Patents & Innovations
157 consolidated patent claims across custody, consensus, compliance, attestation, autonomic infrastructure, trading integrity, fraud detection, and evidentiary systems
Full Patent Portfolio
157 claims spanning custody & MPC, validator/consensus/bridge, compliance gating, attestation & evidence, autonomic self-healing infrastructure, zero-knowledge privacy, treasury & federation, trading & market integrity, identity/KYC, fraud detection, and evidentiary/litigation-support systems — each mapped to production code, not aspirational.
A. Custody & MPC
Claims 001-006Self-Custody MPC Architecture with Threshold Signing
A user-primary key-shard model with fail-closed, HSM-preferred threshold signing that structurally cannot reach quorum without the user's own share.
Distributed Custody Failover Across Independent Providers
A custodian-agnostic compliance co-signing layer that keeps a client's attestation history intact when it fails over from one independent institutional custodian to another.
Decentralized Custody Marketplace with Additive Coverage Limits
Independently-operated custody providers, each enforcing its own operational egress ceiling, additively combined into one account-level capacity figure under a single compliance gate.
Social Recovery Ceremony with Guardian Quorum and Timelock
A state-machine-governed guardian-set rotation requiring both a cryptographic approval quorum and an elapsed mandatory delay window before it takes effect.
Non-Custodial Proof-of-Holdings via Challenge-Response
A court-chain-sealed, publicly-verifiable holdings predicate minted from a signature over a single-use challenge - no transaction, no custody, no private-key exposure at any point.
Binding-Message Replay-Protected Multi-Mode MPC Shard Recovery
Three independently-verifiable recovery proof kinds, each cryptographically bound to the specific backup being recovered, so a captured recovery signature has zero value against any other backup.
B. Validator, Consensus & Bridge
Claims 007-018Multi-Jurisdictional BFT Validator Bridge
Lock-and-Mint Cross-Chain Settlement Secured by an M-of-N Validator Threshold, Per-Regulatory-Zone Daily Volume Limits, and a Guardian-Role Fraud Veto
Multi-Gate Validator Bootstrap with Time-Limited Consensus Authorization
A Four-Gate Handshake, Config, Image-Digest, and Key-Proof Sequence Gating Issuance of a Short-Lived Consensus Authorization Token
Container Image Digest Verification Gate
Fail-Closed Refusal to Start or Restart Consensus Services on Any Pinned-Manifest Image Digest Mismatch
Time-Limited Consensus Authorization Token
A 24-Hour Bearer Token Minted Only After Challenge-Response Proof of Key Possession Across a Five-Key-Type Validator Identity
Correlation-ID Secure Boot for Multi-Phase Validator Bootstrapping
Asynchronous, Out-of-Order-Safe Request/Response Matching Over an Outbound-Only Event Bus, With Independent Per-Message HMAC Authenticity
SCN Validator-Secured Merkle Bridge with Fraud-Proof Challenge Period
Merkle-Proven Withdrawal Records, Independent Per-Validator Co-Signing to Threshold, and a Guardian-Role Fraud Veto Between Approval and Release
Bridge Authority Wrapper Tokens on a Payment-Only Ledger
Cross-Cell Value Release as an Ordinary Authorized Balance Transfer From a Reserved Float Account, With No Separate Mint Primitive
Hybrid Post-Quantum Cross-Cell Value-Release Verification
Genesis-Pinned 61-Slot ML-DSA-65 Key Decomposition Enabling Fail-Closed, In-Consensus, Per-Cell Opt-In Hybrid Signature Verification
Relayer-Independent Lock Re-Derivation for Cross-Cell Settlement
Reconstructing a Claimed Source-Cell Lock Directly From the Source Cell's Own Registered RPC, Gated by a Three-Tier Per-Corridor Circuit Breaker
Jurisdiction-Diversity-Gated Validator Key Ceremony with SPOF Detection
Hard-Rejecting Group-Key Ceremony Invitation on Insufficient Jurisdictional Diversity, With a Standing Concentration-Risk Detector
Progressive Post-Quantum Consensus Rollout via Fail-Open Vote Extensions
A Registry Gap Can Never Halt the Chain: Only a Registered Validator That Actually Fails to Produce a Valid Extension Is Rejected
Post-Quantum Cryptographic Migration Without Network Downtime
A Percentage-Gated Phase Machine Operationalizing a Classical-to-Hybrid-to-Post-Quantum Migration Doctrine With No Coordinated Network Halt
C. Compliance & Transaction Gating (ATCE)
Claims 019-023Autonomous Transaction Compliance Engine with Zone-Partitioned Settlement
A single deterministic, in-consensus policy evaluator reused unmodified as both the per-transfer currency compliance gate and the federation cross-cell arrival gate.
Deterministic In-Consensus Compliance Gate with Merkle-Committed Jurisdiction Set
A compliance policy of arbitrary jurisdiction-list size represented in exactly two fixed 32-byte storage slots - a packed scalar word plus an order-independent jurisdiction-set commitment.
On-Chain Regulated Currency Object with Enforced Solvency Invariant
A lifecycle-governed native currency object whose outstanding supply is a real ledger quantity checkable against an attested reserve root, with chain-ID-domain-separated mint and burn authority.
Non-Custodial Pre-Clearance Authorization Layer
A required, independently-produced compliance co-signature bound by hash to the exact transaction it authorizes, contributed by a party that never takes custody of the asset at any point.
KYC-Before-Bridging Gate on a Non-Custodial MPC Wallet
Dependent claim (of Claim 22): a KYC-status precondition enforced ahead of passkey signing and threshold-signing session construction, so an unverified account's wrap/bridge/movement request never reaches the signing layer.
D. Attestation, Verdict Engine & Evidence
Claims 024-053Civil-Admissible Cryptographically-Sealed Verdict Record
Multi-jurisdiction BFT-quorum-signed verdict records purpose-engineered to satisfy Federal Rules of Evidence 901 and 902(14), verifiable by any third party without issuer cooperation.
Inherited-Quorum Retroactive Verdict Record
Merkle-Path Inheritance Lets One BFT Quorum Signature Cover Thousands of Independently Verifiable Child Findings
CREB Reproducibility Manifest
Seven Hash-Class Replay Verification: a standalone verifier program reproduces any compliance verdict from public artifacts, with no cooperation from the issuer required
Merkle-Chained Append-Only Audit Log with Public BFT Anchoring
Insert-time chain hashing inside the database transaction, anchored on a fixed interval to a public distributed ledger via Byzantine Fault-Tolerant quorum signature
Dual-Independent-Anchor Hybrid Post-Quantum Seal
A hybrid Ed25519 + ML-DSA-65 signature bound to two mutually independent clocks the issuer does not control - a verified RFC 3161 timestamp authority and a public-blockchain anchor
Chain-Operator-Independent Proof-Native Block Finality Anchoring
Extending Claim 28's dual-independent-anchor seal to a blockchain's own finality certificates, so a chain is never the sole anchor of its own finality
Stateless Deterministic Document Key Rotation
Two-tier HMAC-derived access keys rotate automatically every calendar period with zero server-side key state
Deterministic LLM Verdict with Numeric Drift Guard
Bounding a language model's numeric output by an independently-computed deterministic floor so a civil-evidentiary verdict cannot drift beyond a configured tolerance
Model-Card Sealing System
Bound Into a BFT-Signed Verdict Receipt: cryptographically identifying the exact model, version, prompt, and parameters behind every AI-mediated compliance verdict
Money Passport Credential Bundle
Four independently BFT-signed attestations - accredited status, proof of funds, source of funds, and income - bound into one portable, freshness-gated credential
Ephemeral No-Retention PHI Classification with Cryptographic Commitment Binding
An in-memory enclave judges unstructured clinical narratives and persists only a de-identified verdict, a commitment, and a seal - the cleartext never touches disk
Client-Perimeter Edge/Cloud Split with Non-Exportable Tokenization Key
A customer-resident edge connector is the only component that ever touches cleartext records - the re-identification key never leaves the customer's network
Bi-Directional Neutral-Evidence Network with Architectural Allegiance Firewall
One verdict engine, one shared compliance check canon, two adversarial evidence products - provider-facing AREB and payer-facing PIEB - separated by a deny-by-construction data-access firewall, not organizational trust.
Bi-Directional Effective-Dated Compliance Canon
The same citable, version-pinned check runs pre-bill to substantiate and post-bill to detect - without the provider-facing and payer-facing interpretations ever diverging. Dependent on Claim 36's allegiance-firewalled architecture.
Sealed-Proof Zero-Exposure Compliance Proof
Per-check salted commitments aggregated to a signed Merkle root - proving every check in a canon passed without disclosing what any one check evaluated.
Hash-Chained Sealed Recovery Ledger with Appeal-Overturn Rule Throttling
Every recovery-lifecycle action sealed into an immutable hash chain, with a rule that loses too many appeals automatically pulled from production.
Retroactive Appeal-Supersession Propagation Without Mutating Sealed Records
When an appeal overturns a finding, every downstream sealed bundle that relied on it gets flagged current - not rewritten. Builds directly on Claim 39's hash-chained recovery ledger.
Two-Layer Shadow-Auditor Pre-Submission Denial Predictor
A deterministic authoritative rule layer plus a self-calibrating noisy-OR probability layer predict a government auditor's denial before a claim is ever submitted.
Auditor-Mirroring Dual-Figure Exposure Extrapolation
A point estimate and a conservative one-sided 90% Wilson-score lower bound, extrapolated across the paid-claim universe using the same statistical-sampling method a government auditor would use.
Peer-Cohort-Normalized Documentation Integrity Index
A composite per-worker quality score z-scored within a discipline-and-visit-type peer cohort, with structural guardrails against use as a termination tool.
Per-Field Inline Cryptographic Redaction Commitments
A dual-layer evidence bundle where each redacted field is replaced in place with a truncated hash of its original value - provable field-by-field fidelity without disclosure.
Graduated Containment Account State with Lifeline Allowlist
A capability-restricted compliance hold enforced directly at the ledger execution layer, distinct from a binary account freeze
WebAuthn Passkeys as Validator-Level L1 Transaction Authorization
Consumer passkey assertions verified deterministically by blockchain validator nodes, with fee and destination cryptographically bound into the signed challenge
EDI-to-Sealed-Finding Pipeline with Ingest-Time Tokenization
Control-total reconciliation as an attestation precondition, combined with tokenize-at-ingest and idempotent receipt of X12 837/835 files
Proof-Without-Custody Client-Resident Audit Edge
A minimal-footprint connector for provider-record audit workflows - incremental watermark reads, local evaluation, outbound-only sealed results, zero PHI at the control plane
Substrate-Independent Verdict Manifest with Cross-Cloud Reproducibility Proof
Inner-hash / outer-envelope separation that lets a verdict produced on one cloud substrate be replayed and byte-verified on another
Sovereign-Bound Single-Tenant Deployment with Cryptographic Data-Residency Attestation
A three-element per-verdict cryptographic proof - hardware attestation, proof-of-residency, and cross-jurisdiction-egress denial - binding every verdict to a specific sovereign jurisdiction
In-Tenant Containerized Verdict Generation with Customer-VPC Isolation Invariant
A signed deployment manifest and an egress-failure-as-attestation-failure rule that make tenant isolation a per-verdict cryptographic property, not a vendor promise
Cross-Trust-Boundary Co-Anchoring
A validator quorum co-signs the anchoring event over a customer-appliance-signed bundle hash, without the operator ever receiving the underlying content
Substrate-Isolated Anchor Gateway for Sandboxed Compute Planes
A single narrow choke point that turns a data-boundary policy into enforced software, rather than a convention every downstream service must independently honor
E. Autonomic Fleet & Self-Healing (AEGIS / ProofGuard)
Claims 054-075Earned-Autonomy Graduation for Machine Self-Remediation
Per-Pairing, Bayesian-Confidence-Gated, Revocable Autonomous-Execution Authority for Infrastructure Self-Healing
Blast-Radius-Scoped Fail-Closed Autonomy Constitution
Tiered Impact Classification, Default-Deny Authorization, and a Structural Consensus-Safety Carve-Out for Autonomous Remediation
Adaptive-Immunity Distribution of Learned Remediations Across a Federation
Peer-to-Peer, Central-Round-Trip-Free Propagation of Confirmed Fixes Across a Blockchain Federation
Subsidiarity Router for Self-Healing
Ordered Reflex / Autonomic / Cortex Dispatch to the Lowest Competent Remediation Layer, Escalating to a Human Only on Full Abstention
Agentic Signature Synthesis with Registry-Clamped Authority
Letting a Reasoning Model Author New Autonomous Remediations Without Ever Letting It Author Its Own Execution Authority
Mithridatic Self-Administered Immunization Drills
Periodic Self-Attack of Already-Graduated Remediations Against an Isolated Canary Site to Catch Silent Remedy Rot
Correlation-Triggered Blast-Radius Reclassification
Dynamic, Real-Time Upgrade of Blast-Radius Classification When a Fault Signature Correlates Across the Fleet
Two-Tier Site-Scoped Do-No-Harm with Probation Recovery
Site-Local Failure Containment, Cross-Site-Confirmed Fleet-Wide Demotion, and Reversible Probationary Reinstatement
Late-Joiner Herd Immunity at Fleet-Join Time
One-Shot Join-Time Inheritance of a Federation's Entire Confirmed Remediation Library
Segmented Hash-Chain with Honest Gap Attestation
Cryptographically Distinguishing Tampering from Unavoidable Data Loss Within a Single Evidentiary Chain
Court-Grade Tamper-Evident Ledger of Autonomous Machine Decisions
Hash-Chained, Append-Only Capture of Diagnosis, Authorization, Confidence, Action, and Verified Outcome for Every Autonomous Remediation
Keys-Free Decision Hub with Privilege-Scoped Effector Split
A Central Decision Brain That Holds No Infrastructure Credentials, Paired With Independently-Guarded Effectors That Re-Verify Ground Truth Before and After Every Privileged Action
Threat-Scored Fleet Remediation Gated by Live BFT-Quorum-Safety Math
A Live Validator-Floor Gate That No Threat Score Can Override for Fleet-Scoped Autonomous Remediation
Quarantine-First "Earned-Liquidity" Launch Control Loop
Milestone-Gated Release of Token-Launch Proceeds and Liquidity Bound to a Continuously Re-Scored Market-Integrity Threshold, Not a Calendar Unlock
Beneficial-Owner-Aggregated Sell Throttle Over a Clustered Identity Graph
Rolling-Window Sell-Rate Caps Enforced Against a KYC-Resolved Beneficial-Owner Cluster, Not the Individual Selling Wallet
Liquidity Firewall with Code-Enforced Rolling-Drawdown Caps
Graduation-Gated Vault Support for Launch Pools, Bounded by Ordered 24-Hour, 7-Day, Total, and Hard-Stop Exposure Caps
LP Bait-and-Pull Withdrawal Defense
State-Keyed, Size-Tiered Locking of Liquidity-Provider Capital Itself, Independent of Holder-Side Sell Throttles and Locked-Lot Restrictions
Single Integrity-Score Oracle Governing an Entire Liquidity Lifecycle
One Deterministic, Multi-Signal Composite Market-Integrity Score Read as the Shared Gating Input by Independently-Operating Release, Graduation, and Escalation Subsystems
Graduated Stress-Mode State Machine with Asymmetric Off-Curve Sell Reroute
Four-Level Escalation Driven by Rolling Net-Sell-Pressure and Price-Drop Signals, Pricing a Dynamic Fee Tier and Rerouting Oversize Sells Away From the AMM Curve
Launch-Integrity Bond with Court-Anchored Slashing and Structured Victim Reimbursement
A Risk-Tier-Scaled Forfeitable Bond Posted as a Precondition to Liquidity Support, Slashable Against Enumerated Integrity Violations with Allocation-Directed Reimbursement
Anti-Wash Graduation Gate as a Liquidity-Access Precondition
Code-Enforced Conjunction of a Minimum Stabilization Period, a Risk Ceiling, and Objective Wash-Trading and Sybil-Cluster Exclusions, Gating an Irreversible Liquidity-Unlock State Transition
Locked-Lot Multi-Restriction Token Hold Bound to a Beneficial-Owner Graph
A Single Per-Lot Unlock Timestamp, Resolved to a Beneficial-Owner Cluster, Independently Enforced Across Eight Structurally Distinct Disposal Paths
F. Zero-Knowledge & Privacy
Claims 076-082Zero-Knowledge Compliance System with Multi-Jurisdiction Support
On-Chain Compliance-Statement Registry with Statement-Bound Proof Verification Across Jurisdictions
Composable On-Chain ZK Compliance Gate with Statement-Bound Proof Verification
Inheritable requireCompliance/requireKYC Modifiers Any Contract Can Adopt Without Reimplementing Proof Verification
Versioned Multi-Proof-System ZK Verifier Registry
A CircuitType × Version Matrix of Independently Swappable Verifier Contracts Spanning Groth16, PLONK, STARK and FFLONK
Privacy with Selective Disclosure
Homomorphic Balance Commitments with Multi-Proof-System Range/Sufficiency Circuits and Deterministic Audit Receipts
ZK Proof-of-Reserves with Poseidon Deposit Commitments
Groth16 Solvency Circuits Binding Bounded Private Deposit Sets to a Public Net-Supply-Not-Exceeding-Reserves Invariant
Reverification-Grace-Period Humanity Gate
Soulbound Biometric Proof-of-Humanity with an Inheritable Access Modifier and Grace-Period-Bounded Reverification
PQ Epoch Registry with Hash-Commitment Fallback
Rotating Signing-Epoch Chain with Ed25519 Classical Signatures and an SHA3-512 Hash-Commitment Post-Quantum Hedge
G. Treasury, Settlement & Federation
Claims 083-094Dual-Side Federation Border Enforcement
Departure-Side and Arrival-Side Policy Choreography for Cross-Cell Value Release in a Sovereign Federation
Oracle-Priced Stale-Fail-Closed Settlement Firewall
USD-Denominated Drawdown Caps for a Federation Bridge, Backed by a Priority-Ordered Oracle / Static-Override Pricing Layer That Fails Closed on Stale Data
Genesis-Pinned Domain-Separated Hybrid Authority-Key Custody
Deterministic Derivation of Classical and Post-Quantum Signing Subkeys From a Single Custodied Master Secret, Verified On-Chain Against a Key Pinned at Genesis
Non-Custodial Atomic Multi-Leg (DVP/PVP) Settlement
Per-Leg Compliance Atomicity, Re-Verified Beneficiary Binding, and Fee Assessment Deferred Until Ledger Finality
AI-Driven Predictive Liquidity Rebalancing
Off-Chain AI Stablecoin-Need Forecasts Executed as Market-Impact-Scaled On-Chain Batches, Paired With FIFO/LIFO/HIFO/Specific-Lot Tax Optimization and Wash-Sale Enforcement
Rebate-as-CAC Token with Cliff, Non-Transferability and Par-Value Attestation
A Customer-Acquisition-Cost Credit Issued as a Locked, Non-Transferable Token With Attested Par Value and a Post-Launch Vesting Cliff
Dual-Signed Fail-Closed Runtime License Token
A Short-TTL, Hybrid Classical/Post-Quantum-Signed Entitlement Token That Functions as a Remote Kill Switch for Software Deployed in a Customer's Own Cloud Tenant
Compliance-Corridor-Aware Settlement Routing
Selecting a Settlement Corridor and Serving Node by Jurisdictional Policy Fit and Live Health, Not Price or Latency Alone
Currency Object with Pre-Execution Genome Validation
A Regulated Monetary Instrument Deployed as a Complete Self-Describing Object Whose Every Transfer Is Validated Against Its Own Governance Genome Before Execution
Wizard-Generated Governed Monetary Instrument
A Define, Govern, Deploy, and Prove Pipeline That Turns One Configuration Action Into a Fully Wired, Publicly Verifiable Regulated Currency
Five-Vault Jurisdictional Treasury Allocation with Recovery Re-Routing
A Five-Jurisdiction Grant-Capital Allocation Engine That Reserves Against Pending Verdicts and Routes Recovered Funds Back Into Their Originating Jurisdiction's Vault
Threshold-Tiered Multi-Signer Disbursement with Foundation-Executed Settlement Webhook
Escalating Multi-Signer Authorization Requirements by Disbursement Amount, With the Platform Signaling — Never Executing — the Transfer
H. Trading, DEX & Market Integrity
Claims 095-107MEV-Protected Transaction Execution via Commit-Reveal
Bonded Commit-Reveal Ordering with an Authorized-Executor Allowlist for Front-Running-Resistant Trade Settlement
VRF Batch Auction Shuffling with Reproducible Fisher-Yates Ordering
Seeded Fisher-Yates Randomization of Batch Intents that Decouples Fill Sequence from Submission Time
Deterministic VRF-Shuffled Batch-Auction Clearing
Bounded Iterative Price Discovery, Oracle-Band Clamping, and Per-Intent Limit/Slippage Filtering Over a VRF-Shuffled Batch
Adaptive Market Making State Machine with Hysteresis Thresholds
A Four-State Market-Integrity Machine with Asymmetric Entry/Exit Thresholds and Minimum Dwell Times
Entity Toxicity Scoring Across Five Behavioral Dimensions
A Weighted Composite Score Built From Edge Capture, Win Rate, Flow Direction, Cancellation, and RFQ Reliability
Sybil Cluster Detection via Multi-Signal Correlation
100-Millisecond Timing Buckets Scored on Timing, Size, and Pool-Pair Overlap Correlation
State-Aware Trade Routing with Deterministic Precedence Chain
Venue Precedence Between AMM, RFQ, and Time-Weighted Execution Derived Deterministically from One Shared Market State
Three-Tier Cryptographically-Scoped AMM Control Authority
Autonomous On-Ledger Rules, a Signed Self-Expiring Risk Engine, and Multisig Human Governance Restricted to Halt/Resume
Real-Time Sybil/Toxic-Flow Clustering Integrated Into an AMM's Risk-Control Layer
Closing the Loop From Raw Order-Timing Correlation to Enforced, Self-Expiring Throttles Without Human Intervention
Non-Custodial AI Trading Agent Vault with Hard-Coded Risk Constraints and Drawdown Circuit Breaker
Trade Execution Authority Without Any Withdrawal Path, and a High-Water-Mark Drawdown Breaker Embedded in the Trade-Execution Path Itself
Weight-Curve-Selectable Liquidity Bootstrap Pool Engine
Linear, Exponential, Logarithmic, and Step Weight-Interpolation Shapes, Each Bid Gated by a Real-Time Compliance Check
Institutional Derivatives with Protection-Fund-Backed Portfolio Margin
Net Counterparty Exposure Backed by a Share-Accounted Fund Under a Rolling-Epoch Drawdown Cap, Gated by Tiered Signed Risk Authority
Token Factory with Programmable Compliance DSL
Declarative, Per-Token Compliance Configuration Evaluated Fail-Closed by a Shared Engine on Every Transfer
I. Identity & KYC/KYB
Claims 108-116Biometric Proof-of-Humanity with On-Device ZK Uniqueness Proof
Multi-Modal On-Device Biometric Capture, Zero-Knowledge Uniqueness Proof, and a Soulbound Non-Transferable Humanity Token
Bank-Fingerprint UBO Chain Detection via Recursive Entity Resolution
Normalized Bank-Account Fingerprinting Combined with Recursive Ownership-Graph Traversal for Coordinated-Entity Fraud Rings
Premise-Business Compatibility Rule Engine
Street-View-Derived Premise Features Cross-Checked Against a Versioned Business-Type Compatibility Rule Library
AccreditedID with ZK Source-of-Funds Threshold Proof
Zero-Knowledge Disjunction Proof Over SEC Rule 506(c) Accreditation Thresholds, Sealed Under a Byzantine Fault-Tolerant Quorum Signature
Wallet Asset Intelligence: Reverse Cross-Chain Trace to Off-Chain Asset Discovery
Multi-Chain Transfer-Graph Tracing with a Funding-Rail KYC Pivot to Off-Chain Recoverable Assets
Multi-Severity Bad-Actor Registry with Due-Process Inclusion and Escalation
Three-Tier Cross-Foundation Registry with Statutory Escalation Periods, Notice-and-Response, and Council Vote
Cross-Engagement Bad-Actor Recidivism Registry
Cross-Engagement Recidivism Tracking with Atomic Promotion and Severity-Scored Alerting
Self-Healing Smart Contract System
Anomaly-Class Detection, Auto-Pause, and Governed Remediation for On-Chain Smart Contracts
Self-Healing Contracts with Templated Auto-Approval and Multi-Voter Veto Governance
Known Vulnerability Classes Auto-Approve After a Timelock; Novel Vulnerabilities Require Multi-Voter Governance; a Veto Reaches Even Post-Auto-Approval Fixes
J. Fraud, Waste, Error & Abuse Detection
Claims 117-138 · New verticalMulti-Graph Fraud-Ring Detector with Combinatorial Linkage-Agreement Scoring
Union-find merging of four independently-sourced evidence graphs into a discrete linkage-agreement confidence matrix, where cross-registry disagreement is itself treated as a fraud signal
GLBA-Compliant Bank-Signatory Overlap Detector via One-Way Fingerprinting
HMAC-SHA-256 fingerprinting of routing and account numbers at ingest, with immediate destruction of the raw data, to detect the same human signatory across nominally unrelated entities
Physical-Premises-Capacity ("Volume Impossible") Fraud Detector
Multi-source premise classification cross-referenced against a versioned business-type volume ceiling, firing when claimed billing volume exceeds what a physical location could plausibly support
Agency-Published-Baseline-Calibrated Fraud Confidence Factor
A fraud-confidence multiplier scaled by the officially published improper-payment rate for the specific federal program under review, with the source document captured into the evidentiary chain
In-House Deterministic Wallet Clustering with Custodian-Exclusion Guards
Deterministic on-chain heuristics for Bitcoin and account-model chains, hard-guarded against exchange and custodian hot wallets ever becoming false cluster pivots
Confidence-Gated Automatic Legal-Subpoena-Target Generator
A BFS counterparty crawler that auto-drafts subpoena language for attributed custodians and explicitly refuses to recommend legal process for unattributed addresses
Deterministic Non-LLM Explainability Layer with Per-Signal Regulatory Citation Binding
Pure template functions keyed by signal ID - deliberately never an LLM - with a lookup table that auto-attaches the specific statutory citation behind each triggered signal
Billing-Lineage-and-Compliance Unified Cryptographic Attestation
Atomically claims a unit from a prepaid-grant billing pool before running fraud checks, then binds the billing lineage into the same signed attestation as the compliance verdict
Cryptographically-Bound Vendor Check-Profile Subsetting
Vendors pin a named allow-list of check IDs per settlement type; both the checks that ran and those explicitly skipped are folded into the signed attestation payload
Enforce-When-Provisioned Hardware-Rooted Trust Escalation for Fleet Event Signing
Trust enforcement turns on automatically and irreversibly the moment a trusted-pubkey set or hardware root is configured - rejecting unsigned envelopes from that point forward with no flag to re-loosen it
Per-Transaction Harvest-Now-Decrypt-Later Risk Score
Classifies transport ciphers as classical, hybrid, or post-quantum and combines that with the declared data-retention window into a real-time, per-transaction quantum-harvest exposure score
ZK-SNARK Regulatory-Eligibility Proofs in a Real-Time Transaction Verdict
Groth16 Zero-Knowledge Proof Verification of Accredited-Investor, Sanctions-Clean-UBO, and Non-Sanctioned-Jurisdiction Status Folded Into an Aggregate Compliance Score
Weighted Cryptographic-Agility Scoring with Hybrid-Mode Discount
Per-Transaction Post-Quantum Cryptographic-Posture Scoring Combining Vulnerable-Algorithm Fraction, Unknown-Algorithm Fraction, and a Hybrid-Mode Credit
Unified Cross-CBDC Programmable-Money Compliance Attestation
Vendor/Central-Bank-Agnostic Normalization of Wallet-Status, Programmable-Restriction, Bridge-Integrity, and Velocity Rules Across Heterogeneous CBDC Rails Into One Compliance Signal
Cross-Rail Aggregate Structuring Detector
Detecting CTR-Threshold Evasion When Combined Spend Across ACH, Wire, Card, and Instant-Payment Rails Exceeds the Reporting Threshold Even Though No Single Rail Does
Corridor-Adaptive Correspondent-Chain Hop-Count Anomaly Detector
Live p90/p99 Correspondent-Chain-Length Baselines Computed Per Origin-Destination Corridor, With FATF List Short-Circuits
SWIFT gpi Instructed-vs-Actual Chain Diffing with Full-Entity-Chain Sanctions Screening
Comparing the Correspondent Chain Declared at Wire Initiation Against the Actual SWIFT gpi-Tracked Chain, and Screening Every Entity in a CIPS Participant Chain Rather Than Only Direct Counterparties
Real-Time Trade-Based Money Laundering Detection with Live Commodity-Price Cross-Reference
Ratio of Invoiced Trade Value to a Live Commodity-Reference Price, Amplified by High-Risk Corridor Pairing and Duplicate Trade-Instrument Reuse Detection
Monotonic-Acceleration Detector for Pig-Butchering/Romance-Investment Scams
Flagging a Sender-to-Wallet Relationship Where Every Successive 90-Day Transfer Is More Than 20% Larger Than the Last, Independent of Any External Wallet Blocklist
Bust-Out Fraud Detector Correlating Credit-Bureau Delta with Real-Time Wire Settlement
Escalating a Real-Time Payment Decision When a Large Wire Follows a Rapid Credit-Utilization Jump, Fusing Credit-Bureau Behavioral Data With Live Payment-Rail Decisioning
Biometric-Hash-Reuse-Across-Identities Deepfake Detection
A Collision-Based, Non-Classification Deepfake and Credential-Sharing Signal: Flagging When One Biometric Hash Is Associated With More Than One Claimed Entity Identity
Amount-and-Channel-Gated AI Voice-Deepfake Fraud Check
Activating Deepfake-Confidence, Voiceprint-Match, and Call-Metadata Scoring Only for Voice-Authorized Transactions Above a $100,000 Threshold
K. Evidentiary & Litigation-Support Infrastructure
Claims 139-154 · New verticalDual-Layer Independently-Enforced Legal Hold Across Application and Storage Tiers
Two components that never trust each other - an application-tier hold service and a storage-tier WORM daemon that re-derives hold status from its own table on every delete call
Per-Entity Sharded Hash Chain with Ordering-Enforced CAS-Before-Chain-Advance
One independent hash chain per (tenant, subject-entity) pair, with raw event bytes durably stored before the chain-head-advancing transaction is ever permitted to open
Self-Disclosing Completeness Report Cryptographically Sealed Inside an Evidentiary Bundle
Completeness and exception findings written into the manifest before it is hashed and signed, so the seal attests both the evidence present and exactly what is missing
Immutable Bundle Regeneration Lineage with Deterministic Cached Cross-Version Diff
Regeneration never mutates a sealed bundle - always a new, independently sealed child linked by a lineage pointer, with cross-version diffs cacheable because both endpoints are cryptographically frozen
Capability-Dropping Filesystem-Immutable-Bit Two-Actor Write Protocol
A designed protocol splitting the network-facing write daemon from the one OS capability capable of ever un-sealing a WORM object
Derived-Artifact Redaction Preserving the Original Hash-Chained Blob
Redaction as a forking operation, never an in-place edit - a new independently addressable object with an explicit lineage pointer back to the untouched original
Reversible-Suppression Right-to-be-Forgotten on an Append-Only Ledger
Erasure as a reversible per-row visibility flip, uniformly enforced across every access surface, without ever mutating the underlying hash chain
Deterministic One-Way PII Obfuscation with Latent Re-Identification-Attempt Detection
A deliberate hardness-for-auditability tradeoff: deterministic obfuscation enables detecting reintroduced personal data without ever storing or comparing plaintext
Two-Point Legal-Hold Interdiction of Data-Subject Erasure with Race-Window Closure
Legal-hold status checked at eligibility and again immediately before execution, each unioning two independent hold-attachment mechanisms, to close the gap between request and execution
Destruction Certificate as a Chain-of-Custody Event Bound to a Data-Rights Request
Reusing a general-purpose chain-of-custody event type as the substrate for a privacy-specific destruction certificate, bound back to its originating erasure request
DSAR Export as Transparency-Annotated, Suppression-Aware Archive Assembly
A data-subject export pipeline that reuses the live portal's own visibility predicates and discloses the count and reason for every withheld record inside the archive's own sealed manifest
Self-Verifying Legal-Production Export
Signature-embedded Concordance and Relativity packaging that lets any recipient - entirely outside the issuer's custody - independently verify a production's integrity with standard litigation tooling and no callback
Ledger-Hash-Bound Webhook Notifications
Outbound notifications that embed the event ledger's own tamper-evident envelope hash, captured at enqueue time and preserved unchanged across retries
Evidentiary-Aware Multi-Standard Normalization Layer
X12, HL7v2, NCPDP, and FHIR convergence onto one canonical schema through a strict three-timestamp model, verbatim raw-segment preservation, and a reversible placeholder-identity convention
Immutable Decision-to-Specific-Rule-Version Binding
Temporal citation binding: every rule edit produces a new content-hashed rule-version record, and every decision is bound to the specific version it actually relied on
Confidence-Gated Bidirectional Graph Traversal Over a Relational Evidentiary Store
Multi-source, bidirectional breadth-first traversal expressed as SQL over a relational store, excluding low-confidence relationships from the walk itself and bounding investigative blast radius with hard node and depth ceilings
L. Platform & Infrastructure
Claims 155-157Secure Document Vault with Client-Side Encryption and Revocable On-Chain Access Grants
Documents encrypted entirely on-device before transmission, persisted on decentralized storage, anchored with an on-chain provenance record, and shared through revocable per-recipient key-exchange grants
Tiered Source-Escrow Sovereign Stack Deployment with In-Country Validator Cohort
A deployment template binding perpetual source license, third-party source-code escrow, and an in-country validator-cohort requirement scaled by tier, so continuity and jurisdictional sovereignty survive vendor exit
Continuously Re-Examined Certification with the Policy Engine as Examiner
Deployments are graded against a published standard by the same engine that enforces it in production - scores are continuously re-evaluated, cryptographically anchored, and publicly resolvable