Explained
Censio, explained
What it is, what you get, how it works, and what changes when it is in the room — in plain language, with one worked case.
In one paragraph
Censio is the layer between a machine judgment and the decision made on it. Machines now make judgments that matter: whether a payment clears, whether a claim is paid, whether a name is a match, whether a vehicle proceeds. For every judgment it produces a record that states what was concluded, on what evidence, by which method and with what confidence. The record is sealed, so any later change to it shows, and anchored so that anyone can verify it later without asking us. TIP also specifies an inline gate, which can hold or redirect an action whose evidence falls below a threshold you set.
What you get
- The Trust Object™
- The record of one machine judgment: claim, confidence, method, evidence, seal
- The CensioCert™
- That record in the form something else can hold — a document, a payload, a certificate
- The policy gate
- Specified in TIP: inline, it allows, flags, holds or redirects an action against your rules. The register states its status
- Public verify
- Anyone recomputes a seal against the anchors. It never routes through us
- The register
- What is shipped, what is in build, and what is only specified — stated, not implied
One API and one MCP. The record an auditor opens and the payload an agent parses are the same thing.
How it works, in order
- 01 · A judgment arrives
- Your model or your team concludes something. Censio receives the conclusion and the evidence it rested on
- 02 · The evidence is resolved
- Each source is recorded with its provenance and custody, under EPCP. A contested source is carried as contested, not dropped
- 03 · Confidence is measured
- A named, versioned method — TWDP, CDRP — produces one calibrated number. Not a vibe: a method you can read
- 04 · The record is sealed and anchored
- A digest of the whole record commits to a qualified timestamp and, where live, a public chain. Neither is operated by us
- 05 · Anyone can check it
- The verification walk is published. A regulator, a counterparty or a court recomputes the seal without contacting Censio
It does not decide. It can stop.
Censio never originates a decision; your model or your people do. But it is not only a witness. TIP specifies an inline gate. Deployed, it sits in the operational path and measures each judgment against the rules you have set. Then it acts: allow, flag, hold or redirect. A judgment whose evidence is thinner than your threshold does not proceed until someone with authority says it does.
In a machine-to-machine setting, that is the difference between a decision that was merely logged and one that was governed. Autonomous agents transacting with one another, fleet systems, a drone acting on a perception model: the same rule holds. On your rules, at your discretion, and recorded either way.
Auditability, not logging
A log says that something happened. A Censio record says what was concluded, from what, by what method, at what confidence, at what moment. It says so in a form anyone can prove has not been altered since. The difference is the difference between an incident report and evidence.
When the evidence genuinely moves, the record is superseded rather than edited: a new record links to the one it replaces, and the old one stays readable and stays verifiable. History here is append-only, including our own.
A worked case: sanctions screening at a payments desk
The desk, the figures and the ids below are a specimen; the mechanics are the protocol’s. A payments desk screens every outbound transfer against sanctions lists. A model flags a beneficiary name as a possible match to a listed individual. The match is not exact — a transliteration, a middle name absent — and the model puts its confidence at 0.71.
Without Censio: the model’s output goes to a queue, an analyst clears or blocks it, the outcome is logged. Fourteen months later a regulator asks why that payment cleared. The desk produces a log line, a screenshot of the list version if someone kept one, and an analyst’s recollection.
With Censio inline: the policy for this desk requires 0.90 for an automatic clear. At 0.71 the payment is HELD and routed to review; the hold itself is sealed. The analyst resolves it. The resolution is a second record superseding the first, carrying the list version in force, the aliases considered, the evidence that resolved the near-match, the method version and the exact moment. Both records commit to that day’s epoch anchor.
Fourteen months later the regulator asks the same question. The desk produces a CensioCert. The regulator recomputes its seal against the anchor, on their own machine, and reads what the desk concluded then, on what, by what method, and that nothing has changed since. The desk did not have to be trusted. It had to be checked, and it could be.
That case, as the record sees it
- 11:04:22Z
- Judgment received · name match · confidence 0.71 · method TWDP v2.1
- 11:04:22Z
- Policy sanctions-eu-v4 requires 0.90 · HOLD · routed to review · sealed
- 11:31:08Z
- Analyst resolution · not the listed individual · evidence: 3 sources · SUPERSEDES prior
- epoch 41,208
- Both records anchored · qualified timestamp
- +14 months
- Regulator verifies both records against the anchor · seals intact · no contact with Censio
What Censio is not
It is not a model, and it does not compete with yours. It is not a dashboard, though there are surfaces. It is not a decision-maker, though inline it can stop one. It is the layer that makes a machine judgment measurable, explainable and independently verifiable — and, when you ask it to, enforceable against your own rules.