1. X
  2. Vaara
Log inSign up
Vaara
83 posts
user avatar
Vaara
@vaara_io
Tamper-evident runtime evidence for AI agents. Scores each MCP tool call, writes a hash-chained record bound to TPM 2.0 + IMA, verifiable offline. OSS.
Finland
vaara.io
Joined March 2026
14
Following
15
Followers
RepliesRepliesMediaMedia
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

  • Pinned
    user avatar
    Vaara
    @vaara_io
    Jul 20
    Your AI agent paid over x402, or under an AP2 mandate. Now prove what it was allowed to do, and what it did, to someone with no reason to trust you. Vaara 1.38.0 makes it one signed receipt. Verify offline, from the bytes. EU DSS validator: PASSED. AGPL. #AIagents #eIDAS
    00:00
    7
  • user avatar
    Vaara
    @vaara_io
    Jul 14
    An AI agent's audit receipt, timestamped by a qualified trust service on the EU trusted lists, validated by the European Commission's own DSS tool: PASSED, "Qualified timestamp". The EU's own validator judging our evidence. Vaara 1.30.0, AGPL: github.com/vaaraio/vaara
    00:00
    10
  • user avatar
    Vaara
    @vaara_io
    Jun 24
    A signed AI audit log can still be missing entries. That's the gap that matters. Vaara v1.14.0 ships a standalone checker that re-derives every verdict from the receipt bytes and a public key alone, with none of my code in the loop. Verify it yourself. #EUAIAct #AgenticAI
    7
  • user avatar
    Vaara
    @vaara_io
    Jun 12
    Shipped Vaara 0.70.0: a signed AI execution record bound to a TPM 2.0 quote + the kernel IMA log, then a continuous chain of quotes. Anyone re-verifies every link offline, trusting no operator. Ran it on my own AMD fTPM: tier=continuous. #ConfidentialComputing #TPM #AIGovernance
    11
  • user avatar
    Vaara
    @vaara_io
    May 29
    vaara 0.43 is out. Every allowed MCP tool call now produces a signed before-and-after pair: a SEP-2787 attestation of the request before it runs, and an execution receipt of the outcome after, cryptographically linked. #MCP #ModelContextProtocol #AIAgents #AIGovernance
    8