Legal · Method & trust
Method & trust
How a check is made, how evidence is sealed, and how data is kept apart — in plain words, with nothing claimed that the product cannot show.
Last updated · 2026-09-11
Instruments: how each is held, and how each is validated
Every check reads against the instruments that bind you in your market: the rules written for advertising and for listings by the bodies that oversee them, and, for a brand, its own guideline beside them. This page names no instrument and no body that issues one: the site names a regulator only with its written permission.
Every rulebook carries a version. The rulebooks a sweep reads are data: a version, a change log, the instrument and clause behind every field, and the name of the person who read that interpretation — and a rulebook nobody has signed cannot produce a finding. Today one of them is signed, by a named reviewer recorded as interim until a specialist is retained; the others are unsigned, and from those no sweep reports a finding. From the signed one, read over a captured page, the engine says of one required field whether the page is outside the rulebook's scope, whether the field's string is absent, or whether it is present and not yet confirmed against a register — a sentence about one field, not the end of a check. Where the page does not match the rulebook's trigger, that sentence says out of scope, in the vocabulary's own words. The rulebooks a creative is checked against carry a version and not yet a reviewer's name: the set is stamped with one version on every check, and the core rulebook among them is data with its own version and, for some of its rules, the clause reference and the clause text. But the judge is also handed a summary written in prose inside its instructions, with no version of its own, as its source of clauses; and the rulebook in which every rule is data with its clause text word for word is read in evaluation today, not in a check. Every rule as data, with its clause text and a reviewer's name, is the standard every rulebook is being built to.
A rule that cannot be joined to its source is an opinion, and we do not report opinions. In a sweep, where a field can only be matched as a string and not confirmed against an open register, the check says so. Where no open register exists at all, the word for it is unverifiable: kept apart from the issues and never counted as one.
A finding quotes the claim as it appears in the creative and cites the clause it rests on. The description we write sits beside the quote, never in place of it. Nothing is published by us: a finding reaches only the party that asked for the check.
The engine's vocabulary for a check made in a sweep is fixed to these words, held as data with a guard for a call site to test a word against; no sweep calls the guard today, and no check ends in one of the words. One of them is spoken: from the signed rulebook, when the page does not match its trigger, the sentence about one field says out of scope — the vocabulary's wording, said in a sentence, not recorded as a verdict — and that sentence's own words sit beside the guarded set, not inside it. The other words are reported by no sweep. What a sweep produces today is a capture, sealed or marked incomplete; a run recorded as complete, partial or failed, with its reason; against the last complete run, a change record in a fixed set of states — new, persists, modified, removed, returned, migrated, unobserved, watch-blinded, frame-changed; from the signed rulebook, that sentence about one field; and, from an unsigned rulebook, no finding. A check that ends in one of these words is coming. The words:
- flagged — a checkable claim or a required element, read against a signed rulebook, with the clause cited.
- unknown — the register or the engine could not be reached in this run. It may resolve on the next run; it is never counted as an issue and never as a clearance.
- unverifiable — no open register exists for that field. Re-running does not change it; it is kept apart from the issues.
- no issue found — scoped to the rulebooks and versions that were read. Never a blanket clearance.
- out of scope — the instruction or the rulebook does not cover it, and the check says so rather than stretching.
Evidence, and s.63 readiness
A screenshot is not evidence. What we keep is a sealed bundle of named parts, and a bundle with any part missing is incomplete and cannot be exported.
s.63 is the section of India's evidence law under which an electronic record is admitted. It asks for the process and the fingerprint to be named, and the bundle is shaped to answer both. Readiness is what we build for; whether a record is admitted is a court's decision, not ours.
The bundle is built to be checked without trusting us. A standard tool can verify the timestamp token against the bytes, and a single changed byte fails.
The timestamp comes from an independent public authority. Which one is recorded inside the sealed bundle, where a court can read it, and nowhere on a screen.
The parts:
- the page bytes — exactly what was served, kept as served.
- a hash record — the fingerprint of those bytes and the algorithm that made it.
- a capture manifest — the tool, its version, the time, the address and the account the capture was taken from.
- an independent timestamp — a token from a public timestamping authority, issued over the fingerprint, with that authority's own certificate chain — so the time is not our word.
- a custody record — who ran the capture, where the bytes are stored, and the date until which they are retained.
- a draft certificate — the s.63 certificate text, pre-filled from the parts above, for the person who will sign it.
Data handling: two lanes
One engine, two lanes, is the design: an authority's work and a brand's work through the same fetchers, the same evidence store and the same judge, never seeing each other. The engine is being built for the authority lane first; the brand lane is built on top of the same schema afterwards.
Authority-side data is never visible to a brand. Brand data is never visible to an authority seat. The separation is enforced by the database itself, row by row — not by application code alone. Today, on every table the engine writes, a row belongs to a single workspace and is visible only inside it, and an authority seat is refused every row of those tables, even when that seat also belongs to the workspace. Both rules are tested. A lane written on every row, with a test that a row on each side is invisible to the other, is coming.
An authority lane runs only under a written instruction that names its scope. We never sweep on our own initiative and never bring unrequested findings. A brand lane is to cover only the surfaces the brand has proven it owns; the record of proven ownership is coming, and so is the brand lane itself.
Retention is written into the evidence. Every sealed bundle carries its own retention date in its custody record: three years after the case it belongs to closes, counted provisionally from the capture until the case closes. A capture under a sealed bundle cannot be deleted while the bundle stands.
Brand-side account data follows our privacy policy: you can export it and delete it, and deletion is handled as that policy describes.
The tools we fetch through are not named anywhere a client can see. A path is described only as primary, secondary or tertiary, and the true tool is recorded inside the sealed bundle alone.
See also: Privacy · Security & data
Security: what is here, and what is coming
What is in place today is written on the security page: workspace isolation at the database level, encryption in transit and at rest, and a brand's own data — its Brand Brain — held in India. Where the bytes of a sealed evidence bundle are held is not claimed here: each bundle's custody record names its store and its key.
Everything below is a placeholder. Each line says coming because there is nothing to show yet. None of it is a claim, and each line changes only when there is a document to put behind it.
- coming
SOC 2 report — coming
No report exists today. When one does, its date and scope will be written here.
- coming
ISO certification status — coming
No certification is held today. This line will name the standard and the status when there is one.
- coming
Enterprise security pack — coming
The pack is the lines above and the documents behind them. There is nothing to send today; this line changes when there is.
See also: Security & data