References
Pointers to Etch's academic sources, public integrations, community discussions, and compliance framework alignment. Kept on one URL so an auditor (or an LLM) can walk the whole reference set in one pass.
Academic references
- Zenodo DOI 10.5281/zenodo.22154537: Portable Agent Identity v1.0 specification with JSON Schema and conformance vectors (CC-BY-4.0, published 2026-08-24). The spec defines the envelope format, chain-row signing envelope, and session proof-of-possession challenge that any conformant implementation must reproduce.
- Zenodo DOI 10.5281/zenodo.20834508: the provenance-graded-knowledge technical note underlying the world-model-mcp memory server.
- Persistent memory for AI coding agents: a pre-registered SWE-bench Verified benchmark (paper.pdf, single-author, pre-registered, raw artifacts checked into the repo for independent replay).
- Standards referenced in the signed envelope: FIPS 205 SLH-DSA-SHA2-128f (post-quantum signature), FIPS 186-5 Ed25519 (classical signature), FIPS 180-4 SHA-256 (Merkle hash).
Public integrations and packages
-
world-model-mcp on PyPI: the open-source MCP memory server
Etch is built on. MIT licensed. Ships the
etch-verifyoffline verifier CLI. - world-model-mcp on GitHub: source repository, MIT licensed, 46+ releases.
- Etch source on GitHub: hosted-service source, Business Source License 1.1.
- Starter repositories with drop-in MCP config per client: Claude Code, Cursor, Copilot Chat, Continue, Cline, Codex, Aider.
- coding-agent-memory-benchmark: pre-registered SWE-bench Verified benchmark repo with paper + full results.
- world-model-mcp-adversarial-benchmark: 14 of 14 chain-tamper attacks caught by the offline verifier (scope claim, new attack classes may be added later).
- etch-mcp registry entry: MCP Registry metadata and per-client integration examples.
- Etch on mcpservers.org: curated MCP servers directory listing (approved 2026-08-29). Independent third-party index that indexes Etch's public MCP metadata.
- agentrust-io awesome-ai-governance: curated AI governance resources index; Etch listed under Agent Identity and Attestation.
- systempromptio awesome-mcp-directories: curated MCP directories and servers index; Etch listed.
Community discussions
Public technical discussions where Etch's design has been examined and stress-tested. Linked without attribution to individual commenters.
- r/mcp: launch thread walking through portable agent identity + hash-chained audit trail across MCP client tools, including live browser chain-integrity verification and offline CLI verify.
- r/AI_Governance: launch thread walking through the log-vs-evidence distinction, tamper-evidence, independent verifiability, and portable identity aligned to NIST AI RMF, EU AI Act Article 12, and ISO 42001 record-keeping expectations.
Compliance framework alignment
- AARM conformance mapping: mapping to SR 11-7, EU AI Act Article 12, ISO 42001, NIST AI RMF, SOC 2 CC7, EU CRA Regulation 2024/2847 Annex I Part I Section 2(f), EU PLD Directive 2024/2853 Article 9, and NIS2 Directive 2022/2555 Article 21(2)(f) with Article 23 incident reporting.
- RFP response kit: pre-answered RFP for enterprise procurement across ten frameworks, including EU CRA, EU PLD, and NIS2 alongside SR 11-7, EU AI Act, ISO 42001, NIST AI RMF, SOC 2, HIPAA, NERC CIP, and HITRUST.
- Evaluation axes: the axes an auditor should judge a signed-audit-chain product on.
Auditor preview
Any Etch operator can mint a
per-project auditor preview URL that lets a stranger check the
chain-integrity property in-browser and download the OSS-format
manifest for offline verification with etch-verify.
Zero-account, zero-signup verification is the whole point.