How it works
A diary of physical events, one sealed page at a time.
Every weighing and every handover becomes one record. Each record carries the fingerprint of the one before it. Each day's records are gathered into a root and signed. That is the whole idea — and we state exactly how far each part can be checked, and by whom.
The journey of one record
Five steps, none of them new to your staff.
At the gate
A trained supervisor weighs the bags for one stream on a stamped scale (Legal Metrology) and photographs them in the app. About thirty seconds per handover, ten minutes a day. No change to bins, vendor or routine.
The record is written
Stream, mass, scale-stamp validity, photo, time, place, and the two parties to the handover. The app labels the material into six classes; the stamped scale — not the model — decides the kilograms.
The record is sealed
The record's canonical form is hashed. Its hash chains to the previous record's hash, in sequence, so the order of events is fixed inside the ledger.
The day is signed
Every record hash of the day is gathered into one Merkle root and signed with a separate anchor key. The signed daily statement is what an evidence pack later points to.
The evidence pack
You receive a monthly report per stream. Behind every number sit the sealed records. Evidence packs are yours to keep — the evidence should outlive the vendor, including us.
What a sealed record contains
Illustrative values. A record is never edited after sealing — a correction is a new record that points to the old one.
Verification, by level
How far can each part be checked — and by whom?
We do not say “tamper-proof” or “independently verifiable”. We state the level, on every document. When a level changes, this table changes.
| Level | What it answers | Who can check it | Status |
|---|---|---|---|
| L1 | Payload integrityIs this the record that was sealed? |
Anyone holding the record: the hash of its canonical form must equal the sealed payload hash. | Works today |
| L2 | InclusionWas this record in the signed day? |
Anyone holding the record, its inclusion path and the signed daily statement. | In build — pilot integrity package |
| L3 | Chain linkIs the order of records intact? |
The key holder, or an auditor holding the key under agreement. | Us only, today |
| L4 | Physical truthDid the event really happen, with that mass? |
Never cryptography. Independent counts, re-weighs, processor confirmations and sampling — designed into every pilot. | Pilot design |
Privacy and data
Evidence-first, privacy-preserving.
Photos capture waste, not people
Faces are blurred automatically before a photo is stored. The app is built for the bags at the gate, not the person holding them.
Data stays in India
Records, photos and reports are stored in India. Only mathematical fingerprints would ever need to travel.
Private by default
Your baseline is yours alone. Nothing leaves your account — to a regulator, a buyer or a reporting tool — without your written consent.
One customer per instance
During pilots every deployment is single-tenant, written into the agreement, not left to a setting.
What runs today
A pilot-capable prototype with a sealed ledger and daily signed roots.
Built in Hyderabad, covered by automated tests, ready to be placed at a gate. This sentence is the whole claim.
Sealed, hash-chained evidence ledger · daily signed roots · six-class waste classification · monthly evidence pack · reconciliation engine · command-centre dashboard · opt-in ESG export
Pilot integrity package (L2 for anyone holding the record, customer-held verifier) · per-record device signatures · Proof Corridors · Seal API · claims-conflict check
See it at your own gate before you believe a word of this.
A 60-day proof pilot: one stamped scale, one hour of training, thirty seconds per handover.