AITS is open source.
The AI Traceability System — the open core of Bastion One — is public on GitHub. Record what an AI agent was configured as and what it produced, in a content-addressed form that can be verified as unaltered. Every record’s identity is the SHA-256 of its canonical contents, so any after-the-fact edit is detectable.
The data model
Five objects, each building on the one before it — every one content-addressed by the SHA-256 of its canonical contents.
A registered agent — (uuid, name). The stable API handle that everything else pins to.
Immutable configuration: system prompt, LLM config, tools, and metadata. Recording the same config twice returns the existing row (idempotent).
An immutable snapshot of one inference call, pinned to the agent and config that produced it.
A session graph node linking DUTs into a traceable process, grouped by session.
A binary object an agent read or produced — identified by the SHA-256 of its raw bytes.
GET /verify/{cid}/ # recompute a node’s hash and recursively check its links
GET /audit/ # walk the whole ledger and commit log
Open core
Perfect AI traceability should be a foundational right for developers. The ledger is open. The active enforcement and enterprise tooling are commercial.
AITS — the Traceability Ledger
The reference implementation: agent identity, immutable configs, DUTs, lineage, artifacts, and tamper-evident verification. Apache-2.0, self-hostable, Bring Your Own Storage. Available now on GitHub.
AICS Enforcement + SIEM
The active “Brakes” — deterministic Hard Stop on unauthorized agent actions — plus the compliance presentation layer that streams the ledger into Splunk, Sentinel, Datadog, or GovCloud. See pricing.
Quickstart
Python 3.13+, uv, and Docker. The service runs at http://127.0.0.1:8000 with interactive API docs at /docs.
cp .env.example .env # adjust DATABASE_URL if needed
make dev # boot Postgres + start FastAPI (auto-reload)
Build on the open ledger.
Star the repo, read the architecture, and tell us what you’re tracing.
