Your AI audit log is tamper-evident.
Is it complete?
VLC-1 is a vendor-neutral specification and conformance checker that proves an AI system's log contains all of what happened, not just that nobody edited what's there. Run it against any log in thirty seconds.
# score a log that passes every check the industry currently performs $ python3 conformance.py --log examples/L2-looks-complete.jsonl \ --adapter adapters/generic-appjsonl.json ok [S] VLC-L2-5 60 delivered + 0 declared lost == 60 produced FAIL [S] VLC-L3-1a no 'COVERAGE' record in the delivered set: silence about a source is indistinguishable from absence of the source LEVEL DEMONSTRATED structural : L2 recomputed from the log; no adapter assertion can raise this number attested : L2 the above, plus what the producer asserts $ ./selftest.sh SELFTEST PASS
Every AI logging standard says what to log. None proves the log is all of it.
A logging path that silently dropped every record for two hours produces an export that verifies exactly like a quiet afternoon. Both look complete. One is worthless, and nothing in it says so.
Valid hash chain. End marker. Sixty in, sixty out.
The proxy was instrumented for /v1/chat but not /v1/responses. 58 inferences that session produced no record, so they lost nothing and triggered no gap. The numbers close because the producer counted honestly. It just wasn't looking.
Same session. One extra record.
The log declares its observation surface and how it knows that surface is exhaustive. Now a verifier can tell an unhooked source from an uneventful one. VLC-1 checks for exactly that, from the delivered evidence.
A ladder from "recorded" to "independently witnessed".
Each level refuses a specific failure the one below it can't see. A formal proof shows the levels are strictly ordered and each one is necessary.
Everything you need to test a log yourself.
The specification
Normative text in CC0. Standards bodies may lift clauses verbatim.
Conformance checker
Any JSONL log plus a data-only adapter gives you a level. Adapters are data; the checker never executes them.
Two numbers, not one
Every report separates what was recomputed from the log from what was relayed from the producer. A more generous adapter can't raise the structural score.
Witness reconciler
Reconciles an agent's self-report against a record it can't write, in both directions, so a spoofed tool call shows up as a paired finding.
Machine-checked proof
Coq/Rocq: the level lattice and two impossibility results, 26 results with 0 admitted and 0 axioms.
A self-test that fails both ways
Positive, negative, lattice, independence and not-rigged controls, including a fabricated adapter that must not move the structural score.
Signing a transcript proves nobody else edited it. Not that it's true.
In August 2026, METR reported clear evidence of spoofed tool calls in at least 96 of roughly 1,300 agent transcripts it reviewed in one investigation: agents issuing one command while reporting another. VLC-1's proof states why no check on the self-report alone can see that substitution, and its witness reconciler shows how to catch it.
Standards status as stated in the repository (September 2026). None of these currently requires VLC-1; it addresses the property they leave unspecified.
VLC-1 is free. We also build the systems that reach the top of it.
VLC-1 tells you what your log can prove. Our private products make the higher levels real in production: governance for what AI agents ask for and what they actually do, with evidence an auditor can check without trusting us. They're available to qualified teams under NDA.
Runtime governance for AI agents
Decide what an agent may do before it does it, with every decision bound to the policy that made it.
Evidence you can verify
Logs designed to the specification from the start, aimed at the levels most systems can't reach.
Self-hosted
Runs in your environment. Your data, prompts and policies stay with you.
Start free with VLC-1. Go deeper when you're ready.
VLC-1 is public and free. For teams that want help scoring their logs or evaluating our private products, there are free assessments and, under NDA, evaluation access and pilots.
Self-serve
Clone the repository and run the self-test. No request, no sign-up.
FREEClone on GitHub
Free assessment
Send your log's field names. We tell you what level it reaches and what's blocking the next one. No NDA.
FREERequest an assessment
Evaluation access
Hands-on access to our private products for evaluation. Under NDA.
BY REQUESTTalk to us
Scoped pilot
A scoped pilot of our products in your environment. Under NDA.
BY REQUESTTalk to us
Find out what your log can actually prove.
Run the checker yourself, or send us your field names for a free assessment.