The platform

The trust layer for claim evidence.

CapSeal decides whether a piece of claim evidence can be trusted - at the moment it's captured, not weeks later under a forensic microscope. Five proprietary components, purpose-built for claim evidence, turn a raw photo into an auditable payment decision - and every one of them produces output you can verify independently.

Architecture

Five components. One decision.

Sealing alone does not stop fraud. CapSeal is a proprietary system engineered end to end - five layers of technology we developed and control, from the anti-spoofing capture engine to the cross-carrier network. Copying any one layer does not reproduce the system.

1

Capture integrity

The core IP. We prove a real lens saw a real scene - defeating screen-of-screen replays, injected virtual-camera feeds, and rooted or hooked devices. Our proprietary capture-integrity engine guarantees what the camera hands over is real - adversarial, insurance-specific, and continuously hardened against attacks that have not been published yet.

CORE IP
2

The verdict engine

Turns a raw seal and its integrity signals into an insurance decision - tuned per line of business, with graceful handling of no-secure-chip phones, offline capture, and legacy uploads, so honest claims are never blocked by a technicality. Deterministic and auditable, never a black box.

3

The verification network

A sealed capture, verifiable across insurers, repairers and reinsurers - so one loss can't be monetised twice. Privacy-preserving by design: salted entity hashes and private set intersection let a carrier learn "this evidence was already sealed elsewhere" without either side exposing customer data.

DURABLE MOAT
4

Proof-carrying decisions

Every verdict ships as a signed, replayable proof object - a chain from raw inputs through each check to the conclusion. Your engineers, your auditors, a regulator or a court can re-verify it offline. Explainability is structural, not a bolt-on report.

5

Intelligence hook

The seal proves the evidence is real; it does not read intent. Every verdict feeds a downstream entity-graph engine (AEGIS) that answers the harder question - is the claim itself honest? Provenance for the evidence, intelligence for the intent.

Capture to decision

How a claim flows through

01

Capture

Claimant photographs damage inside your existing app, powered by the CapSeal SDK.

02

Seal

Signed on-device by the phone's security chip - bound to device, time and place before anything can touch it.

03

Verify

The verify service checks the seal, runs anti-spoofing, and emits a proof object.

04

Decide

The verdict engine applies your policy and returns one class into your workflow.

Output

Three verdicts, mapped to your workflow

CapSeal returns a verdict class, not an opaque score - so payment-without-review is reserved for evidence that can prove itself.

ATTESTED-GENUINE

Auto-pay

Hardware-attested, unaltered, integrity checks clean. Safe to settle straight through - the honest majority.

UNVERIFIED

Review

No seal, legacy upload, or a phone with no secure chip. Routed to your normal review - never auto-rejected on a technicality.

TAMPERED / SYNTHETIC

Reject or investigate

Seal broken, spoof detected, or generation artefacts present. Held back before payout, with the proof to defend the decision.

Technical whitepaper

The architecture, formally

The five components above, specified rather than described: the protocols between them, the detection layers inside them, and the calculus that turns their output into one verdict.

CS-TW-01-2026 · Version 1.0 · August 2026 · 13 pages

Provenance-Gated Evidence Capture: Hardware-Rooted Attestation and Multi-Layer Synthetic-Media Detection

A formal treatment of the trust pipeline rather than a summary of it: the device-resident attestation and sealing protocol, the verification-time detection stack, the fusion calculus that produces a verdict, and the security arguments that bound an adversary's forgery advantage.

  • An adversary model with six capability classes, and the seal-forgery game they play against
  • The enrolment ceremony, key hierarchy and challenge-response capture-session protocol
  • Theorem 1, the seal-unforgeability bound; Theorems 2 and 3 on injection and analog-hole attacks
  • The four detection layers - cryptographic, attestational, physical-statistical, generative-artifact - and the estimators behind them: PRNU correlation, CFA periodicity via expectation-maximisation, double-quantisation ghost analysis, spectral discrepancy, cross-modal ego-motion coherence
  • Fusion through calibrated likelihood ratios with a conformal abstention region, which is where the third verdict comes from
Theorem 3 states that display-mediated attacks are information-theoretically undetectable in the limit of a perfect re-imaging channel. We regard that honesty as a feature: no capture system can make photographing a screen logically impossible. The design goal is to make it economically irrational at scale.

Classification is public with parameters withheld. Concrete model parameterisations, decision thresholds, hardening schedules and red-team corpora stay proprietary - the architecture is published, the instantiation is not.

Technical whitepaper (PDF)

See the platform on your own claims.

Bring a sample from one line of business. We'll run it end to end and show you the verdicts and the proofs.

Request a pilot Contact sales