Kronaxis Compliance Book a pilot
Consensus rule compliance gate

Provably
compliant.

One checkpoint sits in front of every regulated outbound action. The regulator aligned baseline and your own overlay both have to sign before the action can execute. The receipt is independent of us, and the regulator can rederive the verdict from scratch.

running on a four validator testnet UKGC LCCP · FCA · UK GDPR · EYFS self hosted, offline microsite
The problem in brief

Compliance today is a promise.

Regulated firms must prove every outbound message, alert, or marketing push followed the rules. In practice, what the regulator gets is the firm’s own logs, written by the firm’s own systems, reviewed long after the damage is done.

Under the UKGC October 2025 framework, FCA Consumer Duty and EU AI Act Article 12, “trust us” is no longer a defence. The fine arrives after the breach.

The gap: the regulator has no way to rederive what the firm’s system actually did before the message went out, and no way to detect a refusal that was quietly turned into a permit.
White paper · method level disclosure

Provably compliant autonomous actions. Read the full write up.

Nine sections covering the architecture, the six gate invariants (three decision time, three holding over time), the threat model, the evaluation evidence, the deployment shapes, and the honest limitations. CC BY 4.0 on the paper text; product, source code and rule sets remain closed. Published on Zenodo at DOI 10.5281/zenodo.20601300 (https://doi.org/10.5281/zenodo.20601300).

Where to go from here

Six doors. Pick the one that matters to you.

The microsite is split into six functional reads, plus the white paper above. Each is self contained and opens offline; the proof and industries pages run real cryptography in your browser.

How it works

An interactive eight chapter walk through the gate, the two rulebooks, the role typed quorum, the consensus check, freshness binding, and how the verdict turns into a receipt. Click any chapter to open the deep dive.

Read the explainer

See the proof

Pick a scenario, send a message through the gate, then recheck the proof. The browser recomputes the tamper evident receipt against real captured testnet artefacts. The six gate invariants are laid out symmetrically; the freshness binding card answers “without a real time lookup”.

Run the demo

Industries

Same gate, seven verticals: gambling, FCA debt collection, financial promotions, UK GDPR, Consumer Duty, community pharmacy, EYFS childcare. Each tab carries the actual rules modelled in its rule set, the named refusal codes, and one permit plus one refuse scenario. Gambling uses real captured proofs.

Browse verticals

Integrations

Nine egress patterns catalogued, two deployment shapes (Inline enforce vs Out of band observe), four integration mechanics (SDK, sidecar proxy, webhook, bus interceptor), and the fail CLOSED vs fail SAFE table per surface. The pharmacy cabinet and the fire egress door are not the same question.

See the surfaces

For regulators

Download a proof bundle, verify it in your browser or with the kc-verify CLI on your own machine. The six checks the verifier runs, the four residual questions the verifier does not answer, and the open source path to building the verifier yourself. Don’t trust us. Recompute.

Recompute the proof

Book a pilot

Six week, single surface, Observe only deployment against your outbound marketing channel. No card at the start. No invoice on walk away. Two binary acceptance conditions. The buyer keeps every byte of evidence. Founding rate window is open.

Read the SOW
The principle in one paragraph

Check us. Don’t trust us.

Every regulated outbound action passes one gate. The gate evaluates two independent rulebooks at consensus time: the regulator aligned baseline and the firm’s own overlay. Both must sign. The verdict and its reasons are written to a ledger the firm, the regulator and an independent auditor all see. No single party, not even Kronaxis, can wave a message through or quietly delete a refusal.

Re running the rule on a fresh machine, against the same descriptor and the same rule text, gives the same answer. The receipt’s sealed inclusion can be re computed cryptographically in your browser. That is the difference between “trust us” and “don’t trust us.”

Honest about the bounded claim
The reference embodiment runs on a four validator BFT testnet and is exercised by 26 named scenarios. The structural properties hold today: dual authority composition, the role typed quorum, the consensus enforced gate, deterministic policy replay, the refusal code taxonomy, the hash bound canonical descriptor, and the per action proof on the ledger. The operational hardening that lands at pilot is named openly: hardware backed signing keys, hardware attested signers, a client hosted layer one signer, reproducible builds, multi party validator distribution, M of N governance, a public transparency log mirror, a biometric mobile signer for human sign off, and persistent ledger state on disk. The substitution point for each item is stated on the For regulators page.