SMARTHAUSThe Mathematically Governed AI Fabric
Investors ↗ Twenty minutes

The evidence chain

From an effect, back to the person who wrote the sentence.

Two receipts, produced by two different products, that join. This is the capability we have found nowhere else, and the one an auditor, a risk officer or a regulator will care about most. An auditor starts at the effect and walks back. Every step is pinned.

Prepared bySMARTHAUS Engineering
DateSeptember 2026
SectionThe Evidence Chain
ProductSMARTHAUS
FROM AN EFFECT, BACK TO A PERSON RECEIPT OF TRUTHWRITTEN BY MAEintent · locked · hashedproof · invariantsscorecard · conformanceprovenancerule 7e21a4…c09a DECISION RECEIPTWRITTEN BY UCPrequest · payment.releaseamount = 40,000.00asked · answered · ranprev · 4f2a9c71e0b3rule set 7e21a4…c09a JOINED ON THE DIGEST OF THE RULE FIVE STEPS · RIGHT TO LEFT A PERSONVERIFIED THE PROOFVERIFIED THE RULETHAT FIREDVERIFIED WHAT WASDECIDEDVERIFIED AN EFFECTVERIFIED‹‹‹‹ every step is pinned

The walk

Five steps, right to left.

Open any step to see it happen.

The two receipts

Written by two different products. They join on the digest of the rule.

Decision receipt

Written by the control plane every time it decides. Carries the request and its exact arguments, the scope, digests of both, the rule set pinned by hash, who was asked, what they answered, how long it holds, whether it executed — and the hash of the receipt before it.

Receipt of Truth

Written by the engine when a rule is built. Carries the proof, the invariants, the scorecard, the conformance record, the provenance, and the locked intent the whole thing was derived from.

The join

The decision does not merely name a rule. It pins the exact rule set by digest at the moment it decided, so the rule you land on is provably the rule that fired.

The ledger is a chain, not a list

Each receipt carries the hash of the receipt before it. Remove or alter one entry and every entry after it breaks.

What an auditor actually does with it

The same evidence, whoever is asking.

Internal audit, second-line risk, the control owner, an external auditor, a supervisor, or the executive who has to sign the assurance statement. They are all asking one question in different words: show me.

01

Start at the effect

A branch was deleted, a payment left, a record changed.

02

Read the decision

What was requested, with which arguments, under which rule set, decided by whom, with what scope, and whether it executed.

03

Cross into the rule

The rule set is pinned by digest, so there is no question which version applied.

04

Open its proof

The calculus, the Lean proof manifest, the invariants, the scorecard, the oracle's conformance result.

05

Finish at a person

The locked natural-language intent, and who wrote it.

Why nobody has it

Both halves are missing from the market independently.

The proof does not travel

Across the formal-methods and verified-compiler industry, no product ships a proof into production with the artifact. The idea has existed since 1997 and was never commercialised. The attestation standards have no slot for it.

The record is not sealed

Not one product in the agent-security market signs or chains a decision record. The integrity technology exists — it is attached to build provenance and log files, never to the decision.

The closest things have one leg

AWS's Cedar has a prover and an independent executed check and gates releases on both — with no intent at the root and no per-release receipt. Cryptographic validation at NIST has a specification-derived oracle run by an independent lab — with no prover. The railway safety platforms compare two independently built binaries every cycle — and explicitly decline to emit a receipt.

And the honest limit at the far end: hashing the intent removes any argument about which intent was used. It does not make the intent correct. The most successful formal-methods programme in the world puts it plainly — a fully proven system is not a guarantee against failure, because the proof relates the implementation to the specification, not the specification to reality. One metro train once failed to stop at a platform because of a specification error.

Start at one seam

Read a real ledger, not a screenshot of one.

Twenty minutes: connect your own coding agent, ask it to do something that writes, deny it, verify in your own environment that nothing happened, then read the chain back to the rule and the rule back to the sentence.

Book the twenty minutes