Skip to content

Stand behind a case you can prove

Evidence anyone can verify, an attributable record of every decision, and the independence rule enforced in the structure itself

Evidence your board can verify itself

A baseline and its hash travel to whoever must trust it, a board, an investor, a partner or the authority, and each confirms it authentic and unaltered without an account

Built for high altitude rigour

The things an auditor asks about first are not bolted on, they are how the model is built

Independence

A checker may approve but never author, the independence rule is process rigour built into the model, not a policy you hope people follow

Attribution

Every decision is an attributable record, who, when and against which version, so the review trail is complete by construction

Sealed evidence

Each baseline carries a tamper-evident hash anyone can verify, signed and timestamped, and it travels with the evidence

Access control

Two orthogonal axes, whether you can reach a resource at all, and what certification actions your role permits, kept separate so the model never becomes a permissions swamp

Your data, in your jurisdiction

Single tenant, hosted in the region you choose, encrypted in transit and at rest, backed up daily with point in time recovery, every change on a tamper evident trail

AI optional, off by default

Every load bearing engine is deterministic and runs in full with AI off. The optional assist runs on your own key against your own endpoint, and nowhere else

Paste a hash, confirm the case

A reviewer, authority or customer confirms a baseline is authentic and unaltered in seconds

01

Freeze a baseline

Capture the safety case at a point in time, a tamper-evident hash is computed across the whole snapshot

02

Share with anyone

Send the baseline and its hash to whoever needs it, no account and no install required

03

Verify in seconds

They paste the hash into the public page and it confirms the evidence is authentic and unaltered

Watch a seal break

Two entries hold, one artefact was edited after signing, and the ledger says so plainly, that honesty is the product

CERTPROVE / AV-01 / EVIDENCE LEDGER
Find anything⌘K
SMD
LIVE
Model
Overview
Requirements
Architecture
Prove
Trace
Lattice
Gaps
Safety
FHA
FTA
Margins
Deliver
Test
Docs
Evidence
Work
Engineering lead

Evidence ledger

LedgerSignaturesHash chain
EntryActionArtifactActorSHA-256Seal
LOG-8821Review sign offSYS-RQ-006 verificationSarah (reviewer)e3b0c44298fc1c14VALID
LOG-8822Parameter updateInverter load profileMike (avionics)8f434346648f6b96VALID
LOG-8823Test uploadThermal runaway TC-04JD (test)a591a6d40bf42040BROKEN

Every sign off is bound to the artifact hash at the moment of signing. LOG-8823 shows a sealed artifact edited afterwards: the seal breaks visibly and stays broken.

REV CBASIS SC-VTOL214 NODES · 337 EDGES SYNCED

What does the authority see?

Certification engineers are rightly conservative, so the answer is worth stating exactly

AUTHOR

The engineer stays the author

Every entry, analysis and sign-off is authored and owned by a named engineer, the platform structures the work, it never becomes the applicant

CITE

The rule is quoted, in place

The applicable clause sits beside the work it governs, and when an entry runs against it the platform warns, with the text of the rule, not a vague flag

SIGN

Nothing is signed by software

Approvals carry a human name, a time and a version, what the authority receives is engineering judgement with its evidence attached, easier to examine, not harder

A case you can hand to the authority

Access is granted on request while the platform is in early release