Every gated decision reports its attack class (wrong payee, lookalike, duplicate invoice, over cap, out of scope) and, from client 0.1.19, the order-of-magnitude band of the amount and how far a deny sat above the cap. Never the amount itself: enums by construction, so the corpus gains a loss-distribution shape without ever touching PII. Live and public at api.fidacy.com/v1/pulse.
Our public metrics are snapshotted weekly, hashed, and anchored to the Bitcoin blockchain on the same chain as every verdict. Tenure stops being a claim: re-hash any snapshot at /v1/transparency/snapshots and check it against the public verifier. A competitor starting later can never have an older anchored history, by construction.
Labeled cases feed an eval loop; aggregate calibration (accuracy, cost-weighted error, fail-safe direction) is published at /v1/transparency. Errors are weighted so approving-what-should-deny costs most: the error direction an underwriter wants.
Structured failure-mode testing, run on every release as a blocking CI gate. Labeled for what it is: a lab result, complementing the field corpus the way a crash test complements accident statistics.
Read this honestly: the field corpus is young and the severity bands started accruing with client 0.1.19. What we bring today is an installed control sensor, a failure taxonomy, a control-level compliance mapping (machine-readable) and an architecture where each published number is checkable rather than asserted. If underwriting needs operational telemetry, this is the layer that produces it.
The market says this layer has to exist. It's running, self-serve: spin up your org, connect an agent in one MCP install, and verify the verdict yourself. No sales call.
The payment is denied. Fail-closed, in every adapter and in the engine itself.
Start with the local firewall. Hosted signed verdicts use volume pricing from $0.04 per verdict. Full pricing →
Built by Lucas de Lima and team. Meet the team →