Atestan Atestan

From a published policy to a decision backed by evidence

The model starts before the critical request is acted upon. Published policy, then sealing, then the recipient, then examination, then the business decision. Each step answers one question and hands the next one a fact rather than an impression.


01

How it works

  1. 1 · Start with the published policy

    The organisation publishes which categories of request it says it always seals. A recipient should not have to trust the request itself in order to discover what the sender’s policy is — so the policy is readable on its own.

  2. 2 · Seal the request — who sealed it

    When a covered request is issued, the organisation creates evidence bound to that request. The purpose is to establish the organisational authority behind the seal — not to claim that everything which follows has already been proved.

  3. 3 · Resolve the intended recipient — for whom

    A different question from who sent it. The recipient is part of the evidence rather than an address that happens to appear in a message — so a valid request does not simply become reusable by whoever obtained a copy of it.

  4. 4 · Examine the evidence, level by level

    The verifier does not turn the process into a binary green-or-red judgement. It reports what the available evidence establishes at each level, and never claims more than the underlying proof supports.

  5. 5 · Use a telephone channel that is genuinely independent

    Some situations still need a human confirmation. An independent channel is a number you already had — never a number supplied by the request itself. If the message says “call us on this number”, calling it is not independent verification: the attacker may control that number too. Use an existing supplier record, or a contact established before the request.

    The dictated code reveals nothing by itself

    Over the telephone, the caller dictates the code and names ONE field to confirm — an account ending, a date, an amount. What travels is a code, not the content — and the answer is: matches, or does not. The code discloses nothing on its own: it is a confirmation mechanism, not a secret that proves who is speaking. Built and tested; the service is running, and no organisation is enrolled, so there is no seal to confirm against today.

  6. 6 · The decision stays a business decision

    Atestan does not move legal responsibility onto the system, and attaching evidence to a request does not make an organisation compliant with anything. It gives the person deciding more to decide on.