“If an AI makes a mistake, the algorithm isn’t sued—the bank is. Yourinput_hashand keyedsignatureprovide tamper evidence.”
Verification receipts
CrossGuard, UCPIntegration, and the built-in OpenResponsesIntegration tools create receipts automatically. Custom Open Responses tools get a receipt only if their verification_fn creates one. Direct calls to the other guards (for example ComplianceGuard.verify_aml_flag) return a result object without a receipt; create one yourself with ReceiptGenerator when you need an audit record:
Receipt fields
Every field below is part of the signed payload.Cryptographic signature
Since v3.0.0, signatures are keyed HMAC-SHA256 over the full canonical receipt — every field in the table above, as sorted compact JSON. The verifier holds the key; there is no default key. The earlier unkeyedget_signature() (no argument) was removed in v3.0.0.
computed_value, violations,
status, proof_steps, anything in the table — produces a different
signature. This is tamper evidence for holders of the key: it does not
establish issuer identity, third-party verifiability, or
non-repudiation. Public-key attestation (ES256) is planned separately —
see qwed-finance#37.
Audit log
Aggregate receipts for regulatory reporting:Query failed verifications
Regulatory alignment
Adversarial defense
We test against “jailbroken” LLMs:Test suites
For compliance officers
When a regulator asks: “How do you verify AI decisions?” Show them:- Input Hash — Proof of what the LLM said
- Timestamp — When verification occurred
- Engine Signature — Which solver verified (Z3/SymPy)
- Proof Steps — Symbolic derivation of truth
- Receipt Signature — Keyed tamper evidence (HMAC)
signature field; get_signature(signing_key)
computes it on demand from the full receipt. Export both artifacts under
unique paths — one pair per receipt — so no export overwrites an earlier
audit record:
receipt-abc-123.json contains the full receipt:
get_signature(signing_key) does and compare it with the stored
signature. Every receipt name found in the directory is checked, a
.json or .sig file without its partner counts as a failure, and one
failure never stops the rest.
The auditor needs the verifier’s HMAC key. It is never stored with the
receipts, so provision it to the auditor through a secret store or an
environment variable:
Related pages
- Previous: The 11 guards — Deep dive into each verification guard
- Next: QWED UCP: transaction verification for AI commerce — Connect finance verification to AI-driven commerce flows
- See Also: QWED Open Responses: verified tool calls for AI agents — Add runtime verification to agent tool calls
Source code and adversarial tests: github.com/QWED-AI/qwed-finance