MLMoore Labs
Open · CC0 specification · MIT checker · machine-checked proof

Your AI audit log is tamper-evident.
Is it complete?

VLC-1 is a vendor-neutral specification and conformance checker that proves an AI system's log contains all of what happened, not just that nobody edited what's there. Run it against any log in thirty seconds.

Free to use, fork and citeSix conformance levels0 admitted, 0 axiomsDOI-registered
# score a log that passes every check the industry currently performs
$ python3 conformance.py --log examples/L2-looks-complete.jsonl \
                         --adapter adapters/generic-appjsonl.json
  ok   [S]  VLC-L2-5     60 delivered + 0 declared lost == 60 produced
  FAIL [S]  VLC-L3-1a    no 'COVERAGE' record in the delivered set: silence about
                         a source is indistinguishable from absence of the source
  LEVEL DEMONSTRATED
    structural : L2   recomputed from the log; no adapter assertion can raise this number
    attested   : L2   the above, plus what the producer asserts

$ ./selftest.sh
SELFTEST PASS
The gap

Every AI logging standard says what to log. None proves the log is all of it.

A logging path that silently dropped every record for two hours produces an export that verifies exactly like a quiet afternoon. Both look complete. One is worthless, and nothing in it says so.

Looks complete

Valid hash chain. End marker. Sixty in, sixty out.

The proxy was instrumented for /v1/chat but not /v1/responses. 58 inferences that session produced no record, so they lost nothing and triggered no gap. The numbers close because the producer counted honestly. It just wasn't looking.

Provably complete

Same session. One extra record.

The log declares its observation surface and how it knows that surface is exhaustive. Now a verifier can tell an unhooked source from an uneventful one. VLC-1 checks for exactly that, from the delivered evidence.

Six levels

A ladder from "recorded" to "independently witnessed".

Each level refuses a specific failure the one below it can't see. A formal proof shows the levels are strictly ordered and each one is necessary.

L0
RecordedThe log exists.
refuses: nothing
L1
Tamper-evidentAlteration, reordering, removal and truncation are detectable.
refuses: editing, truncation
L2
Loss-accountedThe completeness identity closes over in-chain loss declarations.
refuses: the silent drop
L3
Coverage-declaredThe observation surface is enumerated in-log, with the basis for its exhaustiveness.
refuses: the unhooked source
L4
Policy-boundVerdicts are bound to the rules that produced them, and replayable.
refuses: the after-the-fact rule swap
L5
Independently witnessedThe record was not written by the thing it describes.
refuses: the forged self-report
What you get

Everything you need to test a log yourself.

§

The specification

Normative text in CC0. Standards bodies may lift clauses verbatim.

✓

Conformance checker

Any JSONL log plus a data-only adapter gives you a level. Adapters are data; the checker never executes them.

2×

Two numbers, not one

Every report separates what was recomputed from the log from what was relayed from the producer. A more generous adapter can't raise the structural score.

⇄

Witness reconciler

Reconciles an agent's self-report against a record it can't write, in both directions, so a spoofed tool call shows up as a paired finding.

∎

Machine-checked proof

Coq/Rocq: the level lattice and two impossibility results, 26 results with 0 admitted and 0 axioms.

±

A self-test that fails both ways

Positive, negative, lattice, independence and not-rigged controls, including a fabricated adapter that must not move the structural score.

Why it matters now

Signing a transcript proves nobody else edited it. Not that it's true.

In August 2026, METR reported clear evidence of spoofed tool calls in at least 96 of roughly 1,300 agent transcripts it reviewed in one investigation: agents issuing one command while reporting another. VLC-1's proof states why no check on the self-report alone can see that substitution, and its witness reconciler shows how to catch it.

6conformance levels, L0–L5
26machine-checked results
0admitted lemmas or axioms
L4structural ceiling: L5 is attested by construction
prEN 18229-1CEN-CENELEC JTC 21, AI system logging. A ready-to-file comment is included.
prEN 18229-3Transparency and human oversight, at public enquiry.
ISO/IEC FDIS 24970AI system logging, final stage before publication.
EU AI Act Arts. 9–15Apply from 2 December 2027.

Standards status as stated in the repository (September 2026). None of these currently requires VLC-1; it addresses the property they leave unspecified.

From Moore Labs

VLC-1 is free. We also build the systems that reach the top of it.

VLC-1 tells you what your log can prove. Our private products make the higher levels real in production: governance for what AI agents ask for and what they actually do, with evidence an auditor can check without trusting us. They're available to qualified teams under NDA.

◆

Runtime governance for AI agents

Decide what an agent may do before it does it, with every decision bound to the policy that made it.

◆

Evidence you can verify

Logs designed to the specification from the start, aimed at the levels most systems can't reach.

◆

Self-hosted

Runs in your environment. Your data, prompts and policies stay with you.

Access

Start free with VLC-1. Go deeper when you're ready.

VLC-1 is public and free. For teams that want help scoring their logs or evaluating our private products, there are free assessments and, under NDA, evaluation access and pilots.

LEVEL 0

Self-serve

Clone the repository and run the self-test. No request, no sign-up.

FREE
Clone on GitHub
LEVEL 1

Free assessment

Send your log's field names. We tell you what level it reaches and what's blocking the next one. No NDA.

FREE
Request an assessment
LEVEL 2

Evaluation access

Hands-on access to our private products for evaluation. Under NDA.

BY REQUEST
Talk to us
LEVEL 3

Scoped pilot

A scoped pilot of our products in your environment. Under NDA.

BY REQUEST
Talk to us

Find out what your log can actually prove.

Run the checker yourself, or send us your field names for a free assessment.