Evidence in. A reproducible assessment out.
One kernel underlies every delivery surface. It admits evidence with provenance, reconciles it into a graph, reduces that graph to a score and an interval by a single function, and retains what it did. Countries, languages and identifier formats are data it loads — never branches in its reasoning.
First principles
The rules predate the technology, and outlast it.
The instruments of deception change each decade; the structure of the problem does not. A system built on the current generation of technology is obsolete with it. One built on how evidence is admitted, weighed, combined and remembered is not. Five rules follow from that, and the code cannot violate them.
Provenance is mandatory
Confidence is derived
Absence is evidence
Reasoning sees summaries
Memory is earned
One enquiry, end to end
Admit · Gather · Connect · Conclude · Retain
- 01
Admit
Presented identifiers are normalised and typed against the registry. A purpose is mandatory and recorded. The stake — what is at risk and how long you can wait — fixes the tolerable interval and the evidentiary budget. - 02
Gather
Sources are queried within that budget and the permitted tier. One tool, one provider, one signal per call. No tool calls another, and none aggregates on its own authority; each declares the direction of what it found. - 03
Connect
Signals, and the relationships the sources themselves reported, become edges in an evidence graph. Typologies name the structures that matter — a mule chain, a synthetic identity — so a conclusion can cite the relation a source actually reported. - 04
Conclude
The confidence function reduces the graph to a score and an interval, stamped with the methodology version and the moment the evidence was current. Your policy applies its label afterwards, and the policy version is recorded alongside it. - 05
Retain
The assessment, the evidence hashes, and any outcome you subsequently report enter an append-only ledger. The next enquiry about the same entity begins from what is already established.
The output
Every field exists because somebody has to defend the decision.
The interval exists because a single number conceals how much was actually established. The absences exist because a silent failure is indistinguishable from a clean result. The methodology version exists because the answer acted on in March must be reconstructable in October. None of it is decoration.
- score71
- The assessment, on a fixed scale. Computed by one function from the admitted evidence, and by nothing else.
- low · high58 · 84
- The confidence interval. It widens when evidence is thin or in conflict, which is the information a single number destroys.
- evidence12 signals · 0 contradictions
- Counts by provenance class and by the banded trust of each source. Never a source name, never a raw payload.
- findings[]statement · kind · trust_band · disposition
- Each fact in plain language, with what sort of check produced it and whether it supports or weakens trust.
- absences[]timeout · no_data · budget · refused
- What was asked and did not answer, with the reason. An assessment that cannot state what it failed to learn overstates what it knows.
- methodology_versionm1-graph
- The version of the reasoning that produced this. An assessment issued in March can be reconstructed in October.
- as_of2026-09-14T09:12:04Z
- The moment the evidence was current. Assessments never change retroactively.
- labelreview · policy v3
- Your policy applied to the assessment, naming the policy version that applied it. The label is yours; we do not supply it.
Position
What this replaces: none of your existing controls.
Trust intelligence sits alongside verification, bureau data, screening and fraud detection. It is the layer that reconciles what those return, together with evidence none of them collect, into one assessment carrying its own justification.
| Category | The question it answers | What it establishes | What it is silent on |
|---|---|---|---|
| Identity verification | Is this document genuine, and does this face match it? | That a credential is valid. | Whether the holder should be trusted in this transaction. |
| Credit bureaux | How has this person repaid obligations before? | A borrowing history, where one exists. | Counterparties with no file, and every party that is not a borrower. |
| Screening and watchlists | Does this name appear on a list? | Membership of a published list. | Everything not yet on a list, which is where new conduct lives. |
| Fraud detection | Is this transaction anomalous against our own history? | Deviation from an internal baseline. | A counterparty with no history on your platform. |
| Trust intelligence | What can be established about this counterparty, from what evidence, with what confidence? | A computed assessment with its interval, its evidence chain and its methodology version. | The decision itself. That is your policy, and it stays yours. |
Trust intelligence does not displace these. It is the layer that reconciles what they each return, together with evidence none of them collect, into one assessment that carries its own justification.
Architecture
Four surfaces, one reasoning core.
Discover for direct evaluation. The Trust API for systems. Investigate for analysts, cases and evidentiary bundles. Rating for the published, citable form. Every surface returns the same assessment from the same kernel.
The kernel is a library. Customers, keys, policy, audit and rate limits exist only in the gateway, so the reasoning core holds no customer state and remains portable. A market is a pack — artifact types, sources and typologies — not a property of the system.
Kernel
Source layer
Packs
Gateway
Examine it on a live identifier.
Discover runs the kernel at the open tier. X-Ray lifts the ceiling to licensed sources. The API places the same assessment inside your flow.