Explained

Censio, explained

What it is, what you get, how it works, and what changes when it is in the room — in plain language, with one worked case.

In one paragraph

Censio is the layer between a machine judgment and the decision made on it. Machines now make judgments that matter: whether a payment clears, whether a claim is paid, whether a name is a match, whether a vehicle proceeds. For every judgment it produces a record that states what was concluded, on what evidence, by which method and with what confidence. The record is sealed, so any later change to it shows, and anchored so that anyone can verify it later without asking us. TIP also specifies an inline gate, which can hold or redirect an action whose evidence falls below a threshold you set.

What you get

The Trust Object™
The record of one machine judgment: claim, confidence, method, evidence, seal
The CensioCert™
That record in the form something else can hold — a document, a payload, a certificate
The policy gate
Specified in TIP: inline, it allows, flags, holds or redirects an action against your rules. The register states its status
Public verify
Anyone recomputes a seal against the anchors. It never routes through us
The register
What is shipped, what is in build, and what is only specified — stated, not implied

One API and one MCP. The record an auditor opens and the payload an agent parses are the same thing.

How it works, in order

01 · A judgment arrives
Your model or your team concludes something. Censio receives the conclusion and the evidence it rested on
02 · The evidence is resolved
Each source is recorded with its provenance and custody, under EPCP. A contested source is carried as contested, not dropped
03 · Confidence is measured
A named, versioned method — TWDP, CDRP — produces one calibrated number. Not a vibe: a method you can read
04 · The record is sealed and anchored
A digest of the whole record commits to a qualified timestamp and, where live, a public chain. Neither is operated by us
05 · Anyone can check it
The verification walk is published. A regulator, a counterparty or a court recomputes the seal without contacting Censio

It does not decide. It can stop.

Censio never originates a decision; your model or your people do. But it is not only a witness. TIP specifies an inline gate. Deployed, it sits in the operational path and measures each judgment against the rules you have set. Then it acts: allow, flag, hold or redirect. A judgment whose evidence is thinner than your threshold does not proceed until someone with authority says it does.

In a machine-to-machine setting, that is the difference between a decision that was merely logged and one that was governed. Autonomous agents transacting with one another, fleet systems, a drone acting on a perception model: the same rule holds. On your rules, at your discretion, and recorded either way.

Auditability, not logging

A log says that something happened. A Censio record says what was concluded, from what, by what method, at what confidence, at what moment. It says so in a form anyone can prove has not been altered since. The difference is the difference between an incident report and evidence.

When the evidence genuinely moves, the record is superseded rather than edited: a new record links to the one it replaces, and the old one stays readable and stays verifiable. History here is append-only, including our own.

A worked case: sanctions screening at a payments desk

The desk, the figures and the ids below are a specimen; the mechanics are the protocol’s. A payments desk screens every outbound transfer against sanctions lists. A model flags a beneficiary name as a possible match to a listed individual. The match is not exact — a transliteration, a middle name absent — and the model puts its confidence at 0.71.

Without Censio: the model’s output goes to a queue, an analyst clears or blocks it, the outcome is logged. Fourteen months later a regulator asks why that payment cleared. The desk produces a log line, a screenshot of the list version if someone kept one, and an analyst’s recollection.

With Censio inline: the policy for this desk requires 0.90 for an automatic clear. At 0.71 the payment is HELD and routed to review; the hold itself is sealed. The analyst resolves it. The resolution is a second record superseding the first, carrying the list version in force, the aliases considered, the evidence that resolved the near-match, the method version and the exact moment. Both records commit to that day’s epoch anchor.

Fourteen months later the regulator asks the same question. The desk produces a CensioCert. The regulator recomputes its seal against the anchor, on their own machine, and reads what the desk concluded then, on what, by what method, and that nothing has changed since. The desk did not have to be trusted. It had to be checked, and it could be.

That case, as the record sees it

11:04:22Z
Judgment received · name match · confidence 0.71 · method TWDP v2.1
11:04:22Z
Policy sanctions-eu-v4 requires 0.90 · HOLD · routed to review · sealed
11:31:08Z
Analyst resolution · not the listed individual · evidence: 3 sources · SUPERSEDES prior
epoch 41,208
Both records anchored · qualified timestamp
+14 months
Regulator verifies both records against the anchor · seals intact · no contact with Censio

What Censio is not

It is not a model, and it does not compete with yours. It is not a dashboard, though there are surfaces. It is not a decision-maker, though inline it can stop one. It is the layer that makes a machine judgment measurable, explainable and independently verifiable — and, when you ask it to, enforceable against your own rules.

Bring the record with the judgment.