Deterministic assurance for regulated credit

The file looked complete. It wasn't.

You have opened a folder that every earlier check called sound, and found the gap yourself, late, with your name already on it. ProofMemo reads the file on your own machine, checks every figure against the others, and hands you a dated record of what is proven and what is still missing — before it becomes your problem.

You already know the feeling

Notice how much of this you recognise.

Your book runs on a platform you do not own, and the record of your work lives in a system someone else controls.

You have gone back for the file on a deal you know you did right, and found the documents changed, or gone.

You watched a sub-aggregator collapse and pull good brokers down with it, and read your own credit-rep agreement a little differently that week.

And you know that when a file is ever questioned, the liability lands on you, and your word is worth only what you can still show.

Here is what changes the moment you run a file through it

The work you already do, done the same way every time, with a record that proves you did it.

The record is yours, not the platform's

It reads the whole file on your own machine, sixty-six documents end to end, and nothing about your client leaves the room. The record it produces is yours to keep, not your aggregator's to delete.

It finds what the eye slides past

On a live file it surfaced four identity forms with no applicant name and an unsigned declaration. Fifteen hours of manual review had called that file verified. The record does not flatter you — and that is exactly why it protects you.

It hands you proof, not a promise

A dated, tamper-evident record of what you examined and what was still missing, one you hold and can produce years later, on demand. Change one byte and the seal fails and says so, checked in any browser against a key published outside the file. When someone asks how you knew, the answer is already written, and it is yours.

Built to a standard, and measured against it in the open

Most of the industry describes its governance in a policy. We publish ours as something you can run yourself.

4,705
automated tests pass before any change ships
0
client documents that leave your machine while the file is read
19
assessment steps, each labelled by who acts and whether it touches your client's rights
no model
in the decision path — the machine records and checks, it never decides
The standards we already operate under, and the ones we are earning

A first-party declaration, under ISO/IEC 17050-1. We name what we conform to today and what we are working toward, and we hold no third-party certificate yet — because the day we claim one, it will be real.

ISO/IEC 42001 — AI management

We self-assess as conforming today on how the system runs and how its risks are managed and monitored, and we are working toward certification on the surrounding management system. Our AI System Impact Assessment is published in full.

ISO/IEC 27001 — information security

The technical controls are strong because the architecture is built for it — the file stays on your machine, sensitive data is stripped before any model, the record is signed against a key we publish outside it.

SOC 2 — an auditor's report, not a claim

SOC 2 is issued by an auditor over time, not declared. We make no SOC 2 claim, and we are working toward a Type 2 report over the hosted verification service.

See exactly how this maps to your obligations →

The next file you open can be the one you can prove.

You can keep carrying the file in your head, or you can watch the software carry it for you and hand you the receipt. Two doors, and only one of them leaves a record with your name protected on it.

Verify a record See how it helps you comply