Every judgment seals to canonical bytes and anchors beyond our reach. The evidence travels with it.
Specimen record · not a live object
Your model concludes. Censio records it so it can be checked.
Software now decides things that matter: whether a payment clears, whether a claim is paid, whether a name is a match.
For each of those judgments, Censio writes a record: what was concluded, on what evidence, by which method, with what confidence. The record is sealed, so any later change to it shows. It is anchored beyond our reach, so anyone holding it can check it years later without asking us.
That record is a Trust Object. The copy you hand to an auditor is a CensioCert. TIP also specifies an inline gate, which can hold an action whose evidence falls below a threshold you set.
One sealed record for every machine judgment: the claim, the evidence, the method and the confidence behind it.
A certificate anyone can check
The same record in a form an auditor, a counterparty or another machine can hold and read.
A public verify page
Anyone holding a certificate recomputes its seal against the anchor, without our permission and without us logging it.
One API, one MCP
The same record issues and reads through one API and one MCP server. No second product, no mapping layer.
The register
A published page stating what is shipped, what is in build and what is only specified.
Many sources.
One record.
A conclusion is not one document. Evidence arrives from registries, filings, counterparties and the model's own reasoning — and every strand of it resolves into a single sealed object, including the strands that disagreed.
It ends in a verdict, reached without contacting the issuer.
censio · verifyspecimen walk0%
VerifyRead the method →
[ CensioCert™ × TIP™ ]
The certificate is the CensioCert
A Trust Object is the record. A CensioCert is that record in the form something else can hold — an auditor, a counterparty, a regulator, or another machine.
What it is
A single document, issued for one machine judgment. It states what was concluded, how confident the system was, which named method produced that number, how much evidence sat under it, and when it was sealed.
It is the artefact that leaves the building. Everything an auditor, a counterparty or a regulator needs to check the judgment travels inside it — including the anchor references that let them do the checking without contacting us.
What is printed on it
The object id, so the record can be found again. The confidence, against the threshold that was in force. The method and its version, so the reasoning can be read rather than guessed at. The evidence count, including how many sources disagreed. The seal, its epoch, and the qualified timestamp it commits to.
What it does in the room
Censio never originates a decision. TIP specifies an inline gate. Run in the path of an action, it measures each judgment against the rules you set. It can allow, flag, hold or redirect one whose evidence falls below your threshold. The full argument, with a worked case, is on Censio, explained.
How you get one
A certificate is issued with the record, through one API and one MCP — not a REST product and a separate agent product with a mapping layer between them. There is also a public verify page and terminal access for operators who would rather not leave the shell, but those are surfaces onto the same thing. The certificate an auditor opens and the payload an agent parses are one record.
A Trust Object carries the claim, the confidence and the method that produced it — so the decision is made on the record, not on the output.
Is this supplier still certified?
Certification active as of 2026‑08‑31.
Confidence
0.94
Method
M2 · Registry resolution
Sources
2 registries, 1 issuer
Carry the reasoning, not just the answer
Every judgment keeps the path that reached it. A decision you cannot explain six months later is a decision you cannot defend.
Why did the model decline this?
Applicant record resolved · 3 sources
Income evidence incomplete · 1 gap
Threshold not met under S4
Declined on the gap, not on the applicant. The gap is named in the record.
Prove it later, to someone who wasn’t there
The record seals to a qualified timestamp and, where live, a public anchor. Anyone holding the certificate can check it without asking us.
Show me the record for case 4471.
tip://4471·a4f2e9
Sealed
2026‑09‑02 14:02:11Z
Anchor
Epoch 8813, root verified
Status
Intact
Specimen conversations. The ids and dates are illustrative and resolve to nothing.
Independently anchored
Every epoch root commits to a qualified timestamp and, where live, a public chain. Neither is operated by Censio.
Tamper‑evident
Any change to a sealed record breaks its fingerprint. The break is detectable by anyone, not reportable by us.
Verifiable without us
A certificate holder checks a record against the anchor directly. Censio does not log that they did.
Where it runs
Regulated, contested, or long-lived.
Shipped
Sanctions screening
Screening decisions carry the list version, the match logic and the evidence that cleared or held them.
Shipped
Claims
A claim assessment records what was considered, what disagreed, and the confidence the model actually held.
Shipped
Counterparty diligence
Diligence files supersede as filings change, without erasing the position taken at the time.
In build
Underwriting
Pricing and acceptance decisions replay against the evidence held at the moment they were made.
In build
Credit
Affordability and limit decisions with the methodology version attached to each outcome.
Specified
Agent mandates
The warrant an autonomous agent acted under, and the chain that authorised it.
Minutes to integrate
Quickstart
One REST endpoint issues the record. One MCP server exposes it to an agent. Verification needs neither — it is a walk anyone can run against bytes they already hold.
The specification for the machine-judgment record: what RECORD states, how SEAL canonicalises, where ANCHOR commits, what VERIFY walks, and how SUPERSEDE replaces without erasing.
Why verification must not route through the issuer
If the party that made a judgment is also the party that confirms it, the confirmation carries no information. What independence actually requires, and what it costs to build.
The record TIP produces for one machine judgment. It carries the claim, the confidence, the method that produced it, the evidence it rests on, and a fingerprint that seals all of it together. It is the thing an auditor reads, not a log line.
Does Censio make the decision?
Censio never originates a decision — your model or your team does that. But it is not only a witness. Run inline, it sits in the operational path and measures each machine judgment against your own parameters and governance rules, and it will block, flag or redirect an action whose evidentiary support falls below a threshold you set. So it can stand between a judgment and its consequence, at your discretion and on your rules. What it will not do is decide in your place.
What happens if Censio disappears?
A sealed record stays verifiable. The epoch root is committed to a qualified timestamp and, where live, to a public chain, neither operated by us, and the verification walk is specified in the open. If verification routed through us, the confirmation would carry no information.
Can a record be changed?
Not silently. Any edit breaks the fingerprint, and the break is detectable by anyone holding the certificate. When the evidence genuinely moves, SUPERSEDE issues a new record linked to the one it replaces — the superseded record stays readable and stays verifiable.
Do you see our data?
Sealing works on a fingerprint, not on the content. What is anchored is a digest. We also cannot see who verifies a record, because verification does not route through us.
Is the specification public?
The specification is. The conformance test vectors and the reference implementation are issued to implementers under agreement and are not published — that is a deliberate withholding, and it is stated on the register page too rather than left as a blank.