High-volume refunds, payouts and chargebacks executed by agents. Human in the loop. One tamper-evident composite receipt that any regulator, partner or customer can re-verify offline — with zero trust in us.
order:demo-7421E-commerce is the highest-stakes, highest-volume, lowest-tolerance environment for agentic actions. A €49 refund looks small — until it's 18,000 of them, chargebacks spike, or an auditor arrives.
Dashboard screenshot. Internal log entry. "Approved by admin-42". All inside your system. A motivated actor (or compromised agent) can rewrite it. Auditors have to believe you.
One signed composite record: the exact agent intent, the generated credit-note artifact, and the human credentialed approval. Re-check the signature, the inclusion proof in the transparency log, the timestamp, and the Bitcoin anchor — entirely offline.
Each proof is independent. Together they make a receipt that is extremely hard to fake after the fact.
All four are exercised on the same e-commerce composite receipt in the demo.
The verifier is deliberately separated. You see exactly which gate rejected the receipt. Perfect for e-commerce audits and partner reconciliation.
Recomputes the signing payload and verifies the detached signature against the public key in the receipt.
Folds the leaf hash up the sibling path. Must reproduce the signed Merkle root in the checkpoint.
Verifies the checkpoint signature and that the log size at time of inclusion is consistent. OpenTimestamps anchor provides external time.
Structural validity of the composite profile, claim classes within honesty bounds, and Bitcoin time anchor.
Pilots are open. Verifying is free forever. The neutral witness service is what you pay for.