Security cores · live
Don't take our word for it. Run the verifiers.
Every panel below runs Origin's real evidence engines in your browser — the same code the test suite gates. Sign a portable receipt and watch one flipped byte void it. Prove a receipt sits inside a signed Merkle batch. Bind a decision to the exact policy version it ran under. Issue a config-bound reference check from the deterministic oracle. The over-grant analyzer also has a page of its own: /over-grant.
Model proposes. Environment verifies. Gate decides. Trace proves. — All data on this page is synthetic demo data and labeled as such. A green check means "reproducible under this verifier," never "safe" or "correct." Verification is client-side; nothing is uploaded.
- Sigil signing — flip one byte and it voids
- Merkle batch — eight receipts, one signature
- Proof-carrying policy — yesterday’s decision, yesterday’s policy
- Reference check — issued by the oracle, bound to the config
- Attenuation — widen one edge, watch the blast radius move
- Over-grant analyzer — authority held vs used (full page: /over-grant)