Prove one consequential workflow end-to-end.
A bounded engagement that connects Secoya to one real decision, exercises the failure paths and produces an assurance report stating exactly what the deployment established—and what it did not.
Indicative founding offer · subject to agreed scope, readiness review and signed statement of work
Five outcomes—not ten weeks of access.
The parties agree the precise workflow and evidence boundary in the statement of work. Each gate then produces a binary result supported by retained test evidence.
- 01
Customer-controlled signing
In-scope records are signed using a customer-controlled KMS or HSM key that Secoya cannot independently use.
- 02
Durable replay rejection
Duplicate submission is rejected using persisted state, including after restart and the agreed recovery exercise.
- 03
Independent time evidence
Each selected record receives verifiable time evidence from the external source named before commencement.
- 04
Observable history
A separately controlled monitor retains signed tree heads and detects the agreed seeded rollback, deletion or inconsistent-history scenario.
- 05
Workflow completeness
Every in-scope source decision reconciles to exactly one retained record, and a deliberately suppressed event raises the expected control failure.
The pilot passes only when every agreed seeded integrity and control failure is detected and no deliberately invalid record is accepted.
Readiness comes before delivery time.
The delivery period begins when the named dependencies are available—not merely when the contract is signed.
Conditions before commencement
- Trusted-time provider selected and accessible.
- Monitor host and controlling team named.
- Customer KMS/HSM access and test credentials available.
- Source workflow and decision boundary documented.
- Security, test and data-handling approvals complete.
What separately controlled means
The monitor is administered separately from the source-system owner, with credentials and retained state that neither the source operators nor Secoya can alter.
The report distinguishes operational separation inside the customer from an externally independent organisation. It never describes one as the other.
Test the failure paths without creating uncontrolled risk.
The parties agree the failure categories, test boundary and emergency stop conditions. A named customer test authority selects the affected records and timing; delivery operators are not told the specific instances.
The report records whether each exercise was blind, partially blind or announced so the strength of the resulting evidence is not overstated.
A bounded assurance report
- Architecture and control boundary actually tested.
- Evidence retained for every acceptance gate.
- Detected failures, exceptions and remediation status.
- Operational-independence classification.
- Residual risks and unestablished claims.
- Recommendation for production acceptance or further work.
What the founding fee does not include.
Separately agreed costs
- Independent cryptographic or penetration audit.
- Cloud, KMS/HSM, timestamping and third-party monitoring charges.
- Production licences or work beyond the selected workflow.
- Customer remediation outside Secoya’s integration boundary.
Mandatory audit-status statement
Unless commissioned separately, the final report states that no independent cryptographic audit was performed within the pilot.
Pilot results demonstrate the tested implementation and deployment behaviour. They do not constitute FIPS validation, legal advice or a determination of regulatory compliance.
Bring one decision worth defending.
Start with the workflow, the accountable sponsor and the reason the decision may need to be proved later. The first conversation is a fit and readiness assessment—not a hidden implementation commitment.
