Prove it — to a party that does not trust you.
A log is a story told by the party under investigation. This is a record your auditor, your insurer, your acquirer, even the vendor on the other side of the incident, can re-derive without trusting you, your model provider, or your cloud.
A node is a grounded claim, not a log line.
Every claim reduces to one of three roots, and the root is part of the claim rather than metadata about it. Grounding is what the claim terminates in: an observation that was witnessed, a deterministic derivation, or a decision made earlier that everything after it must stay consistent with.
A claim that grounds in nothing, or in itself, is not a weak claim. It is not a claim. The verifier names that condition grounding_unresolved, and it is the whole difference between evidence and assertion.
Four relationships, four independent sources.
A claim sits in a neighborhood. To forge it you must satisfy all four constraints at once, and satisfying one tends to break another. Consistency with one is cheap. Consistency with all four, from four sources that do not answer to each other, is not.
None of the four is an alert someone configured. They already stand around every claim and every action, so a bad one fails a constraint whether or not anyone saw it coming. Catching the next one never depends on having imagined it first.
Is there a path from this claim back to the task that authorized it? A step that touches files with no derivation path to the work at hand fails here.
Did the authority exist before the work began, and does the ordering hold? A credential justified by a job that closed months ago is stale, whatever it still opens.
Do the conditions the sealed grant named actually dereference? This is the only one of the four that is access control, and the only one that refuses.
Has this actor issued this verb before? The answer is a lookup, not a score, and absence is the finding. It reports; it never blocks.
Coherence is the proof, not the seal.
A claim is coherent when it agrees with all four of its neighbors at once: where it came from, when it happened, what it was allowed to do, and what its actor has done before. Any single one of those agreements is cheap to manufacture. All four at the same time, from four sources that do not answer to one another, is not. That simultaneous agreement is the thing a forgery cannot hold together; move one piece to cover a lie and it stops matching the other three.
So the proof was never the seal. A seal tells you the bytes have not changed since they were written; it says nothing about whether they were ever true. Coherence is the question with teeth, was this claim ever sound, and it is the one an outsider can re-derive without trusting us. A claim can pass the first test and fail the second. One of ours did, in production, for four days.
A green seal on an incoherent claim is worse than no seal.
Definition of record · Part I
All four decide correctly. One survives the argument.
Each of these objections has been asked in earnest, and in every case there is a component here that does the thing being named. The distinction is never the decision. It is what is left behind once the decision is made, and by whom it can be checked.
(grant, action) pair. Everything needed to recompute the verdict without trusting us.What a refusal actually carries.
2026-08-17, production. A coding agent proposed a destructive verb against a live pod. The gate refused on two named predicates and the command never reached the cluster. Note what is not in the record: no score, no confidence, no model. The verdict is a computation over two documents.
{
"verb": "unclassified",
"actor": "deploy-orchestrator",
"outcome": "refused",
"resource": "helm uninstall myapp -n myapp-production",
"failures": [
{ "predicate": "verb_in_envelope", "expected": "git.push, k8s.read", "actual": "unclassified" },
{ "predicate": "environment_in_envelope", "expected": "staging", "actual": "production" }
],
"gate_version": "authority-gate/1",
"proposal_snapshot": "dd46f69c5befc998084220877b71692763372114f7dadb6f30d58de6600cb771"
}The refusal returns into the agent’s loop as a tool error naming the unsatisfied condition and the grant clause it came from. The agent does not choose to stop; the call fails. And the refusal is itself a sealed claim, so the reconstruction a post-mortem would go looking for is already in the record.
You don’t run the graph. You run on it.
The evidence graph is the layer under the compliance, vendor-risk, diligence and agent work you already do on the platform. You never operate it directly. It surfaces in the three places that matter to the people who do not trust you.
A control attestation, a vendor-risk finding, a diligence pack: each one arrives bound to the grounding it rests on, sealed and externally anchored. Nothing you hand out stands on our word.
Put an agent to work on your compliance program and every move it proposes is checked against its grant and sealed before it runs. The graph is what makes each action provable rather than taken on faith.
Trustworthy Autonomy™ →The anchor is an independent timestamp authority, not our database. Your auditor, insurer, or acquirer confirms a record existed and has not changed on their own, so the answer is never us vouching for ourselves.
The one number you can’t re-derive.
Everything above this line re-derives from the chain. Price doesn’t, so we state it rather than make you ask. Three ways to put the evidence graph under your own program: you run it, we run it, or we build it around you.
Embed the SDK in your own stack; you hold your own data and we never become its custodian. One-time $40K integration, $350–500K for multi-product. You are renting the part you can’t rebuild: the projector and graph-wide verifier never leave our side.
Request access →Run on our infrastructure and operate nothing yourself. The base covers your first chains and volume; integrity is metered above it, so a mid-size program lands near $150K all-in. We hold the chain, you hold the proof.
Request access →Audit firms, standards bodies, regulators, defense. Unlimited chains, dedicated infrastructure, contractual custody terms, source escrow: for the buyers who most need to prove it to a fourth party.
Request access →The first five licensees take 50% off year one, held for two years, in exchange for a named reference.
That puts a Library charter at $100K in year one, the anchor halved. It’s the only discount we give.
Trust shouldn’t require faith. It should require evidence.
License the evidence graph under your own program: as a library you run, or hosted by us. Tell us which shape fits and we’ll get you access.