@techreport{ferro-schrock-memory-projection-record-01, number = {draft-ferro-schrock-memory-projection-record-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ferro-schrock-memory-projection-record/01/}, author = {Andrea Ferro and Iman Schrock}, title = {{Signed Memory Projection Records for Verifiable AI Context Delivery}}, pagetotal = 13, year = 2026, month = aug, day = 4, abstract = {Encrypted and signed memory objects can establish source integrity, authorship, and read-time trust without establishing which exact bytes a memory adapter selected and delivered to a downstream AI system. This document specifies a provider-neutral signed Memory Projection Record. The record commits to the recall request and selection policy, the read-time keyring snapshot, the ordered source objects and exact context fragments delivered, the complete projection bytes, and summarized exclusions. It deliberately does not claim that a model received, used, or weighted the projection, that an action was authorized, or that an outcome occurred. ApertoMemory is one source profile; other memory formats can use the same projection boundary.}, }