CapSeal is designed so you never have to take our word for anything. Every verdict rests on hardware you already trust and cryptography your bank runs - and every proof is independently verifiable by your own engineers. The engine that produces it is proprietary to CapSeal.
The trust is by construction. Every guarantee rests on Apple and Google's silicon and bank-grade cryptography, and every proof can be re-verified by your own team, offline, forever. Verifiable by anyone. Producible only by CapSeal.
The "real, un-tampered device" guarantee comes from Secure Enclave and Play Integrity, signed at capture. We consume it; we don't issue it.
Standard asymmetric signing binds the seal to the asset. Change one pixel and it provably breaks - verifiable offline, on your own servers.
Every verdict ships as a signed proof object: the inputs, each check, and the conclusion. Proprietary engine, transparent output - your auditors check the result, not our reputation.
CapSeal integrates alongside your claims system, not in place of it. Seals and proofs can be verified within your boundary; the verify service needs the evidence and its manifest, not your customer database.
Cross-carrier verification uses salted entity hashes and private set intersection. A carrier learns "this evidence was already sealed elsewhere" without either side exposing raw customer information - engineered to de-identification standards.
CapSeal is built around the properties regulators increasingly demand of automated decisions - explainability, auditability, and proportionate treatment of customers.
Everything on this page is asserted. TW-01 is where it is argued - with an explicit adversary model, stated assumptions, and proofs you can disagree with.
A formal treatment of the trust pipeline rather than a summary of it: the device-resident attestation and sealing protocol, the verification-time detection stack, the fusion calculus that produces a verdict, and the security arguments that bound an adversary's forgery advantage.
Theorem 3 states that display-mediated attacks are information-theoretically undetectable in the limit of a perfect re-imaging channel. We regard that honesty as a feature: no capture system can make photographing a screen logically impossible. The design goal is to make it economically irrational at scale.
Classification is public with parameters withheld. Concrete model parameterisations, decision thresholds, hardening schedules and red-team corpora stay proprietary - the architecture is published, the instantiation is not.
Technical whitepaper (PDF)We'll walk your security, model-risk and compliance functions through the proof model and the data architecture.
Book a security review Contact sales