cloakllm-verifier
v0.12.0
Published
Independently verify CloakLLM audit artifacts (hash chain, RFC 3161 timestamps, KeyManifest provenance, compliance reports) without the PII-detection stack or trusting CloakLLM's code.
Maintainers
Readme
cloakllm-verifier (JS)
Independently verify CloakLLM audit artifacts — without the PII-detection stack, and without trusting CloakLLM's code. (JavaScript; the Node mirror of the Python cloakllm-verifier.)
It reuses CloakLLM's own verification code (single source of truth — no reimplementation, no drift) and adds zero runtime dependencies beyond cloakllm itself (which is zero-dep). A lean install for auditors, regulators, and CI that need to check, not produce.
npm install cloakllm-verifierCLI
cloakllm-verify audit ./cloakllm_audit # hash-chain integrity
cloakllm-verify timestamp ./cloakllm_audit # offline RFC 3161 checkpoint tokens
cloakllm-verify keys cert.json --manifest m.json # KeyManifest provenance + revocation
cloakllm-verify report report.json ./cloakllm_audit # re-validate a compliance report
cloakllm-verify all ./cloakllm_audit # everything, one exit code
cloakllm-verify audit ./cloakllm_audit --json # machine-readable (CI)Exit code 0 = verified, 1 = failed/invalid. Output is ASCII-only.
API
const { verifyAll } = require('cloakllm-verifier');
const r = verifyAll('./cloakllm_audit');
if (!r.ok) throw new Error(JSON.stringify(r)); // { ok, audit, timestamps, ... }What it checks
- Hash-chain integrity — recomputes every SHA-256 link from the canonical JSON; any tampered, reordered, deleted, or relinked entry fails.
- RFC 3161 trusted timestamps — offline-verifies every
chain_checkpointtoken; reports the earliest provable time. - KeyManifest provenance + revocation — verifies a signed certificate against its published KeyManifest and a root-signed RevocationList.
- Compliance-report re-validation — independently re-verifies the audit chain a report describes; rejects any report claiming a verified chain or a COMPLIANT verdict over a log that does not actually verify.
The JSON output keys mirror the Python verifier so both --json outputs are directly comparable.
MIT · part of CloakLLM
