Skip to Content
SDK referenceRelease NotesSDK 1.0.0 overview

SDK 1.0.0

SDK 1.0.0 is the first stable VeriProof SDK release. Every package in it enforces policy: a core SDK for each of six languages, and 35 Enforce adapters for the agent frameworks those languages use.

Tools and SDKs in the customer portal lists the packages enabled for your tenant and provides their installation commands.

What the release includes

LanguageCore packageEnforce adaptersMinimum runtimeRelease notes
TypeScript@veriproof/sdk-core11Node.js 22TypeScript 1.0.0
Pythonveriproof-sdk8Python 3.11Python 1.0.0
.NETVeriproof.Sdk.Core5.NET 10.NET 1.0.0
Javacom.veriproof:veriproof-sdk-core6Java 21Java 1.0.0
Goveriproof.app/sdk/go3Go 1.26.6Go 1.0.0
Rustveriproof-sdk2Rust 1.96Rust 1.0.0

Select an adapter count to see which frameworks that language covers.

What every package does

  • Checks policy before governed work runs and again before its result is released.
  • Returns a typed result for each of the five policy outcomes: Allow, Warn, Transform, Escalate, and Deny. If VeriProof can’t be reached, the action fails closed.
  • Pauses work for a person with authority and resumes it from a signed, structured review response.
  • Stops an active run when a Stop directive applies.
  • Records session evidence your auditors can check.

An Enforce adapter applies those checks at one documented framework boundary. It depends on its language’s core SDK, which installs with it. Anything the adapter doesn’t cover stays with the core SDK’s governed action. SDK categories and framework coverage shows the exact boundary for each adapter.

Versions and fixes

  • A released version never changes. VeriProof doesn’t rebuild or replace the bytes of a published 1.0.0 package.
  • Fixes ship as patch versions. A correction is released as a new patch version with its own release evidence.
  • Every package has release evidence. Its exact artifact passed a clean install, a security scan, and registry verification, and the release manifest is signed.

Pin exact package versions in your application. Take new versions from Tools and SDKs rather than reusing commands from an older release or another tenant.

Check compatibility before you upgrade

A package version and a contract version are not the same thing. Each VeriProof deployment publishes the contracts it supports in its discovery document:

https://<your-veriproof-portal>/.well-known/veriproof-configuration

The SDK 1.0.0 packages use SDK ingest contract 1. Compare that with the target deployment before you update a client. Agent integration versions explains the other contracts in the same document.

Last updated on