Skip to content
Trust API · api.griffynx.com

One call. A decision you can defend.

Present what the counterparty offered, declare the purpose of the enquiry, state what is at stake and how long you can wait. Receive a score with its confidence interval, the evidence summary, the findings as plain statements, the absences, and your policy's label — carrying the methodology version and timestamp an examiner will ask for.

The call

What goes in, and what comes back.

Every enquiry names its purpose and its stake. The stake — a payment, a credit line, an account, a listing, a hire — determines how tight an interval the decision requires and how much evidence is worth gathering to reach it. The deadline determines when you receive a first answer.

POST /v1/inquiriesrequest
POST /v1/inquiries
Authorization: Bearer gx_live_…
X-Purpose: fraud_prevention

{
  "subject": {
    "presentations": [
      { "type": "PHONE", "value": "+91 98765 43210" },
      { "type": "EMAIL", "value": "a.sharma@example.in" }
    ]
  },
  "intent":  "onboarding_screen",
  "purpose": "fraud_prevention",
  "stake":   { "kind": "account", "reversible": false, "deadline_ms": 3000 },
  "render":  "none"
}
one assessment, evidence attachedresponse
200 OK

{
  "inquiry_id": "0f4c…",
  "status": "concluded",
  "assessment": {
    "score": 71, "low": 58, "high": 84,
    "preliminary": false,
    "methodology_version": "m1-graph",
    "as_of": "2026-09-14T09:12:04Z",
    "label": { "value": "review", "policy_version": 3 },
    "evidence": {
      "signals": 12, "failed_signals": 2, "contradictions": 0,
      "by_trust_band": { "high": 4, "medium": 6, "low": 2 }
    }
  },
  "findings": {
    "findings": [
      { "kind": "account_age", "about_type": "EMAIL",
        "statement": "The address has been seen in public records for under 60 days.",
        "trust_band": "medium", "disposition": "weakens" }
    ],
    "absences": [
      { "about_type": "PHONE", "kind": "budget",
        "reason": "A carrier lookup was not run at this tier." }
    ],
    "coverage": { "checks_run": 14, "checks_answered": 12, "checks_unanswered": 2 }
  }
}

Illustrative values in the shapes of the published contract. Every field above is in the OpenAPI document at api.griffynx.com.

The response

Every field, and why it is there.

An integration decision turns on what comes back, and prose about it is always vaguer than the object itself.

The assessmentreturned on every call
score71
The assessment, on a fixed scale. Computed by one function from the admitted evidence, and by nothing else.
low · high58 · 84
The confidence interval. It widens when evidence is thin or in conflict, which is the information a single number destroys.
evidence12 signals · 0 contradictions
Counts by provenance class and by the banded trust of each source. Never a source name, never a raw payload.
findings[]statement · kind · trust_band · disposition
Each fact in plain language, with what sort of check produced it and whether it supports or weakens trust.
absences[]timeout · no_data · budget · refused
What was asked and did not answer, with the reason. An assessment that cannot state what it failed to learn overstates what it knows.
methodology_versionm1-graph
The version of the reasoning that produced this. An assessment issued in March can be reconstructed in October.
as_of2026-09-14T09:12:04Z
The moment the evidence was current. Assessments never change retroactively.
labelreview · policy v3
Your policy applied to the assessment, naming the policy version that applied it. The label is yours; we do not supply it.

Eleven families, one contract

What is served today, and what is published.

Inquiries and health are served now. The remaining families are published as a fixed contract: the request and response shapes will not change beneath an integrator, and each returns 501 until its handler ships.

The documentation marks the status of every endpoint. Discovering it at three in the morning is worse than reading it here, and a contract that quietly changes is worse than both.

ServedContract published

Inquiries

Served

Ask about a subject and receive an assessment. The endpoint most integrations use and, for many, the only one they require.

Health

Served

Liveness for your monitoring. /healthz additionally reports the running build, the source count and database reachability.

Observations

Contract

Your own testimony about a subject. What you know and nobody else does enters here carrying its provenance, and is weighed accordingly.

Outcomes

Contract

What actually happened after you decided. The single most valuable thing you can return, and the only mechanism by which assessments learn your book rather than the average book.

Material

Contract

Documents, images, audio and video, declared before transmission. Extraction produces bindings; the bytes can be processed and never retained.

Cases

Contract

An investigation with more than one subject and more than one analyst, and a record of who did what. Every case carries an authorisation before it opens.

Monitors

Contract

A standing watch on a subject. You are notified when the answer changes, rather than re-querying on a schedule.

Sessions

Contract

A live connection for open-ended intake: frames in, events out, over a WebSocket.

Entities

Contract

A subject resolved across more than one identifier, and its assessments in sequence — which is reputation over time.

Registry

Contract

The artifact types, intents and purposes your tenancy may present and declare. Read at startup rather than hard-coded into a list that will drift.

Control plane

Contract

Keys, policy, webhooks and your audit trail, under a separate scope. A key that can open inquiries cannot mint another key.

What a buyer can hold us to

Enforced in code, each with a test behind it.

These are the properties that let a model-risk function sign off on a third-party assessment rather than treat it as an unexplainable input.

A single function computes the score

Score and interval derive from admitted evidence alone. No model, analyst, customer, policy or engineer sets, adjusts or tightens them under any circumstance.

Purpose on every call

An enquiry without a registered purpose is refused. Every case carries an authorisation record and a budget; every analyst action is audited.

No provider identity crosses

No source is named and no raw payload is returned. A finding is a statement with its provenance class and the banded trust of its source; raw material is retained by hash for audit alone.

Demography never reaches the score

No source, typology, route or policy default keys on a protected or proxy attribute. Identical evidence produces an identical assessment, whoever it concerns.

Dated, versioned, reproducible

A methodology version and an as-of timestamp on every assessment; ledgers are append-only. The answer you acted on can be reconstructed.

The label is your policy

Thresholds, labels and actions express your risk appetite. The response names the policy version that applied, so a historical label can be explained without relying on memory.

Operating characteristics

Built for a decision that cannot wait.

Answers on a deadline

Set deadline_ms and receive a preliminary assessment within the window, refined afterwards rather than withheld. Synchronous, asynchronous, or revisions streamed over SSE.

Registered, never enumerated

Artifact types, intents and purposes are read from the registry your tenancy is permitted. Adding a type requires a specification and a source, not a release.

Keys shown once, stored hashed

Tenant keys are minted in the control plane, displayed once and retained as a salted hash. Provider credentials never enter this layer at all.

Read the contract before you talk to us.

The documentation is public and generated from the running service, so it cannot claim an endpoint that does not exist. Keys and pilots follow a conversation.