The internet can generate infinite claims. It can't verify any of them. We resolve online identities to legal identities across registers that share no common key, we obtain the claims that are never published anywhere, we prove absence (that a registration doesn't exist), and we freeze the evidence so a finding still holds when it's challenged a year later.
Models can produce any claim. Only the record can settle it.
Someone has to be the ground truth.
A raw listing goes in. A sealed evidence pack comes out. Everything in between is orchestrated on one invariant pipeline. A new regulator, obligation or vertical is configuration on these same rails, not a new build.
Licensed sources only. Source, timestamp and integrity hash attached on arrival.
The claim is extracted and the operator behind it is resolved along the identity spine.
Runs only where the mandate authorises it. The operator is asked on the record, and the transcript is hashed like any other artefact.
A deterministic check against live register state. Neither a model output nor an operator's answer passes through unchecked.
Register snapshot, clause reference, transcript and source artefacts chained into one pack.
Awaiting authorised officer…
We source publicly accessible information through licensed APIs and managed providers, under platform terms, not through crawling infrastructure of our own. Collection breadth is an arms race we don't need to win; the value sits downstream. What matters at ingest is provenance: every item enters with its source, retrieval time and integrity hash attached.
Platform APIs and licensed providers, so nothing in the chain is contested later.
Client holdings processed in an isolated workspace, never pooled, never used to train shared models.
Ingest never interacts with anyone. Where an obligation can only be tested by asking, that is a separate step, run only on your mandate. See Step 03.
Marketplace listings, advertising, storefronts and open publications, all via licensed access.
The ground truth other platforms don't reach: company, licensing, professional and product registers, kept live.
Case files and target lists, cross-matched against external footprints in your isolated environment.
A trading name is not a legal entity. A handle is not a licence holder. Registers use different identifiers, different schemas, different refresh cycles. There is no shared key, and the join is the work.
Our spine collapses storefronts, handles, domains, trading names and corporate identifiers into a single accountable operator, held steady across every mandate we run.
This is not a model output. It is accumulated, hand-won mapping, and it deepens with every case.
Registers record what was registered. Listings show what an operator is willing to put in writing. A large share of non-compliance sits in neither: it is asserted in a direct message, quoted at checkout, or said out loud when a buyer asks a specific question. Nobody publishes it, so no monitoring tool can collect it.
So we ask. Conversational agents put the question the mandate authorises and capture the answer as a first-class artefact, with transcript, timestamp and integrity hash, on the same provenance chain as everything else in the pack.
Routed to Verify. The operator named a sponsor. The register decides whether it exists.
Everything else on this page is observation of information already published. This step is not, so it is governed separately, and it is off unless you switch it on.
Disabled by default. Scope, targets, scripts and disclosure posture are set in the mandate and signed off by your legal authority before a single contact is made. We never initiate on our own account.
Agents ask what the mandate authorises and nothing beyond it. No inducement, no negotiation, no advice, no improvisation outside the approved question set.
Full transcript, channel, timestamp and integrity hash, chained into the same evidence pack as the register snapshot. Nothing is summarised away.
A transcript is not a verdict. What an operator asserts is a claim like any other claim, and it is treated exactly the same way: it goes to the register before it becomes a finding.
Language models read messy text, isolate what is being claimed and generate candidate matches. They are fast, and wrong often enough that no finding can rest on them. An operator's own answer is no safer; it is a claim by an interested party. So neither decides anything. The verdict is a deterministic traversal against register state, and the evidence pack cites the register record.
Confirming a registration exists is a lookup. Proving none exists means ruling out every naming variant, every related entity, every alternate sponsor, exhaustively. Get it wrong and a regulator acts against an innocent business.
That risk is why most of the market sells probability scores. A score is never wrong. We took on the answer, so we had to build the machinery.
Search space exhausted and recorded. The absence is now evidence, not an assumption.
A finding made in March gets challenged in November. By then the register has been updated, the site is down and the listing is deleted. So we snapshot register state at determination and chain provenance end to end: the world as it stood at the moment it mattered, reproducible on demand.
This is a data-model decision made on day one. Monitoring tools can't retrofit it, because they never had to defend an answer.
The kernel is fixed. What changes is the mandate: which obligations apply, which registers are authoritative, where your thresholds sit.
Provider obligations validated across scheme and corporate registers.
NDIS mandateAdvertising and supply obligations tested against the product register.
TGA mandateCorporate and financial services licensing checked against live state.
ASIC mandateInternal policies and supplier obligations encoded on the same engine.
Your mandateFindings arrive severity-ranked with evidence attached; an authorised officer decides what happens next, and every review is logged.
Each mandate adds encoded obligations, resolved operators, recorded engagements and adjudicated outcomes, and they carry across domains, because the same actors keep reappearing.
Every year, generating claims gets cheaper and verifying them gets more valuable. We sit on the right side of that curve.