Security & compliance

Trust by construction.

CapSeal is designed so you never have to take our word for anything. Every verdict rests on hardware you already trust and cryptography your bank runs - and every proof is independently verifiable by your own engineers. The engine that produces it is proprietary to CapSeal.

The trust model

You don't trust us. You trust the math.

The trust is by construction. Every guarantee rests on Apple and Google's silicon and bank-grade cryptography, and every proof can be re-verified by your own team, offline, forever. Verifiable by anyone. Producible only by CapSeal.

HARDWARE

Apple & Google chips

The "real, un-tampered device" guarantee comes from Secure Enclave and Play Integrity, signed at capture. We consume it; we don't issue it.

CRYPTOGRAPHY

Bank-grade signing

Standard asymmetric signing binds the seal to the asset. Change one pixel and it provably breaks - verifiable offline, on your own servers.

PROOF

Replayable on your hardware

Every verdict ships as a signed proof object: the inputs, each check, and the conclusion. Proprietary engine, transparent output - your auditors check the result, not our reputation.

Data handling

Privacy-preserving by design

Your data stays yours

CapSeal integrates alongside your claims system, not in place of it. Seals and proofs can be verified within your boundary; the verify service needs the evidence and its manifest, not your customer database.

The network shares signatures, not data

Cross-carrier verification uses salted entity hashes and private set intersection. A carrier learns "this evidence was already sealed elsewhere" without either side exposing raw customer information - engineered to de-identification standards.

Regulatory alignment

Australia-first, globally extensible

CapSeal is built around the properties regulators increasingly demand of automated decisions - explainability, auditability, and proportionate treatment of customers.

AUSTRALIA

Home-market fit

  • Privacy Act 1988 and the automated-decision transparency reform trajectory - proof objects provide native explanation
  • General Insurance Code of Practice - proportionate, evidence-based investigation friction
  • ASIC claims-handling regime and APRA CPS 230 operational-risk expectations via the audit and replay surfaces
EXPORT

Maps cleanly abroad

  • EU AI Act high-risk-system requirements - explainability and human oversight built in
  • UK FCA Consumer Duty and financial-crime obligations
  • The same proof-carrying architecture satisfies each, making compliance an export asset rather than a rebuild
The honest limit, stated plainly: the seal proves provenance - real device, real moment, unaltered. It does not prove the claimant's intent. CapSeal makes the evidence trustworthy; the intelligence layer behind it addresses whether the claim itself is honest. A vendor that names its limits is the one worth trusting with your payments.
Technical whitepaper

The security argument, written out in full

Everything on this page is asserted. TW-01 is where it is argued - with an explicit adversary model, stated assumptions, and proofs you can disagree with.

CS-TW-01-2026 · Version 1.0 · August 2026 · 13 pages

Provenance-Gated Evidence Capture: Hardware-Rooted Attestation and Multi-Layer Synthetic-Media Detection

A formal treatment of the trust pipeline rather than a summary of it: the device-resident attestation and sealing protocol, the verification-time detection stack, the fusion calculus that produces a verdict, and the security arguments that bound an adversary's forgery advantage.

  • An adversary model with six capability classes, and the seal-forgery game they play against
  • The enrolment ceremony, key hierarchy and challenge-response capture-session protocol
  • Theorem 1, the seal-unforgeability bound; Theorems 2 and 3 on injection and analog-hole attacks
  • The four detection layers - cryptographic, attestational, physical-statistical, generative-artifact - and the estimators behind them: PRNU correlation, CFA periodicity via expectation-maximisation, double-quantisation ghost analysis, spectral discrepancy, cross-modal ego-motion coherence
  • Fusion through calibrated likelihood ratios with a conformal abstention region, which is where the third verdict comes from
Theorem 3 states that display-mediated attacks are information-theoretically undetectable in the limit of a perfect re-imaging channel. We regard that honesty as a feature: no capture system can make photographing a screen logically impossible. The design goal is to make it economically irrational at scale.

Classification is public with parameters withheld. Concrete model parameterisations, decision thresholds, hardening schedules and red-team corpora stay proprietary - the architecture is published, the instantiation is not.

Technical whitepaper (PDF)

Put it in front of your risk team.

We'll walk your security, model-risk and compliance functions through the proof model and the data architecture.

Book a security review Contact sales