Magenta Canon is deliberately under-claimed: a self-run reference implementation whose core proof — gate, receipts, independent verification, tamper detection — is runnable and checkable rather than asserted. Maturity is stated in three states that are never blurred (proven today, building now, roadmap). The claims register, non-claims, and security model are public, and the evidence verifies without trusting the vendor.
- Gate-first: authorized actions are allowed and over-authority actions are blocked before they reach the tool
- Recorded: every allow and block becomes a signed, hash-chained receipt on a Merkle transparency log
- Verifiable: a standalone verifier re-derives the cryptography and shares no code with the server
FOR PROCUREMENT / RISK
You are responsible for whether what the company buys holds up under scrutiny — including its claims.
Magenta Canon is deliberately under-claimed: a self-run reference implementation whose core proof — gate, receipts, independent verification, tamper detection — is runnable and checkable rather than asserted. Maturity is stated in three states that are never blurred (proven today, building now, roadmap). The claims register, non-claims, and security model are public, and the evidence verifies without trusting the vendor.
Your top questions, answered
What stage is this product at?
Reference-implementation stage with a controlled design-partner evaluation path. It is not broad production SaaS, and no compliance certification is claimed. The site separates three states and does not blur them: proven today, building now (the multi-tenant Human Plane, not production-active), and roadmap.
How do we verify vendor claims here?
The central claims are mechanically checkable: run the demo, verify the evidence bundle with a standalone verifier, verify the tampered bundle and watch it fail. The verifier shares no code with the vendor's server, so the check does not depend on trusting us.
What is the lock-in and exit posture?
Evidence bundles are plain JSON verified by a small standalone script — the record of what your agents did remains checkable even without the vendor. The reference implementation runs in your environment during evaluation.
Where are the security and diligence artifacts?
The Trust & Security page (/trust) collects the security contact, non-claims, verification path, and diligence artifacts, with the full posture in docs/SECURITY_MODEL.md.
What does evaluation cost and involve?
Evaluation is private-access by grant: a private checkout, the runnable proof loop, and working sessions with us. See the evaluation page (/pricing) and start via the contact form.
The proof story
The same demo runs every time — five beats, each independently checkable.
-
Allowed
An $89 refund, within the delegated ceiling, is forwarded to the downstream tool.
-
Blocked
A $250 refund exceeds the ceiling and is blocked at the gate — before it reaches the tool.
-
Absent downstream
The downstream tool's own log shows the blocked call never arrived.
-
Verified
A standalone verifier — sharing no code with the server — returns ORIGIN AND INTEGRITY VERIFIED.
-
Tamper fails
Flip one byte of the evidence and verification fails. Tampering is caught, not hidden.
Your proof path
Your diligence path:
- Review /trust and the honest-scope statement — what is claimed, and what is explicitly not.
- Have a technical reviewer run the verifier on the committed sample evidence, including the tamper negative-control.
- Request the controlled evaluation to assess fit against one of your real workflows.
Honest scope — what this is, and is not, today
Under-claiming is the brand. Here is the current posture, stated plainly:
- Evaluation today is private-access and repo-source: a granted private checkout. There is no public npm/npx install path.
- What runs today is a reference proof path you run yourself — not broad production SaaS, and not a hosted multi-tenant service.
- Enforcement is scoped to the MCP tools/call method class. Other MCP methods pass through the gateway ungated; we state that rather than implying every agent action is governed.
- Multi-tenancy: organization scoping exists in the Human Plane at the application layer, behind a hosting-environment gate. The database-enforced tenant boundary and the per-request corridor that carries the tenant principal are merged and exercised by CI, and are not production-active by this project: no shipped code puts the row-level-security policies in force.
- The durable evidence ledger is self-host and selector-gated; it is not activated in the default deployment, so the hosted evidence surface is ephemeral.
- No compliance certification is claimed — no SOC 2, HIPAA, or similar. Compliance determination and legal judgment remain with external reviewers.
- Verification is server-independent — the standalone verifier shares no code with the server — and pins two separate anchors: the witness key and the ceremony-sourced receipt-issuer key. Pinning the witness key alone is fail-open on receipt provenance. The security model documents the remaining trust assumptions (docs/SECURITY_MODEL.md).
Ready to look closer?
Evaluation is private and design-partner controlled — a granted checkout and a direct line to us.
Request a private evaluation