Why not use the Rust implementation[1] of the PGP instead? I feel that writing something new and complex like this in non-statically typed language (Python in this case) is a recipe for disaster. Someone suggested using TUF, but it's also in Python and prone to shifting compile-time errors to runtime.