Atestan Atestan

Evidence has boundaries

Atestan is designed to make claims narrower, not broader. A proof system is useful only if its limitations are explicit — so they are the specification, not a footer. Each one below holds whoever is reading, including us.


01

Security & limitations

Nothing here establishes that a person is the legal representative

A face check with liveness proves a living human matches a document. The link between that human and the organisation’s mandate is declared by the organisation, and no path in this system controls the declaration. The only wording we are permitted to use about that check says declared, and it is held in one place so it cannot drift — naming the hole does not close it. This is the very thing the product exists to address, standing at the product’s own door.

02

What we never claim

A proof product that overstates itself has already lost. These are not disclaimers buried in a footer — they are the product’s specification, and they hold whoever is reading.

  1. “Unverifiable” is not “fraudulent”

    Absence of proof is not proof of fraud. A message from an issuer we do not cover is shown as not covered — amber, never an accusation.

  2. A compromised issuing authority is a real limit

    If an attacker truly compromises an organisation’s issuing authority, Atestan can prove the communication was cryptographically authorised. It cannot, on its own, tell you the human operator was compromised. Authentication of identity is not legitimacy of the act.

  3. We do not make you compliant

    Atestan strengthens integrity, authenticity and non-repudiation properties. Regulatory compliance remains a property of your whole system, and we will not tell a regulated buyer otherwise.

  4. We do not move your liability

    No proof shifts a company’s legal responsibility onto its recipient, and financial institutions keep theirs under PSD3/PSR and DORA. We say “independently verifiable and exportable proof”, and we will not use stronger legal language until a payments lawyer has cleared it.

  5. Not post-quantum end to end

    One internal primitive remains classical. It is written down, it is on the register, and it is one of the questions we are putting to an external cryptographer.

  6. Never a rung higher than reached

    The interface shows the rung actually established. When a rung stays dark, it says why — as you just saw in the demonstration.

  7. Not yet independently ratified

    The engine is built, tested against independent reference implementations, and reproducible. It has not yet been ratified by an external cryptographer, and there has been no external security audit. Until both have happened, we say exactly this.