Magenta Canon is deliberately under-claimed: a single-tenant reference implementation whose core proof — gate, receipts, independent verification, tamper detection — is runnable and checkable rather than asserted. The claims register, non-claims, and security model are public, and the evidence verifies without trusting the vendor.
- Gate-first: authorized actions are allowed and over-authority actions are blocked before they reach the tool
- Recorded: every allow and block becomes a signed, hash-chained receipt on a Merkle transparency log
- Verifiable: a standalone verifier re-derives the cryptography and shares no code with the server
FOR PROCUREMENT / RISK
You are responsible for whether what the company buys holds up under scrutiny — including its claims.
Magenta Canon is deliberately under-claimed: a single-tenant reference implementation whose core proof — gate, receipts, independent verification, tamper detection — is runnable and checkable rather than asserted. The claims register, non-claims, and security model are public, and the evidence verifies without trusting the vendor.
Your top questions, answered
What stage is this product at?
Reference-implementation stage with a controlled design-partner evaluation path. It is not broad production SaaS, and no compliance certification is claimed. Roadmap items are labeled as roadmap.
How do we verify vendor claims here?
The central claims are mechanically checkable: run the demo, verify the evidence bundle with a standalone verifier, verify the tampered bundle and watch it fail. The verifier shares no code with the vendor's server, so the check does not depend on trusting us.
What is the lock-in and exit posture?
Evidence bundles are plain JSON verified by a small standalone script — the record of what your agents did remains checkable even without the vendor. The reference implementation runs in your environment during evaluation.
Where are the security and diligence artifacts?
The Trust & Security page (/trust) collects the security contact, non-claims, verification path, and diligence artifacts, with the full posture in docs/SECURITY_MODEL.md.
What does evaluation cost and involve?
Evaluation is private-access by grant: a private checkout, the runnable proof loop, and working sessions with us. See the evaluation page (/pricing) and start via the contact form.
The proof story
The same demo runs every time — five beats, each independently checkable.
-
Allowed
An $89 refund, within the delegated ceiling, is forwarded to the downstream tool.
-
Blocked
A $250 refund exceeds the ceiling and is blocked at the gate — before it reaches the tool.
-
Absent downstream
The downstream tool's own log shows the blocked call never arrived.
-
Verified
A standalone verifier — sharing no code with the server — returns ORIGIN AND INTEGRITY VERIFIED.
-
Tamper fails
Flip one byte of the evidence and verification fails. Tampering is caught, not hidden.
Your proof path
Your diligence path:
- Review /trust and the honest-scope statement — what is claimed, and what is explicitly not.
- Have a technical reviewer run the verifier on the committed sample evidence, including the tamper negative-control.
- Request the controlled evaluation to assess fit against one of your real workflows.
Honest scope — what this is, and is not, today
Under-claiming is the brand. Here is the current posture, stated plainly:
- Evaluation today is private-access and repo-source: a granted private checkout. There is no public npm/npx install path.
- What runs today is a reference proof path — a single-tenant reference implementation you run yourself. This is not broad production SaaS.
- The durable hosted witness is not activated in production; the hosted evidence surface is ephemeral unless it is.
- No compliance certification is claimed — no SOC 2, HIPAA, or similar. Compliance determination and legal judgment remain with external reviewers.
- Verification is server-independent — the standalone verifier shares no code with the server — and the security model documents its remaining trust assumptions (docs/SECURITY_MODEL.md).
Ready to look closer?
Evaluation is private and design-partner controlled — a granted checkout and a direct line to us.
Request a private evaluation