Concepts
What is AI execution provenance?
AI execution provenance is the record of where and on what one execution of an AI model ran: the provider, the kind of environment, the hardware and runtime when they are known, and how long each phase took, with each fact labelled by who knows it.
Auvryn is provider-neutral execution infrastructure for AI models. It validates ONNX models, runs them as durable ExecutionJobs on infrastructure it does not own, and returns verified results with provenance and telemetry.
Every fact keeps its source
- Reported by the provider
- What the provider says about the run: its device, its run time, its queue time. Recorded as the provider’s claim.
- Measured by Auvryn
- What Auvryn observes from its own timestamps and storage: total latency, time in queue and running as Auvryn saw them, bytes in and out.
- Derived
- What Auvryn computes from recorded values, such as a correctness verdict against an expected output.
- Operator configured
- What Auvryn’s operators declare about a provider instance, such as jurisdiction or data residency. Never guessed.
Unknown is not zero
A value nobody knows is absent, never recorded as zero. A run that takes less than a millisecond is kept at its exact precision in the result’s metadata rather than rounded to a false 0 ms.
Provider-reported latency vs end-to-end latency
The time a provider reports for a run is usually the inference itself, often microseconds for a small model. End-to-end latency, measured by Auvryn, includes upload, queueing, device preparation and result retrieval, and can be minutes. Both are true, they answer different questions, and Auvryn records them as two facts.
What Auvryn records for each execution
- The provider and its contract version, copied when the job is created and never rewritten.
- The execution environment: cloud, edge, orbit or simulated, and whether the run was simulated.
- Hardware, runtime and region, only when the provider reports them.
- Jurisdiction and data residency, only when an operator configures them.
- Queue time, execution time, total latency and data volumes, each with its source.
What it is not
Execution provenance in Auvryn is a sourced record, not a hardware attestation: it does not prove cryptographically that a specific chip ran the model. Attestation (trusted execution environments, signed quotes) is a separate, complementary layer.
Related
Facts reviewed 2026-10-07.