HOW VERIFICATION WORKS
A record you can check
without trusting us.
Most “verified” badges mean a company looked and said yes. Ours means the question was sealed before the evidence, the verdict can be replayed, and the chain is anchored where we can't touch it.
RECEIPT · 21 ENTRIES
CHAIN VERIFIESCHAIN HEAD · ANCHORED
53518f1d…6c5d · public ledger
EIGHT MECHANISMS, ONE CHAIN
In the order the record is built
Each entry is hash-linked to the one before it. Nothing can be judged against evidence that came later. Open any step for what you can check yourself.
01Criteria sealed firstCRITERIA-LOCKED · seq 0002
Every criterion must name an observable outcome and the proof that settles it. The set is hashed and sealed before any evidence exists.
WHAT YOU CAN CHECK
The criteria seal has a lower sequence number than every capture after it.
CRITERIA-LOCKED · seq 0002
6 lines · provable
sha256 6c85…1b9b
no evidence yet
02Capture bound to its criterionCAPTURE · seq 0007
Each photo, reading, or demo is signed on the device, addressed to one criterion, and stamped against that criterion's capture window. Late or misaddressed is sealed as exactly that.
WHAT YOU CAN CHECK
Every capture shows its device signature, its criterion, and whether it landed in the window.
CAPTURE · seq 0007
line 3 · window 07:30–08:15
signed on device · 07:41
seq 0011 — capture-window-missed
03The referee's question is sealedVERDICT · seq 0010
The referee sees a fixed bundle: criterion, evidence, instruction. It is hashed before the model runs, and the verdict cites the frames it relied on.
WHAT YOU CAN CHECK
Replay the same bundle and you get the same hash.
VERDICT · seq 0010
question sealed · 1f58…0d88
line 1 — met · 6 frames cited
replay matches
04When unsure, it refusesREFUSAL · seq 0012
"Not assessed" is never a pass. If the evidence can't settle a criterion, the referee says so with a code from a published register, and the milestone waits.
WHAT YOU CAN CHECK
Every refusal is a sealed entry with a code you can look up.
REFUSAL · seq 0012
line 3 — not assessed
modality-cannot-establish · v6
asks for a load-test report instead
05One chain, re-verified before releaseRELEASE CHECK · seq 0019
Every entry is hash-linked to the one before it. A release fires only if the whole chain still recomputes; if any byte changed, the money holds.
WHAT YOU CAN CHECK
Recompute the chain from entry one. If it matches the head, nothing was altered.
RELEASE CHECK · seq 0019
19 entries · recomputed
head fe6f…1ca5 = anchored
release signed
06Anchored on a public ledgerANCHOR · public ledger
The chain head is written to a public ledger Northn doesn't control. Only the digest travels — no content, names, amounts, or media.
WHAT YOU CAN CHECK
Find your receipt's chain head in the public anchor. No need to ask us.
ANCHOR · public ledger
digest fe6f…1ca5 · published
no content leaves
northn.dev/verify
07Rules ship as editionsRULEBOOK · edition
The criteria grammar, refusal register, and capture policies are versioned and anchored. A rule change is a new edition, never a silent edit.
WHAT YOU CAN CHECK
Every verdict names the edition it was ruled under.
RULEBOOK · edition
criteria grammar · ed. 2026-07
refusal register · v6
edition digest anchored
08Some verdicts need no modelREADING · no model
A reading against a tolerance band is settled by arithmetic on the record. A unit the criterion didn't name goes to a person, never a conversion. AI agents leave an execution trace with the same seal.
WHAT YOU CAN CHECK
Band, reading, comparison — all on the seal. Recompute it yourself.
READING · no model
band 380–420 cfm · read 402.5
holds — by arithmetic
psi vs kPa — sent to a person
ONE RECORD, END TO END
What a receipt actually looks like
A $9,500 software milestone with six criteria. Every hash below recomputes.
- LEFT
The chain — 21 entries in order
1 refusal, one release. Amber is a hold.
- RIGHT
The receipt for the chain head
Root, signature and the public anchor it was written to.
- CHECK
Recompute it in your browser
Paste the JSON on /verify or download it and run your own.
THE CHAIN · 21 ENTRIES
Sprint 2 — Payments API
Meridian Freight Systems · software
- 0001baca08…a5cf
Engagement created · firm
- 00026c858e…1b9b
Criteria sealed · 6 lines
- 00037a8f7b…e765
Sent to client
- 00044d7afd…a7f6
Client access issued · client
- 00056a1ffc…7640
Client accepted the terms
- 0006c16682…6463
$9,500 funded · release on human approval
- 00075ecebb…a784
Capture window set for the demo
- 0008bff5ce…d296
Capture · sprint2-demo.mp4
- 0009db080b…f2e5
Capture · payments-api-test-run.log
- 0010d1d62c…f0a3
Verdict · met · vision-referee · 6 frames cited
Frames 2 and 5 show the 201 response with `idempotency_key` echoed; the request body at frame 1 carries the same key.
- 0011789976…7297
Verdict · met · document-referee
Log lines 412–419: second POST with key `idk_7f3a…` returns the original payment id `pay_01J…` with status 200 and no new charge row.
- 00128f96a1…e884
Refused · modality-cannot-establish
A demo recording cannot establish a p95 latency figure over ten minutes at 200 rps.
- 0013516168…187c
Capture · k6-load-report.html
- 00146b1d77…3d54
Verdict · met · document-referee
Report summary table: 200 rps sustained 10m00s, p95 = 212 ms, p99 = 288 ms. Threshold in the criterion is 300 ms.
- 0015c41e6b…4741
Verdict · met · document-referee
Log lines 588–591: refund of 12,000 against a 9,500 payment returns 422 with `error.code = refund_exceeds_original`.
- 00160cacbd…8c0a
Verdict · met · document-referee
Log lines 640–702: three delivery attempts at 2 s, 4 s, 8 s; each carries an `X-Signature` header; the tenant secret id matches the config dump at line 88.
- 00179e3d22…1a74
Verdict · met · vision-referee · 3 frames cited
Frames 9–11 show the audit table with one row per transition (created → authorized → captured), each with actor and ISO timestamp.
- 0018001d39…1337
Client approved
- 0019fe6ffe…1ca5
Released · $9,500 · chain recomputed first
- 0020b0e2a1…c6c8
Client review · 5/5 · payor credential
Fact panel computed from the chain and sealed with the review
- 002153518f…6c5d
Talent credential published · countersigned
HEAD · SEQ 21
53518f1db8…6c5d
RECEIPT · CHAIN-HEAD
northn/chain-head@197e07ff0-38ea-4dd3-abcb-a49a180afb9d
anchored after release at seq 19 · Jun 19, 2026
- Fields hash to the root · 5 salted leaves
- Ed25519 signature verifies · northn-dd7f74bee6566680
- Head matches the chain · seq 19
MERKLE ROOT
179025047cc32692f225fa91e74bbedba34fdeb11ad49002a56a7e30a5bbfd9c
PUBLIC LEDGER
illustrative coordinates- entry
- #2731
- anchored
- 2026-06-19 18:05:18 UTC
- status
- confirmed
WHAT IS ON THE LEDGER▾
{"id":"97e07ff0-38ea-4dd3-abcb-a49a180afb9d","kid":"northn-dd7f74bee6566680","root":"179025047cc32692f225fa91e74bbedba34fdeb11ad49002a56a7e30a5bbfd9c","sig":"V+z999HoSMV4a2xmw6lFKKkvUtiVYnwR5nGGyRbPuGno5xcFcdElqaemcygzR629mbIvosDRoDZ4kh7f5UPBBw==","t":"chain-head","v":1}Root, signature, key id. No names, amounts, or content.
THE RECORD FOLLOWS THE PERSON
The same receipts become a track record
The Sprint 2 release above is the credential on the right — issued by the firm, published with the person's consent, checkable by a hiring manager without a phone call. Firms carry the same record.
How firms and people carry the recordTALENT RECORD · app.northn.dev/t/r-okafor-k4m2
Rina Okafor
Backend engineer — payments APIs, integrations, reliability
3
firms
12
milestones released
55
criteria met
89%
first pass
- COUNTERSIGNED
Checkout SDK v2
Northwind Labs · Jul 2026 – Aug 2026
- Milestones
- 3/3 released
- Criteria
- 14 met · 88% first pass
- Evidence
- 52 · 49 attested
- COUNTERSIGNED
Sprint 3 — Reconciliation service
Halvorsen Digital · Jun 2026 – Jul 2026
- Milestones
- 2/2 released
- Criteria
- 9 met · 90% first pass
- Evidence
- 41 · 39 attested
- COUNTERSIGNED
Sprint 2 — Payments API
Halvorsen Digital · Jun 2026
- Milestones
- 1/1 released
- Criteria
- 6 met · 86% first pass
- Evidence
- 3 · 2 attested
5 credentials · published with the person's consent
Verify one →THE SAME CHAIN, THREE RECORDS
A milestone, a run sheet, a certificate
Paid work releases money on the record. Record-only products stop at the seal. Same chain either way.
PAID WORK
A software milestone
- 0001Criteria sealed — 6 lines
- 0002Demo captured · frames cited
- 0003Verdict replayed — hash matches
- 0004$9,500 released on approval
For software firms →
RECORD ONLY · NORTHN BENCH
A lab run sheet
- 0001Protocol steps sealed — 6 lines
- 0002Run 1 start — inside its window
- 0003Curve R² posted by the plate reader
- 0004ALCOA+ export verifies offline
For labs and CROs →
RECORD ONLY · NORTHN STUDY
An authorship certificate
- 0001Consent sealed — first entry
- 0002Composition sealed as it happened
- 0003AI assist disclosed on the ledger
- 0004Certificate verifies in a browser
For schools and integrity offices →
STRAIGHT ANSWERS
What a skeptic asks first
Do I have to trust Northn to trust the record?
No. Recompute the chain from your receipt and check the head against the public anchor. The referee's verdicts replay the same way.
What stops criteria changing after the work?
They're sealed as the first entry. Any later edit gets a different hash and a later sequence number — the record shows it happened.
What happens when the AI isn't sure?
It refuses, with a named code. "Not assessed" is never a pass, and the milestone waits for more evidence or a person.
Does AI move the money?
No. Money moves only on a trigger both sides agreed to up front — and only if the record still verifies. Funds sit with regulated financial institutions, never Northn.
Holding a Northn receipt?
Check it. Don't ask us.
Paste the file and your browser recomputes every hash. Or look up the receipt ID and read the ledger. No account, no login.
WHAT LEAVES THE PLATFORM
- Digests of the record, anchored publicly
- Never content, names, amounts, or media
- Release instructions name the milestone — no work content