Trust intelligence infrastructure

AI produces intelligence. Censio produces trust.

The layer between a machine judgment and the decision made on it.
Every judgment leaves a sealed record. Anyone can check it later, without asking us.

Sanctions screeningEPCP · custody sealed
sourceHM Treasury
retrieved2026‑09‑04 09:12Z
stateunchanged
Counterparty fileEPCP · custody sealed
sourceCompanies House
retrieved2026‑09‑04 09:12Z
statesuperseded ×1
Adverse mediaEPCP · contested
sources6 of 52
agreementpartial
statecontradiction low
Trust ObjectTIP/1.0 · sealed
Trust ObjectCX‑924837
assessmentSolvency II compliance review
confidence94% · evidence high
evidence52 sources · contradiction low
methodologyv3.1 · published
verificationIndependent · seal intact

Checkable by someone who trusts neither of us.

Every judgment seals to canonical bytes and anchors beyond our reach. The evidence travels with it.

Specimen record · not a live object

Your model concludes. Censio records it so it can be checked.

Software now decides things that matter: whether a payment clears, whether a claim is paid, whether a name is a match.

For each of those judgments, Censio writes a record: what was concluded, on what evidence, by which method, with what confidence. The record is sealed, so any later change to it shows. It is anchored beyond our reach, so anyone holding it can check it years later without asking us.

That record is a Trust Object. The copy you hand to an auditor is a CensioCert. TIP also specifies an inline gate, which can hold an action whose evidence falls below a threshold you set.

Censio, explained

What you get

A record per judgment
One sealed record for every machine judgment: the claim, the evidence, the method and the confidence behind it.
A certificate anyone can check
The same record in a form an auditor, a counterparty or another machine can hold and read.
A public verify page
Anyone holding a certificate recomputes its seal against the anchor, without our permission and without us logging it.
One API, one MCP
The same record issues and reads through one API and one MCP server. No second product, no mapping layer.
The register
A published page stating what is shipped, what is in build and what is only specified.

Many sources.

One record.

A conclusion is not one document. Evidence arrives from registries, filings, counterparties and the model's own reasoning — and every strand of it resolves into a single sealed object, including the strands that disagreed.

1.0Record

States the claim and its evidence

Read the method
2.0Seal

Hashes the canonical bytes

Read the method
3.0Anchor

Commits beyond our own reach

Read the method
4.0Verify

Checked without asking the issuer

Read the method
5.0Supersede

Replaces without erasing

Read the method

One constitution. Six statutes. TIP defines the whole life of a machine‑judgment record — what it states, how it seals, and where it anchors.

FIG 0.1

The record

A Trust Object is layered — claim, evidence, method, version. Every layer is part of what gets sealed.

FIG 0.2

The anchor

Fingerprints batch into an epoch. The root commits to a qualified timestamp and, where live, a public chain — neither operated by us.

FIG 0.3

The surfaces

One REST API, one MCP server, the certificate an auditor holds, and the page anyone can check it on.

Resolve the claim withEvidence Search

Every assertion inside a Trust Object resolves to the sources that support it — and to the ones that argue against it.

The evidence network
  • Resolved 7 sources
  • Checked 2 registries
  • Weighed 1 dissent
  • Sealed 14:02:11Z

Test the record withPublic Verify

Anyone holding a certificate can check it against the anchor without asking us for permission, and without us knowing they did.

Verify a record

Verification

What checking a recordactually looks like

It ends in a verdict, reached without contacting the issuer.

censio · verifyspecimen walk0%
VerifyRead the method →

[ CensioCert × TIP ]

The certificate is the CensioCert

A Trust Object is the record. A CensioCert is that record in the form something else can hold — an auditor, a counterparty, a regulator, or another machine.

What it is

A single document, issued for one machine judgment. It states what was concluded, how confident the system was, which named method produced that number, how much evidence sat under it, and when it was sealed.

It is the artefact that leaves the building. Everything an auditor, a counterparty or a regulator needs to check the judgment travels inside it — including the anchor references that let them do the checking without contacting us.

What is printed on it

The object id, so the record can be found again. The confidence, against the threshold that was in force. The method and its version, so the reasoning can be read rather than guessed at. The evidence count, including how many sources disagreed. The seal, its epoch, and the qualified timestamp it commits to.

What it does in the room

Censio never originates a decision. TIP specifies an inline gate. Run in the path of an action, it measures each judgment against the rules you set. It can allow, flag, hold or redirect one whose evidence falls below your threshold. The full argument, with a worked case, is on Censio, explained.

How you get one

A certificate is issued with the record, through one API and one MCP — not a REST product and a separate agent product with a mapping layer between them. There is also a public verify page and terminal access for operators who would rather not leave the shell, but those are surfaces onto the same thing. The certificate an auditor opens and the payload an agent parses are one record.

One API, one MCP.

CensioCertTIP/1.0
Object
TO-8F41-C2E9-77A1
Issued
2026-09-08 · 11:04:22Z
Method
TWDP v2.1
Confidence0.94
14 sources · 2 contestedthreshold 0.90
Sealedepoch 41,208qualified timestamp
SpecimenVerify at censio.io/verify
inline · policy gateSIMULATED

Judgment, on the record.

Check a claim before you act on it

A Trust Object carries the claim, the confidence and the method that produced it — so the decision is made on the record, not on the output.

Is this supplier still certified?

Certification active as of 2026‑08‑31.

Confidence
0.94
Method
M2 · Registry resolution
Sources
2 registries, 1 issuer

Carry the reasoning, not just the answer

Every judgment keeps the path that reached it. A decision you cannot explain six months later is a decision you cannot defend.

Why did the model decline this?
  1. Applicant record resolved · 3 sources
  2. Income evidence incomplete · 1 gap
  3. Threshold not met under S4

Declined on the gap, not on the applicant. The gap is named in the record.

Prove it later, to someone who wasn’t there

The record seals to a qualified timestamp and, where live, a public anchor. Anyone holding the certificate can check it without asking us.

Show me the record for case 4471.

tip://4471·a4f2e9

Sealed
2026‑09‑02 14:02:11Z
Anchor
Epoch 8813, root verified
Status
Intact

Specimen conversations. The ids and dates are illustrative and resolve to nothing.

Independently anchored

Every epoch root commits to a qualified timestamp and, where live, a public chain. Neither is operated by Censio.

Tamper‑evident

Any change to a sealed record breaks its fingerprint. The break is detectable by anyone, not reportable by us.

Verifiable without us

A certificate holder checks a record against the anchor directly. Censio does not log that they did.

Where it runs

Regulated, contested, or long-lived.

Shipped

Sanctions screening

Screening decisions carry the list version, the match logic and the evidence that cleared or held them.

Shipped

Claims

A claim assessment records what was considered, what disagreed, and the confidence the model actually held.

Shipped

Counterparty diligence

Diligence files supersede as filings change, without erasing the position taken at the time.

In build

Underwriting

Pricing and acceptance decisions replay against the evidence held at the moment they were made.

In build

Credit

Affordability and limit decisions with the methodology version attached to each outcome.

Specified

Agent mandates

The warrant an autonomous agent acted under, and the chain that authorised it.

Minutes to integrate

Quickstart

One REST endpoint issues the record. One MCP server exposes it to an agent. Verification needs neither — it is a walk anyone can run against bytes they already hold.

Read the API
# specimen · verify a Trust Object without contacting the issuer
$ censio verify CX‑924837
fetching canonical bytes…
sha256 8f2a…c41d
epoch 20260904.07 · root a91e…77b0
timestamp matched
digest recomputed
● verdict independent · seal intact
issuer was not contacted

Notes

From the protocol desk

All notes
04 September 2026

TIP/1.0 — the five methods, published

The specification for the machine-judgment record: what RECORD states, how SEAL canonicalises, where ANCHOR commits, what VERIFY walks, and how SUPERSEDE replaces without erasing.

ProtocolRead
27 August 2026

Why verification must not route through the issuer

If the party that made a judgment is also the party that confirms it, the confirmation carries no information. What independence actually requires, and what it costs to build.

VerificationRead

FAQ

Questionsand answers

What is a Trust Object?

The record TIP produces for one machine judgment. It carries the claim, the confidence, the method that produced it, the evidence it rests on, and a fingerprint that seals all of it together. It is the thing an auditor reads, not a log line.

Does Censio make the decision?

Censio never originates a decision — your model or your team does that. But it is not only a witness. Run inline, it sits in the operational path and measures each machine judgment against your own parameters and governance rules, and it will block, flag or redirect an action whose evidentiary support falls below a threshold you set. So it can stand between a judgment and its consequence, at your discretion and on your rules. What it will not do is decide in your place.

What happens if Censio disappears?

A sealed record stays verifiable. The epoch root is committed to a qualified timestamp and, where live, to a public chain, neither operated by us, and the verification walk is specified in the open. If verification routed through us, the confirmation would carry no information.

Can a record be changed?

Not silently. Any edit breaks the fingerprint, and the break is detectable by anyone holding the certificate. When the evidence genuinely moves, SUPERSEDE issues a new record linked to the one it replaces — the superseded record stays readable and stays verifiable.

Do you see our data?

Sealing works on a fingerprint, not on the content. What is anchored is a digest. We also cannot see who verifies a record, because verification does not route through us.

Is the specification public?

The specification is. The conformance test vectors and the reference implementation are issued to implementers under agreement and are not published — that is a deliberate withholding, and it is stated on the register page too rather than left as a blank.

Bring the record with the judgment.