← Files VeraARCHIVED FILE
privacy/services/run-receipt-stamping.json
7.16 KB · Oct 2, 2026 · 00:29 UTC
{
"schema_version": 2,
"service_id": "run-receipt-stamping",
"display_name": "Server-stamped run receipts",
"governed_paths": [
".codex-plugin/plugin.json",
"scripts/model_data_report.py",
"scripts/notarized_run_receipt.py",
"skills/vera/SKILL.md",
"skills/vera/references/model-data-report-contract.md"
],
"governed_repository_paths": [
"modules/hosted_services/api.py",
"modules/run_receipts/__init__.py",
"modules/run_receipts/api.py",
"modules/run_receipts/signing.py",
"modules/run_receipts/store.py",
"templates/vera_run_receipt_verify.html"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"external_boundaries": [
{
"id": "automatic-server-stamped-run-receipt",
"kind": "hosted_service",
"destination": "Mparanza's fixed HTTPS Vera run-receipt endpoint and public verification page",
"purpose": "Bind one local model-data report to a Mparanza server timestamp and Ed25519 signature, then let the studio or its customer verify the retained proof",
"content": "Each substantive run with a durable local report automatically sends exactly schema version, one random per-run receipt UUID, the Vera version when the request was first created, and the SHA-256 digest of the canonical local model-data report, plus ordinary connection metadata. The report itself, workflow and local run IDs, client or case data, professional purpose, phase labels, counts, filenames, file contents, source-document hashes, prompts, and model outputs are not sent. A later verification request sends the same opaque receipt UUID and report digest.",
"retention": "Mparanza retains the opaque receipt UUID, server timestamp, Vera version, report digest, signature, signature key ID, and implicit receipt schema version as the proof record, without an automatic deletion period. The local HTML and JSON receipt remain in the studio's run output, or in a supplementary run receipts directory for a retry after output finalization, until the studio removes them. Administrative deletion of the server proof must be requested from Mparanza and makes later verification impossible.",
"activation": "automatic_per_durable_run",
"optional": false,
"requires_confirmation": false,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"Every successful durable model-data report build through Vera's own command invokes the receipt client automatically; there is no local enable, disable, or consent setting. If the service is unavailable, the completed work and local report remain intact, the retry-stable request remains pending, and the report command still succeeds without claiming that a server receipt exists. The generic Studio Archive report helper reuses local validation with server attestation disabled and reports not_requested; it does not invoke this external service.",
"The client constructs a four-field allow-listed request, restricts production traffic to the fixed Mparanza HTTPS route, permits HTTP only on an explicit loopback port for testing, bounds responses, and rejects additional or mismatched response fields. The default transport rejects HTTP redirects before any redirected request and rejects endpoint URLs containing credentials.",
"The server rejects additional request fields, assigns its own timestamp, signs the complete retained record with Ed25519, stores only the minimal proof fields, applies request-size and rate limits, and fails closed when signing or verification keys are unavailable.",
"The local customer receipt states that the proof covers existence, server time, and report integrity only; it does not claim who submitted the digest, provider delivery, analytical correctness, semantic necessity, DPIA completion, legal advice, or GDPR compliance.",
"Retries retain the original UUID and version. A retry after finalization verifies the retained report against the sealed artifact manifest and writes supplementary receipts outside the immutable output tree.",
"The workflow remains subject to host network permissions and action-specific approval rules. A denied transmission is not retried through another tool or destination; permission-denied retries wait for the required authorization.",
"OpenAI desktop onboarding is a local-only exception: reports beneath its .vera-onboarding-local-only directory marker return not_requested/local_onboarding before receipt request construction, including direct later stamp retries. The Claude projection omits this new onboarding behavior.",
"The report build returns the readable local report as display_markdown for the final response, including when stamping is pending. The show command renders a saved report after validating its recorded hashes; it reads no source documents, writes no files and makes no network or stamping request. Displaying the report uses the current model context and does not send its content to Mparanza."
]
}
],
"security_controls": [
{
"id": "minimal-receipt-request-allow-list",
"control": "Both client and server enforce the same closed receipt request schema, and the server's Pydantic model forbids every unregistered field.",
"implemented_by": [
"scripts/notarized_run_receipt.py",
"repository:modules/run_receipts/api.py"
],
"on_violation": "The request or response is rejected before a proof is accepted or written locally."
},
{
"id": "fixed-receipt-destination",
"control": "The installed client accepts only the fixed Mparanza HTTPS receipt route, with an explicit loopback HTTP port allowed solely for local testing. Endpoint credentials are rejected, and the default stamping and verification transport refuses redirects rather than following another destination.",
"implemented_by": [
"scripts/notarized_run_receipt.py"
],
"on_violation": "The client aborts before making a network request."
},
{
"id": "signed-idempotent-minimal-storage",
"control": "The server generates the timestamp, signs the exact minimal record with Ed25519, persists no report or case fields, and treats reuse of a receipt UUID for a different digest or version as a conflict.",
"implemented_by": [
"repository:modules/run_receipts/signing.py",
"repository:modules/run_receipts/store.py"
],
"on_violation": "Missing keys make the service unavailable, invalid signatures are not returned as verified, and conflicting retries are rejected."
},
{
"id": "bounded-public-receipt-service",
"control": "The public receipt API caps request bodies and per-source and global operation rates before stamping or verification.",
"implemented_by": [
"repository:modules/run_receipts/api.py"
],
"on_violation": "Oversized or excess requests receive an explicit 413 or 429 response without creating a receipt."
}
],
"review": {
"reviewed_at": "2026-09-28",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_shared_service_source",
"source_fingerprint": "c75f9698062fc3f23a63305d222018c588433500e407016e7bc92256d9b9cdfb"
}
}
SHA-256: 479897835e33cc7436ac62de1d72866afdd6bd884cab1e62aaf6c68183a58d54