Sigillum
Dynamic Sites Engine

A claim is published only if it can be traced to proof.

Most systems publish first and check afterwards, if ever. This one refuses to emit a claim it cannot trace to an authoritative source, and holds everything until a named person has signed it off. What cannot be substantiated is dropped, not softened.

Gate record Export permitted
Claims submitted
23
Traced to source
15
Dropped
8 — no source of truth for the assertion
Attested by
Named reviewer, on the record, with date and notes
Audit entry
Written before export, queryable afterwards

Illustrative shape of a gate decision. The count that matters is the third one: a dropped claim is the engine working, not failing.

The engine

Five moves, in order. Nothing skips ahead.

01 — Claim

Every assertion is named

Anything entering the record is treated as a claim to be answered for, rather than as copy to be polished.

02 — Source

Traced to an authority

Each claim must link to the source of truth it is audited against — a datasheet, a published standard, an issued certificate, a dataset.

03 — Attestation

A person signs it off

A named human attests, with date and notes, and the sign-off blocks release until it exists. Not optional metadata skipped under deadline.

04 — Emission

Fail-closed, never fabricated

Unsubstantiated or unattested claims are dropped with the reason recorded. The engine's failure mode is saying less, never inventing.

05 — Audit

A record that outlives the decision

Who vouched for what, on what evidence, and when — permanent and queryable, because the question is always asked later.

Why this rather than checking afterwards

Detection is a race you lose. Gating is structural.

The problem has changed

Producing a plausible false claim now costs almost nothing. Every defence built on catching them afterwards — moderation, fact-checking, litigation — is linear human work set against effectively free fabrication.

So the gate moves

Substantiation stops being a review step bolted on at the end and becomes the precondition for anything appearing at all. A classifier degrades as fakes improve. A source requirement does not.

Applications and use cases

Anything with an authoritative source can be gated.

An application is the engine plus an adapter that supplies its domain's source of truth — documents, sensor readings, AI output, human attestations, API responses. The catalogue is open by design: anything authoritative and addressable can occupy the source slot, so this is where the engine applies today and where it goes next, not a closed list.

ApplicationAudited againstStatus

Product pages and catalogues

Vendor datasheets, spec files, claim restrictions

Live — as Vellum

Quality-system conformance

ISO 9001, ISO 13485, IEC 60601, ISO 14971 clauses

Adapter proven — as Muniment

AI output gating

A grounding or retrieval corpus

Adapter needed

Incentivised review mitigation

Verified-purchase and transaction records

Adapter needed

Marketplace feed ingestion

Authenticated vendor feeds and source documents

Adapter needed

Research and scientific integrity

Underlying datasets and methods records

Adapter needed

ESG and regulated disclosure

Auditable evidence behind each disclosed claim

Adapter needed

Supply-chain chain of custody

Handoff and custody evidence at each step

Adapter needed

Credential verification

Issuing-authority records

Adapter needed

Provenance-ranked discovery

Curated issuers and their registers

In design — Assay

Insurance and warranty claims

Policy terms plus adjuster attestation

Adapter needed

Adapter needed means the engine is built and the domain's source adapter is not. We say which is which rather than listing all ten as capabilities.

Our products

Applications we run as products.

Vellum — document provenance

Live

Seals engineering and quality records into a bundle, signs that bundle with your organisation's key, and lets anyone who receives it check both — without access to your systems or ours. Vellum runs as a hosted service and as a desktop application for Windows.

Source of truth — the manufacturer's own controlled documents

How Vellum works · Open Vellum · Download for Windows

Muniment — quality-system conformance

Adapter proven · product in build

Certificates and declarations of conformity as hash-verified objects in an evidence register, with conformity stated along two axes and honest terminal states. Where a regime provides no external assessment, it says so with the reason attached rather than implying something is missing. It organises and verifies evidence; it does not confer conformity.

Source of truth — published standards and issued certificates

Assay — provenance-ranked discovery

In design

Turns a category search into ranked product options, each carrying the strongest vouching that could be confirmed. Options traced to a verified source are hallmarked; options that cannot be traced are marked unverified and demoted — which means not verified by us, never a claim that they are not genuine.

Source of truth — curated issuers and their registers

Honest boundaries

For a provenance product, overclaiming is self-refuting.

  • The engine is proven; each application needs its adapter. The gate is built, hardened and regression-locked. Every application is that same gate with a domain adapter, and those are built one at a time. The accurate claim is a proven engine, an adapter per vertical — not that it already does all of this.
  • It raises the cost of fabrication; it does not eliminate it. A verified source that lies is still a lie, and no engine adjudicates subjective taste.
  • Integrity is not authenticity. A digest proves a document is unchanged since it was registered. Whether the issuer should be believed is a separate question, answered separately.
  • It establishes trust in evidence; it does not decide for you. Weighing conflicting evidence, reasoning under uncertainty and recommending a course of action are a different discipline, and deliberately not this one. The engine hands over trustworthy inputs and stops there.
  • The verifier is itself verified. 1,466 tests across 157 files, strict typing, and a pre-commit gate that blocks a commit rather than warning about it. A system vouching for others' credibility should be demonstrably correct, not merely assert that it is.
Working with us

Pilots first, on one bounded scope.

We prove the engine on a real piece of your work before anything wider is discussed. If you publish claims you would have to defend — to an auditor, a regulator, or a customer who asks — that is the conversation to have.

Usually that is a product information, quality, compliance or regulatory-affairs team; a supply-chain function; an AI governance group; or a publisher answerable for what appears under its name.