The platform

The trust layer for claim evidence.

CapSeal decides whether a piece of claim evidence can be trusted - at the moment it's captured, not weeks later under a forensic microscope. Five components turn a raw photo into an auditable payment decision, and every one is built to be verified independently.

Architecture

Five components. One decision.

CapSeal is not "C2PA signing" - that part is a free, open standard we stand on. The product is the four layers the open standard doesn't give you, plus a clean hook into deeper intelligence.

1

Capture integrity

The core IP. We prove a real lens saw a real scene - defeating screen-of-screen replays, injected virtual-camera feeds, and rooted or hooked devices. Open libraries sign whatever the camera hands them; we guarantee what the camera hands them is real. Adversarial, insurance-specific, and continuously hardened against new attacks.

CORE IP
2

The verdict engine

Turns a raw seal and its integrity signals into an insurance decision - tuned per line of business, with graceful handling of no-secure-chip phones, offline capture, and legacy uploads, so honest claims are never blocked by a technicality. Deterministic and auditable, never a black box.

3

The verification network

A sealed capture, verifiable across insurers, repairers and reinsurers - so one loss can't be monetised twice. Privacy-preserving by design: salted entity hashes and private set intersection let a carrier learn "this evidence was already sealed elsewhere" without either side exposing customer data.

DURABLE MOAT
4

Proof-carrying decisions

Every verdict ships as a signed, replayable proof object - a chain from raw inputs through each check to the conclusion. Your engineers, your auditors, a regulator or a court can re-verify it offline. Explainability is structural, not a bolt-on report.

5

Intelligence hook

The seal proves the evidence is real; it does not read intent. Every verdict feeds a downstream entity-graph engine (AEGIS) that answers the harder question - is the claim itself honest? Provenance for the evidence, intelligence for the intent.

Capture to decision

How a claim flows through

01

Capture

Claimant photographs damage inside your existing app, powered by the CapSeal SDK.

02

Seal

Signed on-device by the phone's security chip - bound to device, time and place before anything can touch it.

03

Verify

The verify service checks the seal, runs anti-spoofing, and emits a proof object.

04

Decide

The verdict engine applies your policy and returns one class into your workflow.

Output

Three verdicts, mapped to your workflow

CapSeal returns a verdict class, not an opaque score - so payment-without-review is reserved for evidence that can prove itself.

ATTESTED-GENUINE

Auto-pay

Hardware-attested, unaltered, integrity checks clean. Safe to settle straight through - the honest majority.

UNVERIFIED

Review

No seal, legacy upload, or a phone with no secure chip. Routed to your normal review - never auto-rejected on a technicality.

TAMPERED / SYNTHETIC

Reject or investigate

Seal broken, spoof detected, or generation artefacts present. Held back before payout, with the proof to defend the decision.

See the platform on your own claims.

Bring a sample from one line of business. We'll run it end to end and show you the verdicts and the proofs.

Request a pilot Read the docs