Compliance
The Loom's audit-logging capability, mapped to the requirements it serves.
The honest scope
EU AI Act Article 12 requires automatic event logging for high-risk AI systems — a classification that applies to the provider or deployer of such a system, not to P31. P31 does not operate a high-risk AI system. It provides the audit-logging layer that such a deployment would use. The Digital Omnibus deferred the high-risk logging obligation to December 2, 2027 (Annex III standalone systems) and August 2, 2028 (Annex I embedded systems) — P31's architecture is ready for it, rather than reporting it as an immediate deadline.
The IETF drafts referenced below (draft-sharif-agent-audit-trail-04, draft-sato-soos-gar-02) are individual Internet-Drafts, not adopted standards — alignment is as-of-date and the drafts expire without revision.
The verify mechanism on this page is a reproducible command (clone + pnpm verify), not a live URL — the stable custom domain is behind Cloudflare Access and preview URLs rotate, so no public URL is a reliable proof.
Requirement → implementation → verify
Scope: Applies to providers/deployers of HIGH-RISK AI systems. P31 is infrastructure, not a high-risk system. Obligation deferred by the Digital Omnibus to Dec 2 2027 (Annex III standalone) / Aug 2 2028 (Annex I embedded).
Implementation: The Loom appends every agent action to a SHA-256 hash chain (RFC 8785 canonicalization), with optional ML-DSA-65 signatures.
Passing looks like: chain recomputes from genesis; every link holds; `valid: true`
Scope: Retention is a configuration parameter of the deployment, not fixed by P31.
Implementation: Chain storage in D1 (primary) + R2 (cold backup). Retention window is configurable.
Scope: Individual Internet-Draft (2026-09-15). Not an adopted standard. Expires ~2027-03 without revision.
Implementation: Loom chain format aligns to the AAT JSON record, SHA-256 chaining, and ML-DSA-65 signatures.
Passing looks like: verify output matches the AAT JSON record shape (agent id, action, outcome, trust level)
Scope: Individual Internet-Draft (2026-06-09). Referenced for Session Audit Record structure.
Implementation: GAR session-audit-record shape referenced in the Loom record.
Scope: Ratified standard, published 2026-06-30. P31 alignment is DESIGNED — the endpoint + Merkle anchor implement the model, not a certified SCITT deployment.
Implementation: Public verify endpoint + Merkle batch anchor follow the SCITT model (Merkle inclusion proofs).
Passing looks like: Merkle inclusion proof for a record is computable in O(log n)
Scope: Published 2026. Used for ML-DSA-65 signature encoding.
Implementation: Optional ML-DSA-65 signatures on chain records use RFC 9881 identifiers (NIST Level 3).
Scope: Individual Internet-Draft (2026-09-20). Not an adopted standard.
Implementation: The Loom record uses the WIMSE in-toto predicate inside a DSSE envelope; carries the seven minimum WIMSE audit fields.
Scope: Individual Internet-Draft (2026-09-08). Referenced in Lumi capability-token design.
Implementation: Lumi capability tokens reference the AIC-JWT direction; the Loom records the proposed action + capability.
Scope: Individual Internet-Draft (2026-04-20).
Implementation: Aligned on pre-execution enforcement + signed receipt format.
Scope: P31 has NOT obtained SOC 2. This maps the logging control to the criteria shape.
Implementation: Tamper-evident append-only log; pre-execution gate records refusals, not just actions.
Scope: P31 has not pursued certification.
Implementation: The audit format maps to the 42001 audit requirements; certification is a later decision.
About the live endpoint
A live public endpoint is available on request (the stable domain https://loom.p31ca.org/api/loom-public/verify is behind Cloudflare Access — a documented, open gap — and Cloudflare Pages preview URLs rotate, so no preview URL is reliable to print here). For a durable, self-serve proof, run pnpm verify in a clone of the repo — it exercises the same chain-verification logic.