$HERMETIC · pre-launch on Pons · Robinhood Chain
docs / protocol

Receipts and attestation

A receipt is the public trace of a private session. It is designed to be useful to someone who will never see the data.

The session receipt, `hermetic/receipt/1`

The app builds it in your browser when you close a session.

Field Content
kind session, or attestation when no message was sent.
service The gateway that served the session, today https://api.redpill.ai.
nonce The 32 random bytes your tab sent with the attestation request.
attestation.report The full attestation report: TDX quote, event log, keyset, container configuration.
attestation.report_sha256 sha256 of the report's canonical JSON (RFC 8785).
attestation.workload_keyset_digest The keyset the quote binds: receipt signing key, E2EE keys, TLS keys.
attestation.compose_hash The container configuration measured into RTMR3.
attestation.enclave_signer The ECDSA address the gateway binds into a second quote, when it verified.
conversation_sha256 sha256 of the conversation's canonical JSON. The text itself is not in the file.
exchanges[] For each answer: the request and response hashes, and the enclave's signed ACI receipt.

What goes on chain

HermeticRegistry.seal stores four values against the receipt hash, keccak256 of the receipt's canonical JSON:

  • who sealed it and when;
  • the report hash and the keyset digest;
  • the ECDSA signer, or zero;
  • the model id, in the event only.

No question, no answer, no prompt. A hash can be sealed once.

Verifying a receipt

Drop the file on the receipts page. Your tab:

  1. Recomputes the receipt hash and reads its seal from Robinhood Chain.
  2. Checks that the report in the file matches its recorded hash.
  3. Verifies the TDX quote against Intel's root, with collateral fetched fresh from the Phala PCCS.
  4. Recomputes the keyset digest and checks that the quote binds it together with the session nonce.
  5. Verifies every enclave receipt's Ed25519 signature under the attested key, and checks it commits to the recorded request and response hashes.
  6. Checks that the seal on chain names the same keyset and report.

Whoever kept the transcript can also match it to conversation_sha256. Nobody else learns anything from the file.