Attestation Platforms¶
Hardware evidence can support TRACE Level 1. Level 2 additionally requires transparency anchoring; selecting a hardware platform does not establish either level by itself. A recipient must verify the evidence and its binding to the record-signing key.
Platform names and evidence¶
Standalone TRACE records use the names in the canonical schema. Runtime configuration names such as cMCP's sev-snp, tdx, and opaque are not interchangeable with these wire values.
| Platform guide | Standalone runtime.platform | Evidence to appraise |
|---|---|---|
| AMD SEV-SNP | amd-sev-snp or the profile-specific azure-cvm-sev-snp | Signed SNP report, certificate chain, measurement, and key/challenge binding |
| Intel TDX | intel-tdx | Signed TD quote, collateral, measurement registers, and key/challenge binding |
| NVIDIA H100 | nvidia-h100 | GPU attestation evidence and its explicit binding to the workload and signing key |
| TPM2 | tpm2 | Quote, selected PCRs, trusted attestation-key provenance, and challenge binding |
| Software | software-only | Software signature and producer-defined commitments; no hardware assurance |
The schema also registers other platform identifiers. Registration is not a claim that this Python SDK collects or appraises evidence for every platform.
Vendor annexes¶
A vendor annex maps one producer onto the Trust Record. Annexes are informative and reviewed by the vendor author and one Maintainer, per GOVERNANCE.
| Annex | runtime.platform | What the producer's evidence is |
|---|---|---|
| Bernstein | software-only | An Ed25519-signed record over a hash-chained run journal, with a deterministic coordination sequence a verifier can re-derive. No hardware assurance; Level 0 |
What the SDK checks¶
agentrust_trace.verify_record checks the standalone record's schema, profile, signature against a trusted key, freshness, and configured nonce/revocation inputs. It does not collect a hardware quote or turn a platform string into verified hardware evidence. There is no agentrust-trace verify-hardware command in this package.
Use a verifier for the producing runtime and evidence format. For cMCP's distinct RuntimeClaim envelope, follow cMCP verification and its hardware-validation record.
Continue to trust levels or interpreting hardware evidence.