The Problem
You cannot retroactively produce
an audit trail that was never written.
Automated systems now make decisions that money, data, and compliance depend on. Every one of those decisions is a future audit event. The organizations that will pass those audits are not the ones with the best story. They are the ones holding the stub.
Origin Is Not Enough
Other trails prove where a thing came from.
This one records what it withstood.
Signing and build provenance answer authorship: who produced an artifact, from what source. That is necessary and it is not sufficient. When an automated system makes a decision your compliance depends on, the question an auditor actually asks is whether the decision was examined, and what it survived. Counterfoil records that. For every step: what was checked, the verdict it returned, and a statistic showing the check measurably separates pass from fail. The receipt is not only that work happened. It is what the work was held against.
Confident And Wrong
A language model will state a fabricated fact
with the same fluency as a true one.
The hard problem with generated output is not that it is sometimes wrong. It is that wrong output arrives in the same confident register as correct output: invented statute numbers, plausible figures with no source, citations to documents that do not exist. To an untrained reader, and to a tool that only relays what the model said, the fabrication is indistinguishable from the fact until someone acts on it.
Our discipline treats every model, including our own advisors, as an untrusted source. High stakes questions go to a panel of independent models across different lineages, not a single answer. A verification pass then holds each claim to its own evidence: specific numbers, dates, and citations that cannot be confirmed are marked and removed, and the reasoning that survives is kept. When a finding later fails re-analysis, the correction is recorded in public rather than quietly revised.
What you receive is not model output. It is model output that has been checked against itself, with the fabrications marked and the survivors attached to their proof. In an era of fluent machines, the sellable difference is not the answer. It is the stub that shows which parts of the answer withstood scrutiny.
What You Receive
Four artifacts, in order.
Cryptographic inventory with file-level receipts
What cryptography you run and where: codebases, binaries, network handshakes, key management. The first question of every framework, answered with evidence attached to every finding.
Prioritized migration plan
Ranked by exposure window, blast radius, and cost, including the hybrid transition years most stacks will actually live through. A sequence a board can approve and an auditor can follow.
Attested evidence per asset
Every finding and every migration step appended to a hash-chained, cryptographically signed audit ledger. Each record independently verifiable after the fact, in both directions along the chain.
Gate performance statistics
We publish the discrimination statistics of our own verification gates, so your auditor sees not just that checks ran, but that the checks measurably separate pass from fail.
How the Stub Works
Verifiable in both directions.
Tamper-evident by construction.
Four properties, enforced in code rather than promised in policy. Anyone holding the counterfoil can re-verify it without trusting us, including which checks the work faced and how they ruled.
Every action appends one record: what ran, what it found, when, with what inputs.
Each record carries the hash of the one before it. Remove or alter any link and the chain breaks loudly.
Records are authenticated with a keyed signature. A forged record fails verification without the key. A receipt can also carry a second seal from a hardware root of trust (TPM 2.0), a key that cannot leave the machine that issued it. That narrows key theft and cross-machine forgery. It does not make the input honest, and the receipt says so.
The finished chain verifies forward and backward to its anchor. Your copy is the counterfoil: the stub you keep.
The same discipline binds our marketing to our code: every capability claim on this page is tied to an executing proof in a claims registry, and the coverage matrix we show buyers is rendered from that registry rather than written by hand. See a live sample of the underlying log on the agent substrate page.
Who It Is For
Built for the audit you have not had yet.
US federal contractors
Post-quantum compliance deadlines arrive by 2030, and misrepresenting cryptographic compliance now carries False Claims Act exposure. When the question comes, a scan summary is not a defense. An evidence chain is.
Regulated industries
The EU AI Act will require automatic event logging for high-risk systems. The 2026 Digital Omnibus deferred the standalone high-risk deadline to December 2027, but the obligation is confirmed, not cancelled, and an evidence trail is far harder to reconstruct after the fact than to keep from the start. Counterfoil exceeds the logging floor: not just logged, but tamper-evident and independently verifiable.
Clinical AI and genomics
An AI system that needs notified-body review under the EU medical device regulations is high-risk under the AI Act. The 2026 Digital Omnibus moved that high-risk deadline to August 2028 for AI inside regulated medical devices, but the evidence obligation is fixed and the lead time to build it is long. FDA asks for the same shape of evidence across a device lifecycle in its draft AI guidance. Genomic data raises the bar again, because the data never expires and its custody obligations outlive every credential that protects it today.
Anyone deploying agents
In a 2026 Grant Thornton survey of roughly 1,000 US senior business leaders, 78 percent lacked full confidence they could pass an independent AI governance audit within 90 days. The gap is not tooling. It is evidence.
Why Believe Us
The hardware receipts are public on the IBM job ledger. The correction record is part of our story: a firm selling evidence discipline should be able to show its own.
Next Step
Two weeks to know exactly
where you stand.
The engagement starts with a two week readiness assessment: what cryptography you run, where the exposure is, and what the auditor will see. Every step of it arrives with its counterfoil attached.