Mutating any entry\nmechanically invalidates every subsequent entry's `prev_hash`, so\ntampering detection becomes deterministic rather than discretionary.\n\nDaily Merkle roots over the chain can be published to a third-party\npublic log so regulators and auditors can verify integrity without\ntrusting the deployer's tooling.\n\n## Install\n\n```bash\nnpm install @ariada-org/haes\n```\n\n## Usage\n\n```ts\nimport {\n  HaesClient,\n  buildMerkleRoot,\n  generateEd25519Keypair,\n  sha256Hex,\n  verifyInclusionProof,\n  buildInclusionProof,\n} from \"@ariada-org/haes\";\n\nconst key = generateEd25519Keypair();\nconst client = new HaesClient({ signingKey: key });\n\nawait client.append({\n  payload: {\n    model_id: \"anthropic:claude-3-7-sonnet\",\n    model_version: \"20250203\",\n    prompt_template_fingerprint: sha256Hex(\"system prompt v1\"),\n    input_redaction_profile: \"pii-strict-v2\",\n    output_checksum: sha256Hex(\"output bytes\"),\n    decision: \"shipped\",\n    signing_key_id: key.keyId,\n  },\n});\n\n// End-to-end chain verification.\nconst verdict = await client.verifyAll(() => key.publicKeyRaw);\nconsole.log(verdict.valid);\n\n// Daily Merkle root over all entries — anchor it to a public log of choice.\nconst entries = await client.snapshot();\nconst hashes = entries.map((e) => e.entry_hash);\nconst root = buildMerkleRoot(hashes);\n\n// Inclusion proof for one entry against that root.\nconst proof = buildInclusionProof(hashes, 0);\nverifyInclusionProof(proof, root ?? \"\");\n```\n\n## API\n\n| Export                   | Type     | Description                                         |\n| ------------------------ | -------- | --------------------------------------------------- |\n| `HaesClient`             | class    | Append + verify orchestrator over a storage backend |\n| `buildEntry`             | function | Build a signed entry from an `AppendInput`          |\n| `computeEntryHash`       | function | Canonical SHA-256 over the JCS-encoded pre-image    |\n| `verifyEntry`            | function | Single-entry chain-link + signature verifier        |\n| `verifyChain`            | function | Sequential whole-chain verifier                     |\n| `buildMerkleRoot`        | function | SHA-256 Merkle root over leaf hashes                |\n| `buildInclusionProof`    | function | Per-entry inclusion proof against the daily root    |\n| `verifyInclusionProof`   | function | Re-verify a leaf-to-root proof                      |\n| `canonicalize`           | function | RFC 8785 JSON canonicalization (JCS)                |\n| `generateEd25519Keypair` | function | Fresh Ed25519 signing keypair (Node `crypto`)       |\n| `InMemoryStorage`        | class    | Reference `HaesStorageBackend` implementation       |\n\n## Standards referenced\n\n- [RFC 8785 — JSON Canonicalization Scheme (JCS)](https://www.rfc-editor.org/rfc/rfc8785)\n- [RFC 8032 — Edwards-Curve Digital Signature Algorithm (Ed25519)](https://www.rfc-editor.org/rfc/rfc8032)\n- [FIPS 180-4 — SHA-256](https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf)\n- [RFC 6962 §2.1 — Merkle hash trees](https://www.rfc-editor.org/rfc/rfc6962#section-2.1)\n- [Crockford base32 — ULID layout](https://github.com/ulid/spec)\n\n## License\n\nEUPL-1.2 for code; CC-BY-SA-4.0 for prose; CC0-1.0 for build config.\nSee [LICENSE](./LICENSE) and [NOTICE](./NOTICE).\n","readmeFilename":"README.md","_rev":"1-be778e785eac5f57b0e681b6a9d06340"}