Corobate

The attestation layer for machine & AI decisions

Attest your basis for decisions — with indelible receipts.

You already run the checks. Corobate seals them — under your brand, your API, your customer relationship — so any verdict re-runs and proves itself. We embed inside your platform and never sell direct.

Your customers are starting to ask for decisions they can prove. Ship that proof inside your product — the deadline is fixed, and readiness is a build-time decision.

Record when and why and how you determined to move forward.

Live sealed receipt
Re-runnable ✓

Subject: · criteria

Confidence 0.00

Bound by:

SHA-256 seal

Break it yourself: toggle a verified input to stale and the seal refuses to sign — that refusal is the product. This runs the same invariants as the core engine; request a live API key in a briefing. 30 seconds, nothing to install.

The gap

A signature proves the file is unchanged. Corobate proves the verdict still follows from the inputs.

Regulated decisions made by machines and AI agents now have to be provable after the fact. When a regulator, counterparty, or auditor asks "show me this decision was justified," a signature and a log confirm that the bytes existed. Corobate goes further: it makes the responsible party's own verdict something a third party can re-execute and integrity-check — so the reasoning itself holds up on its own.

What Corobate is

A receipt anyone can re-run.

Corobate is a verification component that seals a reviewer's due-diligence verdict into a calculated provenance receipt — a content-addressed, hash-chained record any counterparty can independently re-run and integrity-check. It rides inside the tools that already run the checks.

  • It attests the process and inputs behind a verdict — the reviewer stays the one who stands behind the subject.
  • It strengthens the responsible party's own audit evidence, supporting the obligations the law places on them.
  • It makes that verdict replayable and tamper-evident, so trust rests on re-execution that anyone can repeat.
Digital signature / timestamp Corobate seal
Attests Bytes existed / were signed by a key-holder A verdict follows from stated inputs under a stated criteria version, unaltered
You must trust The CA / TSA + key custody Just re-execute it yourself
Legal effect Varies (eIDAS / ESIGN) Supports whoever the law names

The vocabulary is deliberate: Corobate seals, witnesses, and attests — and every claim it makes rests on re-execution that anyone can repeat, standing on its own.

Why it's different

Three disciplines, enforced in code.

01

One provenance class per input

Every input is VERIFIED, MODELED, or SELLER-ASSERTED — so every number in the record arrives with its provenance attached.

02

Gated confidence, honest abstain

Confidence is bounded by the least-reliable critical input; a stale one forces a named ABSTAIN. The system states plainly when the evidence runs thin.

03

Reproduction you re-run yourself

A third party re-runs the decision from the recorded inputs and confirms it reproduces — hash-for-hash. The seal is only as good as its replay.

The differentiator

We seal the discharge of duty — and its boundary.

Corobate seals the method, the criteria version, the content-addressed evidence set, the calibrated operating characteristics including the known blind spots, and a boundary map of where the evidence reaches, and where its view ends. The predictive verdict is demoted to a non-binding, derived readout.

What is sealed — "we ran calibrated method M over evidence E, and here is the edge of what M can see" — is true regardless of outcome. The receipt stands as the user's defense. This is only buildable by a system that already has the abstention, evidence-sufficiency, and calibration machinery. That is the moat.

Regulatory timing

Three markets where "provable" is becoming law.

Illustrative ROI — assumptions validated per pilot
AI agents

EU AI Act · Article 12

WITHHELD (ABSTAIN)

Article 12 logging duty for Annex III high-risk applies 2 August 2026 — the requirement is set. Be the platform that is ready first.

Illustrative: avoids the €15M / 3%-of-turnover penalty cap; ~$50k–$250k/yr audit-labor saved.

Finance

Model risk · SR 11-7

APPROVE · reproduced

Model validation and ongoing monitoring, made replayable — every approval and every abstention returns a record that reproduces.

Illustrative: ~$250k–$2M+/yr validation + avoided remediation across ~175 models per bank.

Batteries

EU Digital Product Passport

CAUTION · gap named

Greenwashing enforcement (ECGT) from 27 Sep 2026 — claims must be substantiated, and gaps named rather than smoothed over.

Illustrative: avoids ≥4%-of-turnover greenwashing fines.

Regulatory references denote the timing that makes provability material; figures are illustrative examples, validated per pilot.

Real sealed receipts

Receipts from actual engine runs — one for each world you live in.

These are outputs of our own simulations, verified by re-execution: each verdict reproduces hash-for-hash under engine.verify. Provenance-classed inputs, confidence capped by the weakest critical one, and the blind spot named on the face of the receipt.

Illustrative values from internal engine runs (2026-07), reproduced on re-execution. Confidence figures are the engine's own — the Article 12 agent reproduces at 0.40, the number the engine actually returns, not a rounded-up card. Corobate attests the process and inputs behind each decision at a point in time.

The business model

OEM / embed. Corobate ships inside your product.

They sign your log. We re-execute your decision — and prove it reproduces.

  • Embed behind your existing REST API / technology-partner program.
  • Every decision and every abstention returns a sealed, reproducible record rendered under your brand — a render_url.
  • Independently verifiable against an external anchor, so a customer's auditor can confirm it from the re-run alone.
  • Sealed record returned in <200 ms.
  • You keep the brand, the customer, the pricing, and roadmap input. Design partners shape the seal spec before it is fixed.
Our loyalty is structural

We never sell to your customer, never appear in their UI, and never hold the relationship. Corobate has no direct sales motion — we can only win when you do.

Engineering credibility

Four invariants enforced in code.

Every screen ships conformant by construction — the shared core builds only receipts that hold.

Invariant 01

Constraint before fit

A kill-switch gate (DISQUALIFY / CAUTION / ADVANCE) runs before any scoring. Protective information first.

Invariant 02

Abstention first-class

ABSTAIN builds, seals and renders with the same weight as approve. Refusal is a first-class result.

Invariant 03

Sealed before shown

The receipt hash is chained to a tamper-evident ledger before the verdict renders. The renderer throws on an unsealed receipt.

Invariant 04

Provenance on every number

Every figure is VERIFIED / MODELED / SELLER-ASSERTED. Only tagged evidence enters the record.

Under the hood SHA-256 hash-chained receipt ledger; calibration by Brier score / skill score; a calibrated gate (p_cal ≥ 0.80, n ≥ 20 else ABSTAIN) using the Wilson lower bound so small samples stay honest at the gate; Benjamini–Hochberg FDR control; deterministic replay verification — re-execute R(engine_version, inputs, evidence) and confirm SHA-256 matches. Every published verdict re-derives from its own recorded evidence — or the mismatch shows in a single comparison.

Honest by construction

We're new — so instead of testimonials, we offer something better: re-run any answer yourself and watch it reproduce.

Every claim here is one you can check for yourself. For a product whose whole promise is verifiable claims, earning trust that way is the point.

The moat

The discipline is the defence.

Corobate is an embeddable relying-system primitive — the seal that rides inside the tools your customers already trust.

The real defensibility lives in disciplines only this model sustains: sealing before the outcome is known, disclosing publication ratios, and verified abstention. Honest abstention is native here — and structurally hard to match for a business paid per positive pick.

Embedded, it becomes your moat: sell provable diligence — defensible whether the outcome is right or wrong — as a line item you can price.

The embeddable primitive is patent pending — U.S. Patent Application No. 19/747,068, filed July 20, 2026 — part of a broader claim estate.

For partners

The questions your legal, security, and channel teams will ask.

Written to be forwarded. Answered plainly, in the same voice as the rest of the page.

Will Corobate ever compete with us, or sell direct?

No — it is OEM-only by construction. We have no direct sales motion, no dashboard your customer sees, and no relationship with your buyer. Corobate renders under your brand and stays invisible. Structurally, we can only win when you do.

What happens to our customers if Corobate goes away?

The receipt re-runs without us. Verification is deterministic and offline — a customer's auditor re-executes the decision from the recorded inputs with no dependency on Corobate being online, or even existing. Self-hostable verification and source/key escrow are available to design partners, so the seal you ship keeps working regardless of our future.

We'd be an early partner — are we a guinea pig?

No. Design partners get founder-level terms and shape the seal spec before it is fixed. The engine and API are stable and versioned, and the core primitive is patent pending (U.S. Patent Application No. 19/747,068). The name is separately pending trademark clearance — the technology is real, filed, and versioned.

Does embedding this add a regulatory claim we'd have to defend?

The receipt is your defense, not a new promise. It attests what method you ran over what evidence — true regardless of outcome — and names its own blind spots. It supports the obligations the law already places on you rather than adding one to keep. (Your counsel owns the determination.)

What's the integration lift, security posture, and commercial model?

Embed behind your existing REST API; a sealed record returns in <200 ms. Security, data residency, key custody, SLA, liability, and revenue-share are covered in the briefing and the partner agreement. Ask for the security brief — we'll send it before you spend an integration hour.

About us

Four decades of risk and provenance, distilled into one primitive.

Corobate is built by its founder, Stan Smith — who has worked at the frontier of risk management and data provenance since 1982, coined the term "Data Supply Chain," and holds six issued patents across the data-supply-chain and data-provenance domain. Corobate itself is the subject of his seventh — a U.S. patent application filed July 2026 (patent pending).

Since 1982

Four decades in the field

Risk management and data provenance — from before the discipline had a name.

Six patents

Issued, not pending

Six issued patents across the data-supply-chain and data-provenance domain.

The vocabulary

Coined "Data Supply Chain"

The term the field now uses to reason about where its data comes from.

The disciplines the engine enforces — one provenance class per input, freshness bounds, confidence capped by the weakest critical input, and honest abstention — are not academic. They come from a career spent making risk decisions defensible in the real world. When you embed Corobate, you are building on that track record, not betting on newcomers.

Talk to us

Partner & briefing enquiries — partners@corobate.com. Prefer to look first? Break the live receipt above, or ask for a sample sealed receipt and the security brief.

Start here

Prove it yourself — three ways, in ascending order of commitment.

You don't have to take our word for anything. Each step stands on its own.

01

Break the live receipt

Toggle a verified input to stale in the demo above and watch the seal refuse to sign. Re-run it and confirm it reproduces, hash-for-hash.

Right now · on this page · 30 seconds Open the demo ↑
02

Test the engine yourself

Request a sandbox render_url and API key, and run your own decisions through the sealing logic against your own inputs.

A short email · sandbox access Request sandbox access →
03

Book a technical briefing

30 minutes with an engineer — architecture, embed surface, and where it fits your API. No slides, no procurement. Bring your hardest integration question.

30 minutes · with an engineer Book a briefing →

Prefer to start scoped? Start with one control surface →  ·  Or just want the doc? Get a sample receipt & security brief →

Corobate

Attest your basis for decisions — with indelible receipts.

You watched a proof refuse a stale input. That is the whole product: a verdict your customer's auditor can re-run and trust — rendered under your brand. Bring us a decision; we'll seal it live.

The platforms that win the next audit cycle are the ones whose customers can prove every decision. Be the one that already can.

Thanks — your request is in. We'll reply within one business day at the email you gave. Prefer to talk sooner? partners@corobate.com.

Prefer to look first? Re-run a receipt yourself ↑  ·  Or email directly: partners@corobate.com