When a provider reports a delivery, who checks?
A message provider reports a delivery today, and the bank takes the provider's word — backed by the provider's own database. Millions of delivery reports a day rest on that one sentence: trust our database.
The provider is its own witness
The report that a message was delivered comes from the same party that delivered it. Its only evidence is its own database.
Every dispute ends at 'trust our database'
When a bank and a provider disagree about a message, there is nothing to check. The bank has to believe, or not.
The evidence is personal data
A delivery report carries a phone number. A bare hash of that number looks anonymous, but it is not: there are only about ten billion possible numbers, so it reverses by brute force on a laptop and remains regulated personal data.
Evidence infrastructure underneath the report
With evidence infrastructure underneath, the same report becomes a proof the bank verifies itself, offline, trusting nobody. The report body never enters the ledger, zero phone numbers travel on the wire, and erasure never destroys the proof. The bank does not get a new service. It gets a removed doubt.
A delivery report that carries its own evidence — checkable by the most skeptical client, without asking anyone.
Doubt removed, not service added
For the providerA report that carries its own evidence
Every dispute today ends at 'trust our database'. With attested delivery proofs the provider's report carries its own evidence — checkable by the most skeptical client it has.
For the bankVerification without permission
Find a message, download its proof, verify it offline. No API key to the provider's systems, no call to anyone — the proof stands or falls on mathematics.
For the person behind the numberA pseudonym that stays a pseudonym
Zero phone numbers on the wire. The reference is derived under a secret key; without the key it is just bytes, and the same number under a second provider's key gives an unlinkable reference.
For the data protection officerErasure that is real and still provable
A person's data can be made unrecoverable on request without destroying the proof that the delivery happened. Deletion refuses to run without a trigger reference and two different DPO approvers.
One delivery report. A proof the bank checks alone.
Four results were driven through the real evidence engine: a report becomes attested evidence, the bank verifies it offline, the person's data is erased while the proof survives, and independent witnesses are held to the bank's own bar. Then the page itself shows, on any number you type, why a pseudonym must be keyed — nothing you type leaves the page.
The one changed byte
Change one byte anywhere in the proof bundle and the offline verdict fails. Tamper detection: 7 of 7.
Erasure with the proof intact
The person's data is destroyed by destroying the key. The proof still verifies. A deletion without a trigger reference and two different DPO approvers is refused.
Bare hash versus keyed reference
Type any number. The bare hash looks anonymous and is not. The keyed reference is just bytes without the key — and a second key gives an unlinkable reference to the same number.
The four results were driven through the real evidence engine in a LAB environment on synthetic data only, with one anchor witness today; the pseudonym demonstration runs live in your browser and sends nothing anywhere.
COTRUGLI Tech Proof of Delivery — the trust layer where humans and AI agents do business. Referenced ≠ Verified · the body never leaves the source · history is never rewritten.