Document integrity, forensic and compliance platform
We tell you whether a document is genuine - before you pay a claim, approve a loan, grant a visa, settle an invoice or open an account on the strength of it.
How the file was produced. Whether it matches the template its issuer actually uses. Whether the image has been altered. Whether the entity exists in the register it names. Whether this exact document has already appeared on somebody else's file. intactly examines all of it, against the rules that apply, and returns findings cited to the page they came from.
One document, taken apart. Illustrative, on a synthetic file.
The document that clears every check you can run on it is the one that has already appeared on somebody else's file.
Verdicts are VERIFIED, REVIEW or ESCALATE. Every finding is anchored to two documents, and we make no automated adverse decisions in any sector - a person decides. 142 rules encoded across 24 jurisdictions so far, all of them insurance, every one shipping unverified until a named person has checked it against the primary instrument.
44 documents, 380 pages → every finding cited to its source, 6 inconsistencies, and one verdict a person acts on: REVIEW.
The payslip names a payroll provider. Its production chain is a general-purpose HTML-to-PDF converter, with none of that provider’s output signature.
This bank letter has been seen before - same template fingerprint, different account holder, on two other files in eleven days.
A declared beneficial owner resolves to an entity dissolved in its home register, with an effective date preceding the declaration.
To a human, with the cited brief. Every finding anchored to two documents, every benign explanation stated alongside it. Your team decides.
Sectors
Whether a PDF was produced by the software it claims, whether an image carries the artefacts of synthesis, whether a document matches the template its issuer actually uses, whether the entity exists in the register it names, whether this exact file has been seen before on somebody else's matter - none of those questions change when the industry changes. What changes is the rule set and the name of the thing being decided.
Pay or investigate. Invoices, damage photographs, medical certificates, statements. Everything is built here: the full obligation rule set, the benefit arithmetic, the product and the demonstration. This is the proof vertical and the first revenue.
Read the worked example →Approve or decline. Payslips, bank statements, financial statements, valuations. Fabricated payslips are a documented and rising problem. In Australia the consumer data right supplies a verified income feed that outranks an uploaded document, which is a rail that does not exist in most markets.
Read the worked example →Onboard or refuse. Release funds or hold. Proof of address, bank letters, source of funds and source of wealth declarations, corporate structure and beneficial ownership documents. The document burden is heavier here than in most of banking and the adversary is more sophisticated: onboarding packs are assembled to order, and the same synthetic bank letter appears across several platforms in the same week. Registry resolution and cross-file reuse are the two capabilities this sector needs most, and both are core rather than bolted on.
Read the worked example →Grant or refuse. Bank letters, qualifications, employment evidence, often across several jurisdictions and languages. The closest adjacency by rule structure: eligibility assessed against statutory criteria with a review and appeal path on every decision.
Read the worked example →Advance or hold. Invoices, bills of lading, receivables. Receivables financing rests entirely on documents nobody forensically examines, and the failures in this market are large and public.
Read the worked example →Pay the invoice, or change the bank details. Supplier invoices and payment-detail change requests. Fabricated invoices and business email compromise are the same attack seen from two directions.
Read the worked example →Admit or challenge the evidence. Contracts, correspondence, exhibits. Is this exhibit authentic, offered as a service to firms and to tribunals. Smallest by volume and the highest value per decision.
Read the worked example →Only insurance is built. The rest are specified, not shipped: no rule set outside insurance has been encoded and no non-insurance bundle has been examined in production. We are saying what the engine is for, not claiming six products we do not have. Insurance stays the selling focus until there are three paying carriers. If yours is on that list and you have the problem now, ask us what it would actually take - the answer is a number of weeks, and we will give you the real one.
The thesis
A system that reads a bank letter works anywhere. A system that knows the letter is evidence against a statutory test, that the clock it starts runs in business days under one jurisdiction's calendar, and that acting on it requires notice - that system only works where it was built. So we built the first half once and the second half per jurisdiction, and we keep the rules as data rather than as code, which is why a new sector costs analyst time rather than a rebuild.
Document lineage and fabrication detection. Image forensics. Template comparison. Sender authentication. Cross-document reconciliation. Entity resolution against live registers. Cross-file reuse. Provenance and replay.
Built once, every sector
What test the evidence has to meet. Timeframes and their units. Benefit formulas and indexed caps. Dispute and appeal pathways. Public holidays, of all things, which change the answer.
Encoded per jurisdiction and sector
No automated adverse decisions, in any sector. No assertion without two sources from two documents. Protected attributes firewalled from assessment. No opaque score anywhere in the product.
Everywhere, in code
The uncomfortable consequence is that entering a jurisdiction or a sector is not a configuration exercise. It is reading the instruments, encoding them as data with citations, and having a qualified person verify each one against the primary source. A model can draft a rule in seconds and cannot certify it. That is slow and it does not compress - but it is fundable, and we would rather say so than oversell it. An institution with enough patience can build that for itself. The thing it cannot build for itself is next.
The network
A fabricated bank letter is not obviously fabricated. It is well made, internally consistent, and it survives every check a careful assessor can run against the one copy in front of them. What exposes it is seeing it twice - same template fingerprint, different account holder, eleven days apart. And the second sighting is almost never on your file. It is on somebody else's.
The evidence that convicts a document sits outside the institution examining it. One carrier, one lender, one exchange sees its own intake and nothing else.
So the check runs across institutions. There is no version of it a single participant performs alone, however good its models are.
And no carrier sends its claim evidence to a competitor's in-house build. It will send a de-identified fingerprint to a neutral third party under contract. That asymmetry is not a head start we happen to have. It is a door that only opens for a vendor.
Shared claims-history exchanges have run on this logic in North America for decades, and no participating carrier has replaced one with something built internally - not because the software is hard, but because the rows belong to their competitors. This is the same structure applied to the document rather than the claim record, at a privacy standard those exchanges predate.
Vendor-only by construction. A participant cannot assemble this for itself at any budget, because every row it needs is held by a competitor.
The index is built and seeded. What reads zero is member contribution, and we left that counter in place rather than blend it into the figures above. A corpus we assembled ourselves is a head start, and a head start is fundable. Cross-institution sightings are not: they need firms that compete with each other in one index, which a participant cannot arrange and a neutral party can. The first member to join sets the floor that every member after it starts from.
Six jurisdictions read instrument by instrument, every rule carrying the paragraph it came from. An institution with the same patience can reach these numbers, and some will. That takes years, and we would rather say so than imply it cannot be done.
Ledger A is recomputed from the engine every time this site is built, and a test fails the build if a figure here disagrees with the code. No number on this page is typed by hand.
Your data never leaves your tenant. The network shares fraud fingerprints, not files.
The sentence we put in front of a member's privacy officer and in front of their regulator. Everything below is how it is made true, and where it still has to be proved.The tenant boundary, and the extraction step that is the legal firewall. Raw evidence becomes schema-level features before anything reaches the line: document fingerprints, template hashes, metadata anomaly signatures, entity-graph topology rather than entities. The document is still in the tenant when the match comes back.
Where a model is tuned on your raw data, the artefacts that tuning produces are owned by you and served only to you. Your claims file does not become a feature in the product your competitor buys.
invoice PDFs from producer X carrying post-dated XMP edits
source-of-funds statement template Y, reused across unrelated accounts
No name, no policy or claim number, no document content. Not withheld from members - not present.
Properly de-identified information is not personal information under the Privacy Act, and the disclosure restrictions largely fall away. Properly is doing all the work in that sentence. A feature set rich enough to be useful can be rich enough to re-identify, and that is how this class of design fails - not by anyone sending a document, but by sending enough derived detail to reconstruct one. So the methodology is assessed against the OAIC's de-identification framework rather than against our own confidence in it.
Matching runs as a private set intersection over hashed identifiers, so neither member sees the other's set, file or customer, and neither learns anything about the entries that did not match. The heavier alternative - training locally, shipping only weight deltas, adding differential-privacy noise - is federated learning, and it is not what runs today. Feature-level sharing with a centrally trained pattern model reaches most of the same place, and we would rather name which one is running than let the more impressive word sit on the page unearned.
Each member consents to contributing de-identified signals and to consuming network verdicts, in one instrument. We act as processor and service provider. We do not become a controller of your evidence by holding it.
Insurer claim forms already carry fraud-investigation and information-sharing consents. Membership requires you to warrant that your collection notices cover contribution to a fraud-detection service. We ask for that warranty rather than assuming it, because the assumption is what fails at the inquiry.
Fraud-signal sharing between competitors is not price or output information and is generally permissible. It is structured so members cannot see each other's commercial data at all, and it goes to counsel for a written memo rather than resting on this paragraph.
Already true everywhere in the platform, and it does not change because a match came from the network. A match is a finding with benign explanations named beside it, routed to a person. It also keeps members clear of the automated-decision-making provisions arriving in the Privacy Act.
No network match goes live before an Australian privacy lawyer has reviewed the membership agreement and the de-identification methodology. There are no members today, so this costs us nothing to say - which is precisely why it is worth writing down now, while it is still cheap, rather than after the first member has signed and the pressure runs the other way.
| Capability | Built internally | On a neutral network |
|---|---|---|
| Forensics on the document in front of you | Reachable. It is engineering. | Same examination, day one. |
| Your own jurisdiction's obligation rules | Reachable. Years of analyst reading. | 142 encoded, every one cited. |
| The same artefact seen twice on your own files | Reachable, within your own intake. | Included. |
| The same artefact seen on a competitor's file | Not reachable at any budget. The evidence is owned by the firms you compete with, and they will not send it to you. | The reason the network exists. |
| Getting stronger because a rival joined | Never happens. An internal build is as strong on its last day as its own volume allows. | Every member added improves the answer every other member gets. |
The honest version of the pitch: everything above the line is a build-or-buy question about cost and time, and a large enough institution can reasonably decide to build it. The two rows below the line are not a build-or-buy question. They are a question about who is allowed to hold the index, and a participant in the market is not.
The first member
There are no members today and the counter above says so rather than rounding it up. What a first member gets is the seeded index, the encoded rule set, and a say in what the contribution schema looks like while it can still be changed. What it gives up is the option of waiting to see who goes first. That is a real cost and it is the only one, so we would rather name it than let you find it later.
Platform
Each answers one question well. The facts that decide whether a matter ends well sit between them, which is where a single-purpose tool cannot look. The first four are sector-neutral and run on any document bundle; the rest take the rule set of the sector they are pointed at.
An example of the last one: you are about to stop weekly payments on a claim that has been underpaid for ninety-seven weeks. The obligation engine does not know about the underpayment. The entitlement engine does not know about the cessation. Nobody in the process sees both.
Jurisdictions
These are insurance rule sets. The forensic core runs anywhere; what is listed here is where the local obligations have been read and encoded. "Live" means the obligations are encoded with citations and, where the market has statutory benefits, the arithmetic is modelled and tested. "Encoded" means the rules are in and the market is missing something named - a benefit scheme, most states, a revised code. Every market publishes its own gaps rather than leaving you to discover them.
71 rules, 8 jurisdictions, 4 benefit schemes. General Insurance Code, Life Code, RG 271, APRA CPS 230 and 234, Privacy Act APP 1 and 11, state workers compensation and CTP schemes with their weekly benefit arithmetic.
See the Australian product →14 rules, 4 regions, 1 benefit scheme. Fair Insurance Code, the CoFI conduct regime, and accident compensation - including the flat 80 per cent weekly compensation with no step-down, which is the structural opposite of every Australian scheme.
14 rules, 3 nations. The DISP complaints timetable, ICOBS claims handling, the Insurance Act late-payment remedy. No statutory benefit scheme to model - UK income protection is contractual. Where ICOBS says "promptly" rather than a number, our own interval is used and labelled as ours.
12 rules, 4 provinces, 1 benefit scheme. Ontario's Statutory Accident Benefits Schedule in depth, including the income replacement benefit and the weekly cap fixed in the regulation and never indexed. Quebec complaints and the AMF transfer right.
13 rules. Consumer Protection Code timeframes, the Consumer Insurance Contracts Act duty to give a specific reason, and the EU AI Act obligations carried as horizon rules. The strictest transparency regime modelled here, and the one this architecture was designed for.
18 rules, 3 states of fifty. The NAIC baseline plus California, New York and Texas, whose day counts genuinely differ, and the federal ERISA timetable that overrides state law for group disability and health. A fifty-state book needs the other forty-seven before this is fit for use, and the platform says so rather than implying national coverage.
If your jurisdiction or your sector is not listed and you have the problem this solves, that is worth a conversation - the order we build in should be set by who actually needs it. [email protected]
What we will not do
No accuracy, detection-rate or time-saved figure appears anywhere on this site, because no pilot has produced one under a methodology we would publish beside it. When one has, the number and the method arrive together.
All 142 obligation rules across six jurisdictions, and every indexed rate, carry
verified: false until a named person has checked them against the primary
instrument. The count appears in every verdict and every report rather than in a footnote.
A matter in a jurisdiction or sector whose rules are not encoded refuses to evaluate rather than returning zero breaches. Zero applicable rules and zero breaches look identical in a report, and anyone reading the second would reasonably conclude they were compliant.
There is no risk score, no ranking of applicants or claimants, and no composite figure spanning compliance and evidence. The only number attached to a person is how many independent documents corroborate a fact about them. A score predicts. A verdict proves.
Closed claims, funded loans, granted applications, paid invoices, onboarded accounts. Matters where you already know how they ended. We examine them against those outcomes and show you the documents that lied.
For an insurer that runs as six weeks on one portfolio against a matched control, on four numbers agreed before we start: days to decision, projected breaches per thousand claims, rework rate at internal dispute resolution, and referral rate to the external complaints scheme. Agreed beforehand, so neither of us gets to pick the flattering measure afterwards. We publish the method with the result, and we publish nothing before there is one.
You are not committing to a deployment, a data migration or a procurement process to do this. You are giving us files whose answers you already know, which is the only honest way to find out whether any of the above is true.