Supporting evidence layer · VeilEngine™

When a workflow needs an inspectable execution record

VeilEngine is a supporting capability for eligible workflows that need a configured data boundary and an offline-checkable record of one request path. It is not required for every engagement, and it is not the starting point for choosing the work.

Current evidence state
Synthetic
configured boundaryTier 1 eligible workflows
gateway receiptsigned
sample verificationoffline PASS
customer deploymentnot established
business outcomenot established
Three fit triggers

Use the extra layer only when the workflow calls for it

Data boundary

Sensitive inputs need a configured path

The engagement must identify eligible data, approved handling, and the systems allowed to participate in the request path.

Execution evidence

A request needs its own record

The operating team needs an inspectable receipt for a configured gateway event, separate from a model provider’s general activity view.

Independent review

The record must verify offline

A reviewer needs to validate the sample signature and hashes with the published public key without contacting VeilEngine systems.

These triggers identify a scoping question, not automatic eligibility, legal advice, certification, or a compliance determination.

Current mechanism

Boundary, receipt, verification

The current claim is intentionally narrow and tied to the published synthetic sample.

01 · Configured boundary

Eligible Tier 1 workflow

The selected workflow, data scope, and permitted request path are configured per engagement.

02 · Gateway receipt

Signed execution record

The gateway creates a signed receipt for the configured event. Negative tests detect tampering with signed fields and included file hashes.

03 · Offline check

Independent sample verification

The included sample session can be checked with the published public key without access to VeilEngine systems.

Evidence and status

What the current sample does, and does not, establish

Synthetic demonstration

Public sample boundary

Establishes: the included sample signature and file hashes verify offline with the published key, and the negative-test fixtures detect the tested tampering.

Does not establish: customer deployment, provider behavior, production maturity, universal data handling, legal or regulatory compliance, or business outcomes.

Open the synthetic sample
Protection-tier status

Current and roadmap

Current: a configured Tier 1 boundary and signed gateway receipt mechanism for eligible workflows, represented by synthetic evidence.

Roadmap: Tier 0, Tier 2, broader provider routing, and cross-session or cross-organization evidence concepts. These are not currently offered capabilities.

Business outcome: not established.

Decide in workflow context

First map the work. Then decide whether VeilEngine belongs.

The Workflow Opportunity Map identifies the workflow, data boundary, systems, human authority, evidence need, and acceptance criteria. That scope determines whether VeilEngine is relevant and what must be validated before implementation.

Review the trust architecture
Map one workflow