Signed receipts
Any third party holding one can verify it independently.
Our job is refusing the wrong action and proving the right one. Every claim below can be checked independently.
Ambiguity, misconfiguration, or partial failure produces refusal, never silent success.
A slow no costs a retry. A confident, wrong yes costs money and trust.
Ed25519 signatures and SHA-256 hash chains, deliberately unoriginal. Every signed format is versioned, so the algorithms can evolve without breaking today's receipts.
Any third party holding one can verify it independently.
Integrity anchors are independently verifiable. Tampering is mathematically visible, not policed after the fact.
Content hashes, defined retention windows, redaction support.
No separate compliance view. The evidence chain is the system of record.
Multi-tenant systems fail quietly at the boundary. Identity, trust, and access never come from the caller.
Most breaches walk in through an admin panel or a leaked secret.
Six controls, exercised in CI on every change rather than audited once.
Full dependency review 2026-07-11: zero advisories, production and full tree.
Independent penetration test (Phase 1) 2026-08, all in-scope findings remediated. Full-codebase security review 2026-07. Provisional patent filed 2026-07-24.
FOUND SOMETHING? Reports go straight to the founder: [email protected]. Full terms: security.txt.
The controls below are architecturally verifiable right now: check the receipt and key endpoints yourself. Third-party certification is separate work, stated here rather than left silent.
Certification changes who else has checked our homework, not what holds.
Bring your hardest questions. Every answer comes with a receipt.
Request early access