Certificates
A file you can check yourself.
When a monitor raises an alarm on a design we locked with you, it writes a certificate: the design, the data, the calculation and the result, signed and sealed into one file. You are not being asked to trust it. You are being invited to redo the sums yourself, on your own machine, and either get the same answer or find out exactly where it disagrees.
Try it
Check a real one, in three commands.
What follows is the certificate from Study 001, the run we did on 24 July 2026 and the first entry in the public register. It is a real file, signed at the time. You can check it here in your browser, or build our command-line tool and check it there.
Certificate of monitoring
actuary-certificate-v4 · the actual artifact,rendered — recompute it
- Run
- real-validation-prospective-fixed-panel-2026-07-24
- Subject
- openai/gpt-4.1-nano · via OpenRouter
- Design frozen
- 2026-07-24 · 5-item maths panel · floor 0.70 · α 0.05
- Registered bound
- alarm within 19 blocks of onset · pre-registered separately
- Result
- alarm at panel 12 · log e 3.3999562471954308
- Period
- 2026-07-24 17:19:34 → 17:24:10 UTC
- Payload hash
- 35aefb0e387dd7f1784c8499d4dff5f99d45d562b926a539a3b4ee7fc08a58c8
- Signed
- Ed25519 · key 079ff1a1fc426e9570f896537edf2fe5612768f5e5ff8e05b1cbd2b299ca1f25
- Chain
- previous payload hash null — genesis
01
Download the two files
certificate.json (36 KB) is the signed certificate, and public-key.hex is the key it has to check out against.
02
Build the checker
The checker is actuary-cli, part of our Apache-2.0 licensed Rust
core. The repository is private while we are in the design-partner stage, so
the source goes out with every certificate we issue — and to anyone who asks
for it: request access. If you would rather not install
anything, check it here in your browser instead.
cargo build -p actuary-cli
03
Redo the sums
actuary verify certificate.json --pubkey public-key.hex
No database, no server, no network connection. If it passes, it means the whole calculation has been rebuilt from the file and came out the same — the very same calculation the demo on our front page runs in your browser.
What it proves
Three checks, none of which need us.
01
The file is byte for byte the one we signed
Certificates are written in a strict, one-and-only-one-way format (RFC 8785). Move a key, respace a number, change a single byte, and it stops matching the signature — which is the point.
02
The numbers add up again
Starting from the inputs the file carries, the checker rebuilds the whole thing: the test cases we fixed, each day’s score, and the evidence as it grew. All of it has to land on the result recorded in the file. We would not have issued the certificate if that replay had failed on our side either.
03
The signature is ours
The signature checks out against our published key. The secret half never leaves the machine that signs; the public half travels with the file, so you can confirm we wrote it and nobody has touched it since.
Contents
Everything needed to rebuild the result from scratch.
- A fingerprint of the design we locked
- Which question pool and which checker version were used
- Every test case, in order, with the score it got
- Each day’s average, and a fingerprint of the evidence at that point
- How sure we were, and how strong the evidence was, at every step
- Which check raised the alarm
- Which version of the certificate format this is
We say certificate, and never certified. No accreditation body stands behind these files. The file stands behind itself, which is why you can check it without asking anyone’s permission.
The boundary
What a certificate does not do
It vouches for the sums, not for the assumptions.
A certificate says the calculation is right, given what the design assumed — and one of those assumptions is that your scores move independently of each other. It cannot prove that assumption from the data, and it does not pretend to.
When that assumption is wrong, the false-alarm promise goes with it. Rather than describe that in words, we measured it: feeding the detector scores that move in clumps of five, across 10,000 simulated runs, it cried wolf 56.38% of the time instead of the 5% we aim for.
Get started
Certificates come from designs we lock together.
We agree the test cases, the minimum score and the false-alarm budget, have them reviewed, and fix them before the first result arrives. That review is what makes the published false-alarm rates apply to your monitor, and it is what the Registered plan pays for.