Back to News
RSS feedgithub.com

Kyv Proposes Verifiable Vendor Liveness Attestations for AI Agents

Summary

Kyv is a draft convention for publishing signed, machine-verifiable operational facts about a company at its `/.well-known/attestations.json` endpoint. The project uses Ed25519 signatures and a daily transparency log so verifiers can check attestations offline after fetching the published material. Its central problem is that a reachable website is not reliable evidence that a vendor is still operating. In the GhostBench benchmark, the authors collected 20 verifiably shut-down SaaS products and six living controls; 19 of the 20 dead domains still returned HTTP 200 responses because they served parked pages, farewell pages, or redirects. Claude Opus 4.8 identified all 20 dead products without tools, but the smaller Claude Haiku 4.5 treated eight of them as viable sign-up-today vendors; facts-only verification corrected three decisions while introducing two new errors. Kyv therefore emphasizes signed, continuously renewed liveness, represented by `alive_since` and continuity in the log, with a missed day visible as a gap. The draft defines levels covering domain and public-key publication, liveness and continuity, banded financial facts, and retention depth, while banning raw financial values, rankings, and scores. It distinguishes mechanically observed facts from domain-holder attestations and third-party issuer claims, and warns that `https_reachable: true` only proves that a domain served a response. The repository includes TypeScript verification, MCP-server, key-generation, signing, and benchmark commands; it is currently labeled v0 draft and requests feedback on its band vocabulary and agent-runtime integration.