
You let an autonomous agent touch your infrastructure. Can you prove what it did?
A log is a claim. VIRP makes infrastructure operations accountable for humans, scripts, and AI agents, with signed records others can check.
Policy sets the limits. Required approvals are signed. Evidence is captured at the boundary, including signed refusals.
Published verification results can be reproduced from bytes.
Captured at the boundary. Presented for review. Checked independently.
The gate decides
On enforcing drivers, VIRP checks commands from humans, scripts, and AI agents against policy and a per-vendor grammar. Permitted reads run; riskier operations wait for a person’s signed approval of the exact command and device. Forbidden operations are refused and recorded. Shadow-mode drivers record decisions without enforcing the approval gate. The record shows what ran, what was approved, and what was refused.

VIRP records it
VIRP signs and chains evidence captured at the gate. A gate record of a device response is not a device-originated signature. Refusals are signed too. Open protocol, Apache 2.0, IETF drafts published.

Docket presents it
Reads the chain and presents the sealed bundle and report. Labels verified evidence, operator attestations, and gaps. Presentation never makes the evidence stronger.

virp-verify checks it
Standalone binary, published hash, no network. Run the same bundle with the same verifier and trust keys to reproduce the verdict and exit code.
Five things, one open protocol.

Docket for VIRP
The evidence book. Docket presents a sealed VIRP bundle and a claims-versus-observations report, with the exact virp-verify command to reproduce the verdict. It shows what the evidence supports, who attested to it, and where the gaps remain.
- Cryptographically verified and operator-attested evidence labeled on the face of the report
- Gaps stated as gaps, never smoothed
- The presentation component holds no signing key and exposes no signing API

Custody for VIRP
Signed video for places nobody is standing: lift stations, pump houses, cultivation rooms, lots. Custody binds each segment to a VIRP chain as it is captured, so footage carries its own chain of custody and a missing minute is recorded as a missing minute. The end-to-end signed-all-the-way-through claim is still gated: the September 1 review left three camera-path findings open.
- Foundation tier: NDAA-compliant cameras, cabling, install, retention
- Custody tier: Foundation plus signing and detection, verifiable offline
- Exports as a Docket bundle
$ virp-verify bundle-313/ --pin examiner-key.json session autopilot-chainwalk 2 entries entry_hashes VERIFIED entry_signatures VERIFIED session_key_binding VERIFIED session burnin-reenabled 3 entries entry_hashes FAILED seq 2: body hash mismatch entry_signatures FAILED seq 2: signature does not cover body session_key_binding VERIFIED overall FAILED
virp-verify
A paid verifier would contradict the whole point. This standalone verifier is free, open, and dependency-free. Bundle-supplied keys can establish CRYPTOGRAPHICALLY-CONSISTENT: the cryptography checks out, but you have not selected a trust anchor. Supply a trusted public key out of band with --pin for CRYPTOGRAPHICALLY-VERIFIED. Keep the bundle, verifier version, and trust keys to reproduce the result offline.
- Static binary, published SHA-256, reproducible build
- Five verdicts, seven exit codes, every failure names the entry
- Independent checks: a damaged signature does not move the hash result

VIRP
The Verified Infrastructure Response Protocol underneath everything here. Policy bounds operations; signed approvals authorize gated changes; a hash-linked chain records the evidence. For humans, scripts, and AI agents. Open source, IETF drafts published. The Rust rebuild and unified management UI are work in progress.
Read the protocolvirp-witness
Records a chain checkpoint
virp-witness records a signed chain checkpoint in an append-only log. Receipts let you check inclusion and compare an export with a witnessed checkpoint; they do not prove device truth, event time, or that every event was captured. Third Level IT operates this witness and one of the chains it witnesses. That is not independent operation. More independence requires a separately operated witness.
Four attacks on our own evidence. Four results you can check.
These four tamper cases have recorded verifier results. Reproduce them with the matching bundles, hashes, and pinned verifier release; they are not a claim about every possible attack.
Built on VIRP
Partner platforms are separate products built on VIRP, with their own features and limits.
Fresh review sessions built it, ran it, and tried to break it. The findings stay on record.
Most were AI-assisted reviews in fresh, isolated sessions. They are not reviews by a firm, and we say so.
| Date | What they did | Top finding, and what happened |
|---|---|---|
| 2026-08-05 | Built and ran the C, Python, and Go suites; wrote four attack harnesses | Approver signatures not in the chain. Fixed with the Ed25519 migration. |
| 2026-08-15 | Built and ran the suite; independently confirmed two prior fixes | Restart laundering. Fixed, confirmed by the reviewer. |
| 2026-08-21 | Architecture review: needed or just neat? | Half of VIRP is unnecessary if you trust the operator. You should not have to. |
| 2026-09-01 | Re-review of the current tree | Three camera-path findings gating the “signed all the way through” claim. Open. |
Deployed by Third Level IT.
You don't buy an appliance. You get an engineer who installs the gate, fits it to your devices, runs the first sealed bundle, and walks your examiner through it. Day rate, no retainer. Metro Detroit on site, elsewhere remote with a first visit.