Secoya One · founding design-partner pilot · one slot

Test one consequential workflow, end to end.

A fixed, paid engagement to connect Secoya One to one real decision boundary and determine whether its evidence can be issued using customer-controlled signing keys, retained against replay and omission, independently checked later—and made operationally useful to the customer.

Fixed fee£30,000 + VAT

Founding-pilot delivery and written evidence report. External review and third-party service charges are excluded.

Delivery period10 weeks

The clock starts after the readiness conditions below are met.

CapacityOne founding slot

One named workflow and one consequential decision boundary.

Two questions

Technical success and customer value are tested separately.

The cryptographic and conformance work demonstrates the protocol. The pilot determines whether it operates effectively inside the customer’s actual control path and improves the organisation’s evidence position compared with existing controls.

Can it operate here?

Test customer-controlled signing, identity and authority mapping, storage, policy, external time, replay state, monitoring and the agreed approval or deployment boundary.

Is the result valuable here?

Test whether the preserved evidence materially improves historical reconstruction, incident investigation, assurance, challenge response and continuity through infrastructure change.

Commercial boundary

Passing the five technical gates does not automatically prove customer demand or commercial value. Those outcomes require evidence from the customer’s workflow and stakeholders.

Acceptance model

Five gates. Pass or fail.

The pilot succeeds only when every gate is evidenced and deliberately invalid cases are rejected.

  • 01 / key controlA record is signed with customer-controlled key material that Secoya cannot use.
  • 02 / replayA replay attempt is rejected against persisted state, including after a service restart.
  • 03 / timeThe record carries time evidence from a source controlled by neither Secoya nor the originating application.
  • 04 / witnessed historyAn independently controlled monitor retains checkpoints and detects a deliberately seeded rewrite or rollback.
  • 05 / completenessN decisions in the source workflow produce N records, and a deliberately suppressed record is detected by reconciliation.
Overarching pass rule

Every seeded tamper, replay, rollback and omission condition must be detected. No deliberately invalid record may be accepted.

Readiness conditions

Ten weeks begins when the dependencies are real.

Required before week one

A named workflow and decision boundary; an accountable customer sponsor and technical owner; an available test environment; representative data; security and access approvals; and named choices for customer-controlled signing, independent time and checkpoint monitoring.

Dependency long-stop

If a customer-controlled prerequisite is unavailable, the affected delivery clock pauses. If it remains unavailable for twenty business days, both parties document a revised schedule or scope rather than pretending the gate was tested.

What the customer receives

A working boundary and an evidence-backed result.

Bounded integration

Connection to one authorised event source through the agreed sidecar, webhook/message route or embedded-library pattern, with schema mapping, attestation, retention and verification around that workflow.

Gate evidence

Repeatable acceptance tests, captured results and the material needed to reproduce the verification decision.

Pilot evidence report

A written account of what passed, what failed, operational value observed, residual risks, dependencies and the status of any external review.

Scope boundary

The pilot is not an independent cryptographic audit, FIPS certification, legal opinion or general production-platform rollout. External review, cloud services, timestamping, monitoring and other third-party charges are separately agreed where required.

Production terms

Production licence terms are available following successful pilot completion and qualification. The pilot fee does not imply an automatic production commitment by either party.

Integration boundary

Secoya One sits around your existing systems rather than replacing the decision platform. The pilot selects the embedded, service or event-driven boundary appropriate to the workflow, then connects the required adapters. Access, mapping, key and trust configuration, storage, controls and approvals remain part of the engagement.

First conversation

Bring one decision worth defending.

We will test whether its evidence boundary is specific enough for the five gates and say plainly if it is not ready.

Scope the workflow