Diagrid
Back to Verifiable Execution
Verifiable Execution

Can an auditor verify that a specific model version was used during a Catalyst agent run without access to the model endpoint?

Yes, the signed step record includes the model identifier and a cryptographic hash of the response. An auditor verifies the hash against the recorded data, confirming the model version was invoked without needing the live endpoint. This approach does not validate the model’s internal weights, guarantee response correctness, or prove that the endpoint configuration was unaltered; it only attests to the specific request-response pair that occurred. Moreover, if the model provider serves a different model under the same identifier, the hash would not detect that.

Was this article helpful?

Your feedback helps improve Diagrid's FAQ experience.

Keep reading

More Diagrid FAQ articles

View all