Secoya One · customer-owned decision evidence

Customer-owned evidence for consequential decisions.

Secoya creates portable, cryptographically sealed records from selected AI and automated decision workflows. Secoya One’s local Evidence Inspector lets reviewers inspect those records, verify their integrity and signatures, and download clear findings.

Your keys. Your records. Verification without Secoya.

A verifier with the published format, a compatible verifier, authentic trust material and the applicable policy can verify the record without access to Secoya or the originating system. The verifier must independently accept the trust anchor.

Secoya Systems Ltd · England & Wales · pre-revenue · developer preview

Secoya · From decision to evidence

See the decision become evidence.

How Secoya One Works

A four-step lifecycle for consequential operational decisions.

01 / Create

Create evidence in your environment

Generate portable, cryptographically signed records within customer-controlled workflows using the Trust Record Format. Source mapping and production integration require deployment-specific work.

02 / Retain

Retain records & verification material

Retain your records, public trust material and verification profiles needed for later verification. Authoritative records remain under customer control.

03 / Inspect

Inspect & verify locally

Run the Secoya One Evidence Inspector on a local machine to inspect protected context, evaluate signatures and identify missing evidence.

04 / Export

Export review-ready findings

Download verification JSON and a structured, printable HTML report. Use browser Save as PDF when a PDF is needed.

Secoya One Evidence Inspector · Local Preview

Local inspection and cryptographic verification

A local application for reviewers and auditors to examine existing Trust Records. The supplied application processes evidence locally and makes no outbound requests. Evidence remains on the local machine.

  • ImportImport Trust Records, optional detached payloads, verification profiles and public trust material.
  • InspectReview the payload and protected context present in each record.
  • VerifyVerify classical Ed25519 signatures or both Ed25519 and ML-DSA-65 under a hybrid-required policy on a supported runtime.
  • UnderstandView individual check outcomes, supplied trust assumptions and findings where evidence is missing or invalid.
  • DownloadExport verification JSON and a branded printable HTML report, with browser Save as PDF.
Actual Inspector acceptance of synthetic hybrid evidence — open full-size screenshot
Actual local preview · synthetic data · Ed25519 and ML-DSA-65 signatures accepted under the selected profile. Select to enlarge.
Actual Inspector rejection of an altered synthetic payload — open full-size screenshot
Actual local preview · synthetic data · altered payload rejected. Select to enlarge.

Local Preview Requirements

Requires Node.js 24.7 or later.

The Inspector verifies existing evidence. Record issuance and production integration are separate components.

Installation details, versions and test evidence

Security Boundaries & Design Principles

Customer-controlled keys

The architecture supports signing within your deployment boundary. Production KMS/HSM adapters require customer-specific implementation and validation. The Inspector uses public verification material.

Verification without a vendor service

A compatible implementation can verify using the published format, authentic public trust material and applicable policy. An active Secoya service is not required.

Clear evidence limits

Signatures establish integrity and signature validity under the selected trust basis. They do not prove that the business assertion was true or authorised, every event was captured, keys were never compromised or declared time was trustworthy.

Independent trust material

Public keys and authority metadata require an independently accepted trust basis. A report accompanies the evidence; it does not replace it. A predecessor reference alone does not establish an unbroken chain.

System Capabilities at a Glance

  • Available local previewEvidence import, payload inspection, classical and hybrid signature verification, JSON export and printable HTML reports.
  • Reference implementationLocal API/webhook-style ingestion reference code and operational test harnesses.
  • Deployment-specific / future workProduction KMS/HSM adapters, transactional replay infrastructure, independently trusted timestamps, historical-continuity integration in the Inspector, authenticated evidence-package export and multi-user administration.

Ready to evaluate customer-owned decision evidence?

Review the published protocol or contact Secoya to request the local Inspector for technical evaluation.