A tamper-evident record for AI decisions
Boruna runs AI and LLM workflows deterministically, under an explicit capability
policy, and seals every run into a hash-chained evidence bundle. Anyone can verify the bundle
offline, and any change to it is detected.
Install
Quickstart
Every run is evidence
For every step, the inputs it ran on, each capability it called (allowed or denied) and
the output it produced, plus every approval, rejection and confidence-gate decision, go into a
hash-chained audit log inside an evidence bundle. boruna evidence verify
recomputes every hash and reports any change.
How bundles are verified →
People decide where it matters
Approval gates pause a workflow until someone runs boruna workflow approve.
A calibrated confidence gate lets an answer skip review only when calibration data shows a
wrong answer would get through at most a set share of the time.
Approval and confidence gates →
Same input, same output
Workflow steps are written in .ax and run on a VM with no ambient randomness,
clock or I/O. A capability must be declared and allowed by policy before a step can call it, and
every call is recorded, so the same inputs give the same run and it can be checked later.
How replay works →
Reports for EU AI Act, NIST AI RMF and ISO/IEC 42001
boruna evidence report --framework eu-ai-act (or nist,
iso42001) verifies a bundle and maps what it contains to the obligations each part
helps meet. It is a technical mapping for your auditor, not a certificate of compliance.
Compliance workflow templates →
Run a workflow, then verify it
Real output from boruna 3.6.0, captured when this page was built.
$ boruna workflow run examples/workflows/confidence_gated_review --policy allow-all --record
data_dir: runs
workflow 'confidence-gated-review' run: Completed
run_id: 9fc7168a51f1f54d
duration: 3ms
step 'publish': Completed (0ms)
step 'review': Completed (0ms)
step 'score': Completed (0ms)
evidence bundle: runs/evidence/9fc7168a51f1f54d
bundle_hash: 8bbe6db68536afcfe256e37d21b22b6dd3911c52a2f8875a68a44ecfe101e775
audit_log_hash: 260eaf86106c97e8fcd939dbb06385c574177014434ff502a767fd2643b8faf3
files: 6
$ boruna evidence verify runs/evidence/9fc7168a51f1f54d
evidence bundle is VALID
Install
Linux and macOS:
curl -fsSL https://raw.githubusercontent.com/escapeboy/boruna/master/install.sh | sh
Windows (PowerShell):
irm https://raw.githubusercontent.com/escapeboy/boruna/master/install.ps1 | iex
Both scripts check the download against the release's SHA256SUMS before
installing. Builds for Linux (x86_64, arm64), macOS (Apple Silicon, Intel) and Windows (x64,
Arm), each tested natively in CI. Manual
download and platform table →
For developers and AI agents
- The
.ax language — small,
statically typed and deterministic.
- MCP server — compile, check, run and seal
.ax from Claude Code, Cursor and other agents.
llms.txt and llms-full.txt
— the language and tooling in a form a model can read in one go.
- Limitations — what Boruna does not do, stated plainly.