{"_id":"@asterpay/attest-sdk","_rev":"2-b0e3677f5a44699b9e744bfdfcbade20","name":"@asterpay/attest-sdk","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@asterpay/attest-sdk","version":"0.1.0","keywords":["eu-ai-act","compliance","ai","gdpr","audit","typescript"],"license":"MIT","_id":"@asterpay/attest-sdk@0.1.0","maintainers":[{"name":"asterpay","email":"petteri@asterpay.io"}],"homepage":"https://github.com/AsterPay/attest","bugs":{"url":"https://github.com/AsterPay/attest/issues"},"dist":{"shasum":"8cdacc060a192d611024c14644146a64734fc6c6","tarball":"https://registry.npmjs.org/@asterpay/attest-sdk/-/attest-sdk-0.1.0.tgz","fileCount":45,"integrity":"sha512-dP0pkzgvScKhKLDQxSfOqFDc3oGOT6Gr7fQGR9GUkNMo/z/7UIadN/wP8Jvl9TclltyNs2I4Hl3lbBSWuMBRKw==","signatures":[{"sig":"MEYCIQDk0hFuvkhFGToDodw8/goPxdqszOnPrl25/CllMF3sMAIhANg2pjWaHbr7Le+Kny4d9GuaobpLW5ExrQqfPztaRrFl","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68615},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"2441e78413828b9bccae4e56881900c7959acc05","scripts":{"test":"vitest run","build":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"asterpay","email":"petteri@asterpay.io"},"repository":{"url":"git+https://github.com/AsterPay/attest.git","type":"git"},"_npmVersion":"11.6.2","description":"EU AI Act compliance toolkit for TypeScript — scanner, risk classification, docs, audit logging.","directories":{},"_nodeVersion":"24.13.0","dependencies":{"typescript":"^5.7.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.5","@types/node":"^20.11.16"},"_npmOperationalInternal":{"tmp":"tmp/attest-sdk_0.1.0_1774428827376_0.5562959620016692","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@asterpay/attest-sdk","version":"0.1.1","description":"EU AI Act compliance toolkit for TypeScript — scanner, risk classification, docs, audit logging.","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsc","typecheck":"tsc --noEmit","test":"vitest run"},"keywords":["eu-ai-act","compliance","ai","gdpr","audit","typescript"],"license":"MIT","repository":{"type":"git","url":"git+https://github.com/AsterPay/attest.git"},"homepage":"https://github.com/AsterPay/attest","dependencies":{"typescript":"^5.7.3"},"devDependencies":{"@types/node":"^20.11.16","vitest":"^3.0.5"},"engines":{"node":">=18.0.0"},"gitHead":"53e0a343f3c99aa36a2446e2df5b2766392364a3","_id":"@asterpay/attest-sdk@0.1.1","bugs":{"url":"https://github.com/AsterPay/attest/issues"},"_nodeVersion":"24.13.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-wI6oQZqYlTNG8CExsqBYYfY2Fq5AWIP72fb9gQ8MgNCNxH/QZZlj4JrOH8bVGyj4bQJ4cE6cZgGqN9FS5nuM/g==","shasum":"4f8aff6efb85c7230d024b5e1a327fc1b39f1700","tarball":"https://registry.npmjs.org/@asterpay/attest-sdk/-/attest-sdk-0.1.1.tgz","fileCount":46,"unpackedSize":73734,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIElBCKloBnsJ7ziyl8O6yQqTYxNPewVMArXTZaIuAvWUAiAvF0Cyy1NPn2e3BHVM0xWqUPnVxs0KTBd1F8syz9kyNw=="}]},"_npmUser":{"name":"asterpay","email":"petteri@asterpay.io"},"directories":{},"maintainers":[{"name":"asterpay","email":"petteri@asterpay.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/attest-sdk_0.1.1_1775408740360_0.49906989860927875"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-25T08:53:47.310Z","modified":"2026-04-05T17:05:40.635Z","0.1.0":"2026-03-25T08:53:47.514Z","0.1.1":"2026-04-05T17:05:40.531Z"},"bugs":{"url":"https://github.com/AsterPay/attest/issues"},"license":"MIT","homepage":"https://github.com/AsterPay/attest","keywords":["eu-ai-act","compliance","ai","gdpr","audit","typescript"],"repository":{"type":"git","url":"git+https://github.com/AsterPay/attest.git"},"description":"EU AI Act compliance toolkit for TypeScript — scanner, risk classification, docs, audit logging.","maintainers":[{"name":"asterpay","email":"petteri@asterpay.io"}],"readme":"# Attest — EU AI Act compliance in one SDK\r\n\r\n**Powered by [AsterPay](https://asterpay.io)** — trust & settlement for AI commerce.\r\n\r\nAttest helps EU teams **discover AI usage in code**, **classify risk heuristically**, **generate Annex IV-style documentation scaffolds**, and **keep tamper-evident audit logs** for AI inferences.\r\n\r\n> **Not legal advice.** Attest is a developer tool. Always involve qualified counsel for conformity assessment and regulatory obligations.\r\n\r\n## Try it now (zero install)\r\n\r\n```bash\r\ncd your-project\r\nnpx @asterpay/attest scan\r\n```\r\n\r\nThat's it. Attest scans your TypeScript/JavaScript source for AI SDK imports (OpenAI, Anthropic, Google AI, LangChain, etc.) and reports what it finds:\r\n\r\n```\r\n📦 Scanned 42 files in ./src\r\n\r\n  src/chat/agent.ts\r\n    → openai (line 1)        ai-sdk\r\n    → @anthropic-ai/sdk (line 2)\r\n\r\n  src/scoring/classifier.ts\r\n    → langchain (line 3)     ai-sdk\r\n\r\n🔍 3 AI-related imports found across 2 files\r\n⚠️  Risk classification: HIGH (Annex III keywords detected)\r\n```\r\n\r\n## Install\r\n\r\n```bash\r\nnpm install -g @asterpay/attest\r\n```\r\n\r\n## Quick start\r\n\r\n```bash\r\ncd your-project\r\n\r\n# 1) See which AI SDKs your code imports (AST scan)\r\nattest scan\r\n\r\n# 2) Heuristic checks: transparency / logging / oversight signals\r\nattest check\r\n\r\n# 3) Generate Annex IV–style Markdown scaffolds (fill with counsel)\r\nattest docs -o ./compliance\r\n\r\n# 4) Local static dashboard (countdown + CLI hints)\r\nattest dashboard\r\n```\r\n\r\n### What each command does\r\n\r\n| Step | Command | What you get |\r\n|------|---------|-------------|\r\n| **Scan** | `attest scan` | List of every AI SDK import in your codebase, file by file |\r\n| **Check** | `attest check` | Compliance signals: do you have logging? transparency disclosures? human oversight patterns? |\r\n| **Docs** | `attest docs -o ./compliance` | Three Markdown files: `technical-documentation.md`, `risk-assessment.md`, `conformity-declaration.md` — pre-filled scaffolds for Annex IV, ready for your legal team |\r\n| **Dashboard** | `attest dashboard` | Local web UI with EU AI Act deadline countdown + quick links |\r\n\r\n## Packages\r\n\r\n| Package | npm | Description |\r\n|---------|-----|-------------|\r\n| `@asterpay/attest` | [![npm](https://img.shields.io/npm/v/@asterpay/attest)](https://www.npmjs.com/package/@asterpay/attest) | CLI (`attest`) + re-exports SDK |\r\n| `@asterpay/attest-sdk` | [![npm](https://img.shields.io/npm/v/@asterpay/attest-sdk)](https://www.npmjs.com/package/@asterpay/attest-sdk) | Programmatic API |\r\n\r\n### CLI reference\r\n\r\n| Command | Purpose |\r\n|--------|---------|\r\n| `attest scan [-r DIR]` | List AI-related package imports per file |\r\n| `attest check [-r DIR]` | Compliance **signals** (not legal sign-off) |\r\n| `attest docs -o DIR [-r DIR] [--name] [--provider]` | Write `technical-documentation.md`, `risk-assessment.md`, `conformity-declaration.md` |\r\n| `attest export [--from ISO]` | Dump audit log JSON (needs prior `Attest.track()` usage) |\r\n| `attest verify [-r DIR]` | Verify audit JSONL hash chain; exits `1` if broken |\r\n| `attest dashboard [-p PORT]` | Serve local dashboard |\r\n\r\nProject metadata for `attest docs` (optional): `.attest/config.json` — see below.\r\n\r\nOptional project metadata (for `attest docs`):\r\n\r\n```json\r\n// .attest/config.json\r\n{\r\n  \"system\": {\r\n    \"name\": \"Customer Support Bot\",\r\n    \"provider\": \"Your Company Ltd\",\r\n    \"description\": \"Tier-1 support assistant\"\r\n  }\r\n}\r\n```\r\n\r\n## Programmatic usage\r\n\r\n```typescript\r\nimport { Attest } from '@asterpay/attest';\r\n\r\nconst attest = new Attest({\r\n  system: {\r\n    name: 'My AI feature',\r\n    provider: 'My Org',\r\n  },\r\n  projectRoot: process.cwd(),\r\n});\r\n\r\nconst risk = await attest.classifyRisk();\r\nconst report = attest.check();\r\n\r\nawait attest.track(\r\n  async () => {\r\n    /* your OpenAI / Anthropic call */\r\n    return { ok: true };\r\n  },\r\n  { purpose: 'support', humanOversight: 'available', containsPII: false },\r\n);\r\n```\r\n\r\n## Monorepo layout\r\n\r\n```\r\nattest/\r\n  packages/\r\n    sdk/     @asterpay/attest-sdk\r\n    cli/     @asterpay/attest\r\n  landing/   marketing site (static)\r\n  docs/      publishing, domains, cloud roadmap\r\n```\r\n\r\n## Why?\r\n\r\nThe EU AI Act (Regulation 2024/1689) requires companies deploying AI in the EU to document, classify, and audit their AI systems. The **August 2, 2026** deadline for high-risk systems is approaching fast.\r\n\r\nAttest doesn't replace legal counsel — it gives your engineering team a head start:\r\n\r\n- **Discovery** — \"Which of our 200 microservices actually use AI SDKs?\"\r\n- **Risk signal** — \"Does our code have the logging/oversight patterns regulators expect?\"\r\n- **Documentation** — \"Give us Annex IV scaffolds so legal doesn't start from a blank page\"\r\n- **Audit trail** — \"Every AI inference is logged with SHA-256 hash chaining\"\r\n\r\n## Contributing\r\n\r\n```bash\r\ngit clone https://github.com/AsterPay/attest\r\ncd attest\r\nnpm install\r\nnpm run build\r\nnpm test\r\n```\r\n\r\nSee [docs/GITHUB_SETUP.md](docs/GITHUB_SETUP.md) and [docs/PUBLISH.md](docs/PUBLISH.md) for setup and publishing details.\r\n\r\n## License\r\n\r\nMIT © AsterPay contributors\r\n","readmeFilename":"README.md"}