Neural Inverse is Open Source →
DocsKeystone Capture

Keystone Capture is a desktop application from Neural Inverse that records AI coding assistant activity to an encrypted local store with HMAC-chained entries and Ed25519 signing. It provides tamper-evident provenance for every AI-generated code change — running entirely on your machine with zero external dependencies.

Architecture

Keystone Capture runs entirely on your machine. No data is transmitted externally.

ComponentBinaryPurpose
Capture Agentkeystone-capture-agentHeadless daemon — monitors AI tool processes, file changes, shell commands, environment variables
Tray Appkeystone-capture-traymacOS/Linux menu bar icon + web UI for monitoring and configuration
Verifierkeystone-capture-verifyIndependent chain verification tool (can be run by auditors)

What Gets Captured

When monitoring is active, the agent records:

  • Process Activity — AI tool launches (Claude Code, Cursor, Copilot, Codex, Kiro, Gemini CLI, etc.), PIDs, project directories
  • File Changes — Creates, modifies, renames, deletes within project directories. SHA-256 content hashes for tamper evidence
  • Shell Commands — Terminal commands invoked by AI processes
  • Environment Variables — Sensitive env var exposure detection (values redacted, names only)
  • IDE Extensions — VS Code/Cursor extension installs and removals
  • MCP Configurations — Changes to MCP server configs across all supported tools

File system events are only attributed to AI tools when they occur within a known project directory. System-level activity outside project directories is discarded.

Cryptographic Guarantees

PropertyImplementation
Storage encryptionAES-256-GCM
Chain algorithmHMAC-SHA256 sequential chain
Event signingEd25519
File hashingSHA-256 (content at event time)
Hardware key supportmacOS Secure Enclave P-256
Export signaturesEd25519 detached signature over signed data
Timestamp anchoringRFC 3161 TSA (optional, for audit-grade external proof)

Quick Start

Download Keystone Capture from the Neural Inverse website.

macOS

# Download and install
curl -fsSL https://cdn.neuralinverse.io/capture/install.sh | bash

# Run the capture daemon
keystone-capture-agent

# Or run with the tray UI (menu bar + web dashboard)
keystone-capture-tray

Windows

Download the installer from neuralinverse.com/keystone-capture.

Linux

# Download and install
curl -fsSL https://cdn.neuralinverse.io/capture/install.sh | bash

# Run the capture daemon
keystone-capture-agent

# Install as systemd service (auto-start on login)
keystone-capture-agent install

Data Directory

All data is stored in ~/.keystone-capture/ (configurable via KEYSTONE_DATA_DIR):

~/.keystone-capture/
├── capture.db      # Encrypted SQLite database (AES-256-GCM)
├── signing.key     # Ed25519 private key
├── signing.pub     # Ed25519 public key
├── .store_key      # AES-256 encryption key
└── capture.log     # Operational log

Enterprise

Keystone Capture works standalone for individual developers. For teams and organizations that need centralized governance:

  • Aegis Platform — Enterprise compliance enforcement, IAM, Enclave, and centralized audit trail across your org
  • AI Governance — Multi-tenant control plane for managing agents, tools, models, and policies
  • Contact Sales — Custom deployment, air-gap, on-premises

Was this page helpful?

Last edited