COTRUGLI Tech · Demos · Proof of Delivery · the brief in four slides
Open the demo →
1 · The problem

When a provider reports a delivery, who checks?

A message provider reports a delivery today, and the bank takes the provider's word — backed by the provider's own database. Millions of delivery reports a day rest on that one sentence: trust our database.

1

The provider is its own witness

The report that a message was delivered comes from the same party that delivered it. Its only evidence is its own database.

2

Every dispute ends at 'trust our database'

When a bank and a provider disagree about a message, there is nothing to check. The bank has to believe, or not.

3

The evidence is personal data

A delivery report carries a phone number. A bare hash of that number looks anonymous, but it is not: there are only about ten billion possible numbers, so it reverses by brute force on a laptop and remains regulated personal data.

2 · The solution

Evidence infrastructure underneath the report

With evidence infrastructure underneath, the same report becomes a proof the bank verifies itself, offline, trusting nobody. The report body never enters the ledger, zero phone numbers travel on the wire, and erasure never destroys the proof. The bank does not get a new service. It gets a removed doubt.

The report is fingerprinted at the sourceThe provider hashes the delivery report where it is made. Only the fingerprint goes to the ledger, which receives and anchors it. The full proof bundle is about 2.5 KB and contains zero phone numbers and zero message ids.
The bank verifies alone, offlineA standalone verifier — one file, no network — recomputes every check, C1 to C9, including that the anchor proof names the receipt it actually anchors. Change one byte anywhere and the verdict fails.
Erasure keeps the proofGDPR erasure works by key destruction: the person's data becomes unrecoverable while the proof still verifies. Deletion is fail-closed — it demands a trigger reference and two different DPO approvers, and refuses anything less.
Independent witnesses, the bank's barIndependent operators co-sign the log's checkpoints. How many are required is the bank's own policy at verification time — never a claim the proof makes about itself.
In one sentence

A delivery report that carries its own evidence — checkable by the most skeptical client, without asking anyone.

3 · The value

Doubt removed, not service added

For the providerA report that carries its own evidence

Every dispute today ends at 'trust our database'. With attested delivery proofs the provider's report carries its own evidence — checkable by the most skeptical client it has.

For the bankVerification without permission

Find a message, download its proof, verify it offline. No API key to the provider's systems, no call to anyone — the proof stands or falls on mathematics.

For the person behind the numberA pseudonym that stays a pseudonym

Zero phone numbers on the wire. The reference is derived under a secret key; without the key it is just bytes, and the same number under a second provider's key gives an unlinkable reference.

For the data protection officerErasure that is real and still provable

A person's data can be made unrecoverable on request without destroying the proof that the delivery happened. Deletion refuses to run without a trigger reference and two different DPO approvers.

4 · Already demonstrated — and live in your browser

One delivery report. A proof the bank checks alone.

Four results were driven through the real evidence engine: a report becomes attested evidence, the bank verifies it offline, the person's data is erased while the proof survives, and independent witnesses are held to the bank's own bar. Then the page itself shows, on any number you type, why a pseudonym must be keyed — nothing you type leaves the page.

The one changed byte

Change one byte anywhere in the proof bundle and the offline verdict fails. Tamper detection: 7 of 7.

Erasure with the proof intact

The person's data is destroyed by destroying the key. The proof still verifies. A deletion without a trigger reference and two different DPO approvers is refused.

Bare hash versus keyed reference

Type any number. The bare hash looks anonymous and is not. The keyed reference is just bytes without the key — and a second key gives an unlinkable reference to the same number.

What is real

The four results were driven through the real evidence engine in a LAB environment on synthetic data only, with one anchor witness today; the pseudonym demonstration runs live in your browser and sends nothing anywhere.

LIVE — In-Browser Pseudonym CheckRECORDED EVIDENCE — Evidence Engine, LAB EnvironmentSIMULATED DATA — Synthetic Numbers and ReportsONE ANCHOR WITNESS TODAYHUMAN DECISION — Two DPO Approvers for Erasure

COTRUGLI Tech Proof of Delivery — the trust layer where humans and AI agents do business. Referenced ≠ Verified · the body never leaves the source · history is never rewritten.