← cotrugli.tech
COTRUGLIPROOF OF DELIVERY
The Trust Layer · Evidence Infrastructure

The provider stops being its own witness.

A message provider reports a delivery today, and the bank takes the provider's word — backed by the provider's own database. With evidence infrastructure underneath, the same report becomes a proof the bank verifies itself, offline, trusting nobody. The bank does not get a new service. It gets a removed doubt.

The report body never enters the ledger · zero phone numbers on the wire · erasure without destroying the proof

Already demonstrated

Driven through the real evidence engine — these are results, not intentions.
01

A delivery report becomes attested evidence

The report is hashed at the source; the ledger receives and anchors the fingerprint. The full proof bundle is ~2.5 KB and contains zero phone numbers and zero message ids.

02

The bank verifies alone, offline

A standalone verifier — one file, no network — re-computes every check (C1–C9), including that the anchor proof names the receipt it actually anchors. Change one byte anywhere and the verdict fails. Tamper detection: 7 of 7.

03

Erasure that keeps the proof

GDPR erasure by key destruction: the subject's data becomes unrecoverable while the proof still verifies. Deletion is fail-closed — it demands a trigger reference and two different DPO approvers, and refuses anything less.

04

Independent witnesses, the bank's bar

Independent operators co-sign the log's checkpoints. How many are required is the bank's own policy at verification time — never a claim the bundle makes about itself.

Live demonstration runs entirely in your browser

A pseudonym that stays a pseudonym — nothing you type leaves this page.
Phone number (synthetic by default — use any)
The naive way — a bare hash
Looks anonymous. It is not: there are only ~1010 possible numbers, so this "pseudonym" reverses by brute force on a laptop — it remains regulated personal data.
Our way — a keyed reference (HMAC)
Derived under a per-tenant secret key. Without the key the reference is just bytes — and the same number under a second tenant's key gives an unlinkable reference:
⚙️ Computed with WebCrypto, byte-identical to the engine's derivation (subj:v1, domain-separated HMAC-SHA256). Open your browser's network tab: this page sends nothing, anywhere. The format is versioned, not carved in stone — partner feedback reshapes it as a new prefix beside the old, never a silent reinterpretation.

Why it matters

Millions of delivery reports a day; one question underneath them all.
FOR THE PROVIDER

Doubt removed, not service added

Every dispute today ends at "trust our database". With attested delivery proofs the provider's report carries its own evidence — checkable by the most skeptical client they have.

FOR THE BANK

Verification without permission

Find a message, download its proof, verify it offline. No API key to the provider's systems, no call to anyone — the proof stands or falls on mathematics.

HONEST LABELS

What this is, and is not

LAB environment · synthetic data only · one anchor witness today (independent witnesses joining is the very next step) · the reference format is provisional and will be reshaped by partner and regulator feedback.