Actuary

Certificates

A file you can check yourself.

When a monitor raises an alarm on a design we locked with you, it writes a certificate: the design, the data, the calculation and the result, signed and sealed into one file. You are not being asked to trust it. You are being invited to redo the sums yourself, on your own machine, and either get the same answer or find out exactly where it disagrees.

Verify one now Download certificate.json

Try it

Check a real one, in three commands.

What follows is the certificate from Study 001, the run we did on 24 July 2026 and the first entry in the public register. It is a real file, signed at the time. You can check it here in your browser, or build our command-line tool and check it there.

ACTUARY · REGISTERED STUDY 001 · PROSPECTIVE

Certificate of monitoring

actuary-certificate-v4 · the actual artifact,
rendered — recompute it
Run
real-validation-prospective-fixed-panel-2026-07-24
Subject
openai/gpt-4.1-nano · via OpenRouter
Design frozen
2026-07-24 · 5-item maths panel · floor 0.70 · α 0.05
Registered bound
alarm within 19 blocks of onset · pre-registered separately
Result
alarm at panel 12 · log e 3.3999562471954308
Period
2026-07-24 17:19:34 → 17:24:10 UTC
Payload hash
35aefb0e387dd7f1784c8499d4dff5f99d45d562b926a539a3b4ee7fc08a58c8
Signed
Ed25519 · key 079ff1a1fc426e9570f896537edf2fe5612768f5e5ff8e05b1cbd2b299ca1f25
Chain
previous payload hash null — genesis
Fields read from certificate.json · the bound was registered separately, before the run Signing-key fingerprint · one cell per hex digit

01

Download the two files

certificate.json (36 KB) is the signed certificate, and public-key.hex is the key it has to check out against.

02

Build the checker

The checker is actuary-cli, part of our Apache-2.0 licensed Rust core. The repository is private while we are in the design-partner stage, so the source goes out with every certificate we issue — and to anyone who asks for it: request access. If you would rather not install anything, check it here in your browser instead.

cargo build -p actuary-cli

03

Redo the sums

actuary verify certificate.json --pubkey public-key.hex

No database, no server, no network connection. If it passes, it means the whole calculation has been rebuilt from the file and came out the same — the very same calculation the demo on our front page runs in your browser.

What it proves

Three checks, none of which need us.

01

The file is byte for byte the one we signed

Certificates are written in a strict, one-and-only-one-way format (RFC 8785). Move a key, respace a number, change a single byte, and it stops matching the signature — which is the point.

02

The numbers add up again

Starting from the inputs the file carries, the checker rebuilds the whole thing: the test cases we fixed, each day’s score, and the evidence as it grew. All of it has to land on the result recorded in the file. We would not have issued the certificate if that replay had failed on our side either.

03

The signature is ours

The signature checks out against our published key. The secret half never leaves the machine that signs; the public half travels with the file, so you can confirm we wrote it and nobody has touched it since.

Contents

Everything needed to rebuild the result from scratch.

  • A fingerprint of the design we locked
  • Which question pool and which checker version were used
  • Every test case, in order, with the score it got
  • Each day’s average, and a fingerprint of the evidence at that point
  • How sure we were, and how strong the evidence was, at every step
  • Which check raised the alarm
  • Which version of the certificate format this is

We say certificate, and never certified. No accreditation body stands behind these files. The file stands behind itself, which is why you can check it without asking anyone’s permission.

The boundary

What a certificate does not do

It vouches for the sums, not for the assumptions.

A certificate says the calculation is right, given what the design assumed — and one of those assumptions is that your scores move independently of each other. It cannot prove that assumption from the data, and it does not pretend to.

When that assumption is wrong, the false-alarm promise goes with it. Rather than describe that in words, we measured it: feeding the detector scores that move in clumps of five, across 10,000 simulated runs, it cried wolf 56.38% of the time instead of the 5% we aim for.

Read the boundary

Get started

Certificates come from designs we lock together.

We agree the test cases, the minimum score and the false-alarm budget, have them reviewed, and fix them before the first result arrives. That review is what makes the published false-alarm rates apply to your monitor, and it is what the Registered plan pays for.

Apply for a design partnership Methodology