Repository navigation
Expand file tree
/
Copy pathindex.html
More file actions
356 lines (329 loc) · 21.7 KB
/
Copy pathindex.html
File metadata and controls
356 lines (329 loc) · 21.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>NoireBox — Proof, not promises. Tamper-evident AI agent audit trails</title>
<meta name="description" content="Every decision your AI agent makes — sealed in a tamper-evident journal, timestamped by an external witness, provable by anyone. Without trusting anyone.">
<meta property="og:title" content="NoireBox — Proof, not promises">
<meta property="og:description" content="Tamper-evident AI agent audit trails: hash-chained, signed, timestamped by an external witness, verifiable offline.">
<meta property="og:type" content="website">
<meta property="og:image" content="https://noirebox.github.io/noirebox/assets/banner.jpg">
<meta property="og:image:width" content="1672">
<meta property="og:image:height" content="941">
<meta name="twitter:card" content="summary_large_image">
<link rel="stylesheet" href="style.css?v=27">
</head>
<body>
<div class="progress" id="progress"></div>
<!-- ═══════════════ NAV ═══════════════ -->
<nav class="nav">
<a class="brand" href="#top"><span class="brand-cube"></span>NOIRE<span>BOX</span></a>
<div class="nav-links">
<a href="#core">The journal</a>
<a href="#plugin">Guardrail</a>
<a href="#witness">Witness</a>
<a href="#proof">Proof</a>
<a href="#api">API</a>
<a href="https://github.com/noirebox/noirebox" target="_blank" class="nav-github">★ GitHub</a>
<a href="fr.html" class="nav-flag" title="Version française" lang="fr">🇫🇷</a>
</div>
</nav>
<!-- ═══════════════ HERO — the banner, live ═══════════════ -->
<header class="hero" id="top">
<div class="hero-inner">
<p class="kicker">// TAMPER-EVIDENT AI AGENT AUDIT TRAILS</p>
<h1 class="wordmark">Noire<span class="wm-grad">Box</span></h1>
<p class="tagline">Proof, not promises</p>
<p class="hero-sub">
Every decision your AI agent makes — sealed in a hash-chained, signed journal,
timestamped by an external witness. Verifiable offline, by anyone,
<strong>without trusting anyone.</strong>
</p>
<div class="gh-badges">
<span class="gh-badge"><i>GDPR</i><b>ready</b></span>
<span class="gh-badge"><i>AI ACT</i><b>art. 12</b></span>
<span class="gh-badge"><i>made in</i><b>🇫🇷 Vosges, France</b></span>
</div>
<div class="cta-row">
<a class="btn btn-light" href="https://github.com/noirebox/noirebox#quickstart" target="_blank">Start free — self-host</a>
<a class="btn btn-ghost" href="#core">See the proof ↓</a>
</div>
<ul class="stats">
<li><strong>311</strong><span>tests green</span></li>
<li><strong>0.6 MB</strong><span>wheel, models included</span></li>
<li><strong>0.17 ms</strong><span>overhead per event</span></li>
<li><strong>250 KB</strong><span>per-language detector</span></li>
</ul>
<div class="install-pill">
<code id="install-cmd">git clone https://github.com/noirebox/noirebox && cd noirebox && ./start.sh</code>
<button class="copy-btn" id="copy-install" title="Copy to clipboard" aria-label="Copy install command">⧉</button>
</div>
</div>
<figure class="hero-visual reveal">
<img src="assets/banner.webp" width="1672" height="941"
alt="The NoireBox journal drawn as a chain of sealed blocks #1023 to #1027, each carrying its hash and signature. Block #1025 glows red: its content was rewritten and the hash mismatch exposes the tampering. An attestation card lists the journal hash, Merkle root, Ed25519 signature and timestamp — all verified. Append-only journal · SHA-256 hash chain · Ed25519 signatures · prompt-injection detection · attestations & Merkle proofs.">
<figcaption>Event #1025 was rewritten after the fact. The chain caught it — everything it sealed stays provable.</figcaption>
</figure>
</header>
<!-- ═══════════════ TICKER ═══════════════ -->
<div class="ticker" aria-hidden="true">
<div class="ticker-track" id="ticker"></div>
</div>
<!-- ═══════════════ 01 CORE ═══════════════ -->
<section class="section reveal" id="core">
<div class="wrap">
<p class="kicker">01 · THE CORE</p>
<h2>One journal.<br><span class="grad">Nothing else matters. </span>🤘</h2>
<p class="lede">
The journal is the product: hash-chained, signed, append-only, anchored to an
external witness. It doesn't know what an agent is — an event is a type and a
payload. That's why it fits <em>every</em> agent, every stack, every language.
</p>
<div class="chain">
<div class="link ok c-blue"><span>#1023</span><code>4f2c6e9a…</code><code>sig ✓</code></div>
<div class="chain-arrow">→</div>
<div class="link ok c-violet"><span>#1024</span><code>9b7e3c1d…</code><code>sig ✓</code></div>
<div class="chain-arrow">→</div>
<div class="link bad"><span>#1025 ✗</span><code>e03a9f7c…</code><code>content rewritten</code></div>
<div class="chain-arrow">→</div>
<div class="link dim"><span>#1026</span><code>7c9d2e1b…</code><code>prev hash ✗</code></div>
<div class="chain-arrow">→</div>
<div class="link dim"><span>#1027</span><code>a1f3b9d4…</code><code>unverifiable</code></div>
</div>
<div class="pipeline" aria-label="How a decision becomes proof">
<span class="pl-step">AI decision</span>
<span class="pl-arrow">→</span>
<span class="pl-step">SHA-256</span>
<span class="pl-arrow">→</span>
<span class="pl-step">Ed25519</span>
<span class="pl-arrow">→</span>
<span class="pl-step">TSA · RFC 3161</span>
<span class="pl-arrow">→</span>
<span class="pl-step ok">✓ immutable record</span>
</div>
<div class="grid-3">
<div class="card"><h3>Hash-chained</h3><p>Every event commits to the previous one. Insert, delete or rewrite — detected, and located to the exact event.</p></div>
<div class="card"><h3>Signed</h3><p>Ed25519 seals from a key that never leaves your infrastructure. A forged journal — even perfectly re-chained — fails.</p></div>
<div class="card"><h3>Append-only</h3><p>SQLite with no UPDATE, no DELETE. Writing is the only operation that exists. Signed events at 0.17 ms apiece.</p></div>
</div>
</div>
</section>
<!-- ═══════════════ 02 PLUGIN ═══════════════ -->
<section class="section alt reveal" id="plugin">
<div class="wrap">
<p class="kicker">02 · GUARDRAILS</p>
<h2>Prevention is pluggable.<br><span class="grad">Proof is universal.</span></h2>
<p class="lede">
Already running Lakera, Llama Guard, your own LLM-judge or your own regexes?
<strong>Keep them.</strong> A guardrail is just one event source — journal its
verdicts and its catches become tamper-evident instead of living in rewritable logs.
</p>
<div class="sources">
<div class="source"><span class="dot g"></span><div><strong>Your guardrail</strong><em>its verdicts, as events</em></div></div>
<div class="source"><span class="dot g"></span><div><strong>Your agent</strong><em>llm_call · llm_output · eval</em></div></div>
<div class="source"><span class="dot b"></span><div><strong>Bundled plugin</strong><em>regex + 250 KB ML, fr & en</em></div></div>
</div>
<div class="plug-flow" aria-label="Drop-in integration">
<span class="pf-chip">OpenAI</span>
<span class="pf-chip">Claude</span>
<span class="pf-chip">LangGraph</span>
<span class="pf-chip">CrewAI</span>
<span class="pf-chip">Custom agent</span>
<span class="pf-arrow">→</span>
<span class="pf-chip hot">NoireBox</span>
<span class="pf-arrow">→</span>
<span class="pf-chip ok">Immutable audit trail</span>
</div>
<p class="note mono">No model lock-in. No infrastructure rewrite. One SDK.</p>
<p class="note">The detector we ship is a working example of the plugin contract — swappable by design
(<a href="https://github.com/noirebox/noirebox/blob/main/docs/ADRs.md">ADR 003</a>: Meta's Prompt Guard evaluated and declined, integration path documented).</p>
</div>
</section>
<!-- ═══════════════ 03 WITNESS ═══════════════ -->
<section class="section reveal" id="witness">
<div class="wrap">
<p class="kicker">03 · THE OUTSIDE WITNESS</p>
<h2>Sealed at T. time ☕<br><span class="grad">The past is read-only.</span></h2>
<p class="lede">
A journal that dates itself proves nothing — that's the suspect writing its own report.
RFC 3161 anchoring lets an external Timestamp Authority sign <em>"I received hash X at
time T"</em>. Only a 32-byte hash ever leaves. A regenerated journal shows a head the old
token doesn't cover — and a backdated token is arithmetically impossible.
</p>
<div class="steps">
<div class="step"><span>1</span><div><strong>Hash</strong><em>only the head, never the data</em></div></div>
<div class="step"><span>2</span><div><strong>TSA signs</strong><em>« hash X received at time T »</em></div></div>
<div class="step"><span>3</span><div><strong>Sealed back</strong><em>the token becomes an event itself</em></div></div>
</div>
<p class="big-line">One seal for the whole fleet. <span class="grad">Certificate Transparency, for AI agents.</span></p>
<p class="note">Fleet anchoring: the heads of N journals form a Merkle tree — a single TSA seal covers them all, and each box proves its place with ~11 hashes, verified offline. To our knowledge, no other agent-audit tool does this. <code>make demo-fleet</code></p>
<p class="note mono">make tsa → local OpenSSL witness, own key chain, 0 €, works offline. Or point NOIREBOX_TSA_URL at any qualified TSA.</p>
</div>
</section>
<!-- ═══════════════ 04 WHY NOW ═══════════════ -->
<section class="section alt reveal" id="whynow">
<div class="wrap">
<p class="kicker">04 · WHY NOW</p>
<h2>AI decides faster than<br><span class="grad">you can audit it.</span></h2>
<p class="lede">When something goes wrong — an incident, a dispute, a regulator — six questions decide everything:</p>
<div class="why-grid">
<div class="why-q">What did the agent <strong>see</strong>?</div>
<div class="why-q">What did it <strong>decide</strong>?</div>
<div class="why-q">Which <strong>model version</strong> ran?</div>
<div class="why-q">Which <strong>tools</strong> did it call?</div>
<div class="why-q">What changed <strong>since</strong>?</div>
<div class="why-q">Was the log <strong>modified afterwards</strong>?</div>
</div>
<p class="big-line">NoireBox answers all six. <span class="grad">Cryptographically.</span></p>
</div>
</section>
<!-- ═══════════════ 05 MEASURED ═══════════════ -->
<section class="section reveal" id="measured">
<div class="wrap">
<p class="kicker">05 · MEASURED, NOT CLAIMED</p>
<h2>Numbers we can reproduce.<br><span class="grad">Not numbers we feel.</span></h2>
<p class="lede">
Every metric below is reproducible from the repo — <code>make test</code>,
<code>make train</code>, the benchmark commands in the specs. A metric we
can't reproduce means <em>unknown</em>, not a rounder number.
</p>
<table class="metrics">
<tr><th>Metric</th><th>Value</th><th>Reproduce with</th></tr>
<tr><td>Sealed event — hash + Ed25519 + SQLite commit</td><td class="m-val">0.17 ms</td><td class="m-how">docs/SPECS.md §6</td></tr>
<tr><td>Guardrail scan, regex engine (7 lines)</td><td class="m-val">0.21 ms</td><td class="m-how">docs/SPECS.md §6</td></tr>
<tr><td>Guardrail scan, ML engine (7 lines)</td><td class="m-val">10.3 ms</td><td class="m-how">docs/SPECS.md §6</td></tr>
<tr><td>Full chain verification, 100 events</td><td class="m-val">44 ms</td><td class="m-how">verifier/verifier.py, any export</td></tr>
<tr><td>Bundled detectors, FR + EN</td><td class="m-val">293 + 243 KB</td><td class="m-how">make train · make train-en</td></tr>
<tr><td>Held-out attack sentences, FR + EN</td><td class="m-val">12/12</td><td class="m-how">tests/test_ml_guardrail.py</td></tr>
<tr><td>Test suite</td><td class="m-val">311 green</td><td class="m-how">make test</td></tr>
</table>
<p class="note mono">Measured on an M-series MacBook, October 2026. One number, one command — if a future release can't reproduce one, the table gets corrected, not inflated.</p>
</div>
</section>
<!-- ═══════════════ 06 PROOF ═══════════════ -->
<section class="section reveal" id="proof">
<div class="wrap">
<p class="kicker">06 · THE PROOF</p>
<h2>One file. One command.<br><span class="grad">Zero trust.</span></h2>
<p class="lede">
An auditor, a DPO, a client — receives the full dossier and recomputes the truth locally.
No API to trust, no dashboard to believe. Arithmetic doesn't lie.
</p>
<div class="terminal">
<div class="term-bar"><span class="dot"></span><span class="dot"></span><span class="dot"></span><span class="term-title">auditor@third-party — no credentials</span></div>
<pre id="term-out"></pre>
</div>
</div>
</section>
<!-- ═══════════════ 07 USE CASES ═══════════════ -->
<section class="section alt reveal" id="usecases">
<div class="wrap">
<p class="kicker">07 · WHO IT'S FOR</p>
<h2>Built for systems that<br><span class="grad">must explain themselves.</span></h2>
<div class="grid-3 uc-grid">
<div class="card"><h3>Finance</h3><p>Every automated decision auditable — credit scoring, trading, claims.</p></div>
<div class="card"><h3>Healthcare</h3><p>Trace AI-assisted decisions end to end, for patients and inspectors.</p></div>
<div class="card"><h3>Legal</h3><p>Preserve evidence and chain of custody for AI-produced documents.</p></div>
<div class="card"><h3>Enterprise AI</h3><p>Know exactly what your agents did, on which input, with which tools.</p></div>
<div class="card"><h3>Security</h3><p>Detect log tampering, not just failures. The journal fights back.</p></div>
<div class="card"><h3>Public sector</h3><p>Algorithmic transparency duties, satisfied by design.</p></div>
</div>
</div>
</section>
<!-- ═══════════════ 08 DEVELOPERS ═══════════════ -->
<section class="section reveal" id="api">
<div class="wrap">
<p class="kicker">08 · DEVELOPERS</p>
<h2>An API, an SDK, a verifier.<br><span class="grad">Nothing else to learn.</span></h2>
<p class="lede">
FastAPI, 11 documented routes, interactive OpenAPI at <em>/docs</em>.
Record from anything that can send JSON — your agent, your CI, your cron job.
</p>
<div class="terminal">
<div class="term-bar"><span class="dot"></span><span class="dot"></span><span class="dot"></span><span class="term-title">dev@yourstack — record & prove</span></div>
<pre class="term-static">$ git clone https://github.com/noirebox/noirebox && cd noirebox
$ ./start.sh <span class="t-dim"># tests + API on :8768 — /docs is live</span>
$ curl -X POST :8768/api/v1/events \
-d '{"type":"llm_call","payload":{"model":"gpt-x","prompt":"…"}}'
$ curl -X POST :8768/api/v1/anchors <span class="t-dim"># seal the chain head (RFC 3161)</span>
$ curl -s :8768/api/v1/export > export.json
$ python verifier/verifier.py export.json
<span class="t-ok">[✓] INTACT — proof, verified by anyone, offline</span></pre>
</div>
<p class="note mono" style="margin-top:20px;letter-spacing:.02em">
GET IT —
<a href="https://pypi.org/project/noirebox/" style="color:var(--violet-soft)">pip install noirebox</a> ·
<a href="https://marketplace.visualstudio.com/items?itemName=noirebox.noirebox" style="color:var(--violet-soft)">VS Code / Cursor — Marketplace</a> ·
<a href="https://open-vsx.org/extension/noirebox/noirebox" style="color:var(--violet-soft)">Open VSX</a> ·
<a href="https://github.com/noirebox/noirebox/releases/tag/v0.12.0" style="color:var(--violet-soft)">VSIX + sources</a> ·
<a href="https://github.com/noirebox/noirebox/pkgs/container/noirebox" style="color:var(--violet-soft)">Docker — GHCR</a>
</p>
<div class="plug-flow" aria-label="Developer surface">
<span class="pf-chip">FastAPI</span>
<span class="pf-chip">OpenAPI · /docs</span>
<span class="pf-chip">Python SDK</span>
<span class="pf-chip">MCP server · 4 agent tools</span>
<span class="pf-chip">Docker</span>
<span class="pf-chip ok">10 routes</span>
</div>
</div>
</section>
<!-- ═══════════════ 09 EUROPE ═══════════════ -->
<section class="section reveal" id="europe">
<div class="wrap">
<p class="kicker">09 · EUROPE</p>
<h2>AI regulation is coming.<br><span class="grad">Make every decision traceable.</span></h2>
<p class="lede">European AI vendors must <em>prove</em> — not promise — what their systems did. NoireBox is engineered around that obligation.</p>
<div class="grid-4">
<div class="card"><h3>EU AI Act — art. 12</h3><p>Record-keeping duties for risk systems: automatic event logs, cryptographic.</p></div>
<div class="card"><h3>GDPR — 5(2) · 15/20</h3><p>Accountability and subject rights: signed exports, verifiable by the DPO.</p></div>
<div class="card"><h3>ISO 42001</h3><p>AI management systems: traceability of decisions feeds the audit directly.</p></div>
<div class="card"><h3>EU Data Act</h3><p>Data access and governance: portable, verifiable records by construction.</p></div>
</div>
<p class="big-line">Compliance isn't a feature. <span class="grad">It's an architectural property.</span></p>
<p class="note">Sovereign: self-hosted, zero telemetry, keys stay yours. Engineered in the Vosges 🇫🇷. A building block, not a certification — we state our perimeter (see the threat model) instead of overselling it.</p>
</div>
</section>
<!-- ═══════════════ 10 FAQ ═══════════════ -->
<section class="section reveal" id="faq">
<div class="wrap">
<p class="kicker">10 · BEFORE YOU BEGIN</p>
<h2>A few questions,<br><span class="grad">straight answers.</span></h2>
<details class="faq"><summary>One NoireBox per agent?</summary><p>Yes — like one flight recorder per aircraft. One instance = one SQLite file, one key pair, one chain. The fleet layer aggregates chain heads (32-byte hashes), never your events: your journal stays on your infrastructure.</p></details>
<details class="faq"><summary>Is this a blockchain?</summary><p>No — one issuer, one verifier. A signed local chain gives integrity and non-repudiation without paying a consensus tax. The blockchain solves a problem we don't have (ADR 001).</p></details>
<details class="faq"><summary>How is it different from Langfuse or Helicone?</summary><p>Those help developers debug what happened — the logs stay modifiable. NoireBox produces a dossier a third party verifies offline. Debug ≠ proof.</p></details>
<details class="faq"><summary>Do I have to use the bundled guardrail?</summary><p>No — it's one event source among others. Keep Lakera, Llama Guard or your own LLM-judge and journal their verdicts with a single POST. The bundled detector is a working example of the plugin contract.</p></details>
<details class="faq"><summary>Do I need a paid timestamp authority?</summary><p>No — <code>make tsa</code> runs a local OpenSSL witness with its own key chain: free, offline, sovereign. Pointing at any public or qualified TSA is one environment variable.</p></details>
<details class="faq"><summary>What does it cost?</summary><p>Core: MIT, $0 forever, verification included. No cloud tier — self-hosted is the product.</p></details>
</div>
</section>
<!-- ═══════════════ 11 ACCESS ═══════════════ -->
<section class="section alt reveal" id="access">
<div class="wrap narrow">
<p class="kicker">11 · START FREE</p>
<h2>Core is MIT.<br><span class="grad">Forever.</span></h2>
<p class="lede">
Journal, guardrail plugin, verifier — free and open, including verification.
Everything runs on your infrastructure; the proof never needed a middleman.
</p>
<div class="tiers">
<div class="tier"><h4>Core</h4><span>$0 · MIT forever</span><p>Self-hosted. Unlimited events. Journal, plugin, verifier.</p></div>
<div class="tier"><h4>Verification</h4><span>$0 · forever</span><p>The standalone verifier, pinned TSA roots and the GitHub Action — free for your auditors, clients and DPO.</p></div>
</div>
<p class="note">No cloud tier, no upsell — if NoireBox ever stops being self-hostable, it stops being trustworthy.</p>
</div>
</section>
<footer class="footer">
<div><span class="brand-cube"></span> <strong>NoireBox</strong> — proof, not promises.</div>
<div class="foot-links">
<a href="https://github.com/noirebox/noirebox" target="_blank">GitHub</a>
<a href="https://github.com/noirebox/noirebox/blob/main/docs/SPECS.md">Specs</a>
<a href="https://github.com/noirebox/noirebox/blob/main/docs/THREAT-MODEL.md">Threat model</a>
<span>MIT</span>
<span>🇫🇷 Engineered in the Vosges</span>
</div>
</footer>
<script src="script.js?v=27"></script>
</body>
</html>