Secure randomness API
What to require from a secure random number API
Learn how to evaluate a secure random number API for random bytes, bounded integers, REST and gRPC integration, receipts, and audit evidence.
Read guideEngineering resources
Use these guides to evaluate secure random number APIs, design reviewable randomness workflows, and decide what an AI agent audit trail must record when models call tools or affect external systems.
Updated August 24, 2026
Evaluate random bytes and bounded-number APIs, compare REST and gRPC, verify receipts and Merkle proofs, and prepare gaming or drawing systems for technical review.
Explore randomness guidesAI audit evidenceAgent audit trails, tool calls, approvals, and external effectsDefine the records needed to reconstruct an AI execution, protect sensitive payloads, detect tampering, and support review outside the originating application.
Explore AI evidence guidesSecure randomness API
Learn how to evaluate a secure random number API for random bytes, bounded integers, REST and gRPC integration, receipts, and audit evidence.
Read guideEvidence architecture
Understand how randomness receipts, hash chains, and Merkle proofs preserve request history and support independent review without exposing raw secrets.
Read guideAPI integration
Compare REST and gRPC for random bytes, numbers, shuffling, and sampling, including connection behavior, latency measurement, retries, and operations.
Read guideRandomness validation
Learn how to interpret PractRand, ENT, Dieharder, NIST STS, and TestU01 BigCrush results and why statistical testing does not replace security review.
Read guideGaming and drawing controls
A technical checklist for gaming, probability items, lotteries, and drawings that need secure random generation, evidence retention, and external review.
Read guideAI agent governance
Learn what an AI agent audit trail should record across prompts, model decisions, tool calls, approvals, external actions, retries, and evidence export.
Read guideAudit log schema
Design a versioned AI agent audit log schema for identity, model runs, tool calls, approvals, outcomes, integrity checks, privacy, and review.
Read guideTool-call evidence
Design AI tool-call logging that records authorization, normalized inputs, results, errors, approvals, external effects, and tamper-evident exports.
Read guideEvidence lifecycle
Plan retention, legal holds, deletion, export manifests, checksums, access controls, and independent verification for AI agent audit evidence.
Read guideShare the workflow, expected traffic, retention policy, and review obligations. Rantropy engineering will identify the events, API controls, and evidence outputs that need to be tested.