Open Source · Apache-2.0

AITS is open source.

The AI Traceability System — the open core of Bastion One — is public on GitHub. Record what an AI agent was configured as and what it produced, in a content-addressed form that can be verified as unaltered. Every record’s identity is the SHA-256 of its canonical contents, so any after-the-fact edit is detectable.

Apache License 2.0 · FastAPI + Postgres · generated Python SDK (aits-client)

The data model

Five objects, each building on the one before it — every one content-addressed by the SHA-256 of its canonical contents.

AgentMutable identity

A registered agent — (uuid, name). The stable API handle that everything else pins to.

AgentConfigcid = SHA-256

Immutable configuration: system prompt, LLM config, tools, and metadata. Recording the same config twice returns the existing row (idempotent).

DataUniqueTag (DUT)Inference record

An immutable snapshot of one inference call, pinned to the agent and config that produced it.

LineageTag (LT)Session DAG

A session graph node linking DUTs into a traceable process, grouped by session.

ArtifactContent-addressed

A binary object an agent read or produced — identified by the SHA-256 of its raw bytes.

# Verifiability is built in
GET /verify/{cid}/  # recompute a node’s hash and recursively check its links
GET /audit/       # walk the whole ledger and commit log

Open core

Perfect AI traceability should be a foundational right for developers. The ledger is open. The active enforcement and enterprise tooling are commercial.

Open Source · Free

AITS — the Traceability Ledger

The reference implementation: agent identity, immutable configs, DUTs, lineage, artifacts, and tamper-evident verification. Apache-2.0, self-hostable, Bring Your Own Storage. Available now on GitHub.

Quickstart

Python 3.13+, uv, and Docker. The service runs at http://127.0.0.1:8000 with interactive API docs at /docs.

make deps           # install dependencies from uv.lock
cp .env.example .env  # adjust DATABASE_URL if needed
make dev            # boot Postgres + start FastAPI (auto-reload)

Build on the open ledger.

Star the repo, read the architecture, and tell us what you’re tracing.