
You let an autonomous agent touch your infrastructure. Can you prove what it did?
A log the agent wrote is a claim. A signed record a stranger can check is evidence. VIRP Systems builds the evidence.
Refusals are signed too, so the record includes what the agent was not allowed to do.
Every claim on this site can be reproduced from bytes.
Proved at the device. Presented to the examiner. Checked by anyone.
The gate decides
Every command an agent proposes on an enforcing driver is classified against a per-vendor grammar before it runs. Reads execute and are signed. Riskier operations stop and produce a proposal a person must sign, and the approval is signed too. Forbidden operations are never transmitted, and the refusal is signed. The record holds what the agent did and what it was not allowed to do.

VIRP proves it
Every command an agent runs and every response a device gives is signed at the boundary and chained. Refusals are signed too. Open protocol, Apache 2.0, IETF drafts published.

Docket presents it
Reads the chain, assembles a sealed bundle, renders the report an examiner can read. Labels evidence by how strong it actually is and never upgrades it.

virp-verify checks it
One static binary, published hash, no network. Anyone can run it against a bundle and get a verdict and an exit code without trusting us.
Five things, one open protocol.

Docket for VIRP
The evidence book. Docket reads a VIRP chain and produces what you hand to an examiner: a sealed bundle, a claims-versus-observations report, and a footer that prints the exact virp-verify command that reproduces the verdict.
- Cryptographically verified and operator-attested evidence labeled on the face of the report
- Gaps stated as gaps, never smoothed
- Holds no signing key and no signing API, by design

Custody for VIRP
Signed video for places nobody is standing: lift stations, pump houses, cultivation rooms, lots. Custody binds each segment to a VIRP chain as it is captured, so footage carries its own chain of custody and a missing minute is recorded as a missing minute. The end-to-end signed-all-the-way-through claim is still gated: the September 1 review left three camera-path findings open.
- Foundation tier: NDAA-compliant cameras, cabling, install, retention
- Custody tier: Foundation plus signing and detection, verifiable offline
- Exports as a Docket bundle
$ virp-verify bundle-313/ --pin examiner-key.json session autopilot-chainwalk 2 entries entry_hashes VERIFIED entry_signatures VERIFIED session_key_binding VERIFIED session burnin-reenabled 3 entries entry_hashes FAILED seq 2: body hash mismatch entry_signatures FAILED seq 2: signature does not cover body session_key_binding VERIFIED overall FAILED
virp-verify
A paid verifier would contradict the whole point. This one is free, open, and dependency-free. It will check a bundle's signatures under the key the bundle itself carries, and report exactly that — CRYPTOGRAPHICALLY-CONSISTENT, the cryptography held with no examiner-selected trust anchor. What it refuses is to treat that key as the anchor. Only a public key you supply out of band, with --pin, earns CRYPTOGRAPHICALLY-VERIFIED.
- Static binary, published SHA-256, reproducible build
- Five verdicts, seven exit codes, every failure names the entry
- Independent checks: a damaged signature does not move the hash result

VIRP
The Verified Infrastructure Response Protocol underneath everything here. Signed observations, a bounded command grammar, a propose-and-approve gate, and a hash-linked chain. Reviewed in the open, drafts at the IETF, source on GitHub.
Read the protocolvirp-witness
fixes it in time
A signed chain proves what a device said and that nothing has been edited. It does not prove when, and it does not prove you are holding all of it. Both gaps have the same cause: the operator writes the timestamps and decides where the chain ends. virp-witness closes them by having a second party record that a given chain state existed at a given moment, in an append-only log anyone can check.
We attacked our own evidence. The verifier named every one.
Four bundles, four attacks, kept and prepared for publication. The bundles and their hashes publish with the pinned virp-verify release, so you can run them yourself.
Independent review sessions built it, ran it, and tried to break it. We publish what they found.
Most were AI-assisted reviews in fresh, isolated sessions. They are not reviews by a firm, and we say so.
| Date | What they did | Top finding, and what happened |
|---|---|---|
| 2026-08-05 | Built and ran the C, Python, and Go suites; wrote four attack harnesses | Approver signatures not in the chain. Fixed with the Ed25519 migration. |
| 2026-08-15 | Built and ran the suite; independently confirmed two prior fixes | Restart laundering. Fixed, confirmed by the reviewer. |
| 2026-08-21 | Architecture review: needed or just neat? | Half of VIRP is unnecessary if you trust the operator. You should not have to. |
| 2026-09-01 | Re-review of the current tree | Three camera-path findings gating the “signed all the way through” claim. Open. |
Deployed by Third Level IT.
You don't buy an appliance. You get an engineer who installs the gate, fits it to your devices, runs the first sealed bundle, and walks your examiner through it. Day rate, no retainer. Metro Detroit on site, elsewhere remote with a first visit.