Trust and security
Cryptographic verification. Customer-side enforcement.
GeoClear provides verifiable evidence. Your systems retain control.
What the evidence covers, and what it does not
| What the evidence covers | Record integrity, policy binding, action commitment, actor commitment, evidence commitment, and verification profile. |
|---|---|
| What GeoClear does not establish | GeoClear does not establish real-world truth, model correctness, mission validity, legal compliance, or risk-free operation. |
| Customer-side enforcement | GeoClear issues the evidence. The customer-designated system enforces accept, hold, reject, quarantine, or escalate. |
| Offline verification | Customers can verify retained records and bundles without requiring GeoClear servers in the audit path. |
| Customer-held evidence | The customer retains the record, policy bundle, evidence commitments, trust material, and verifier reports. |
| Deployment-specific trust profiles | Commercial, dedicated, and customer-controlled or authorized integrator-managed deployments may use different trust profiles. |
Procurement questions
What happens to our evidence if GeoClear is unavailable or no longer reachable?
Customers retain the records, evidence commitments, policy bundles, trust material, verifier reports, and applicable trust bundle. Previously issued records are designed to remain verifiable with customer-held material and offline verifier tooling, without relying on GeoClear application servers in the audit path.
Does GeoClear take the action or control our systems?
No. GeoClear issues the evidence. The customer-designated system enforces accept, hold, reject, quarantine, or escalate. Enforcement stays inside your boundary.
How do we review deeper technical material?
Deeper architecture material is available through a gated architecture brief. Use the contact page to request it.
Interlock events such as missing records, invalid records, fail-open-with-audit, and replay rejections can be emitted through customer-approved OpenTelemetry-compatible pipelines for routing into existing SIEM, observability, and GRC tools.