COTRUGLITECH
Cotrugli Ledger · Proving Ground

Twenty ways to attack it. Twenty declared outcomes.

Anyone can demo the happy path. The interesting question is what a system does when someone alters a document, forges an approval, withholds a quorum, or lies about an anchor. So the proving ground declares the outcome of each attack in advance — and then proves the system behaves exactly as declared. Where we were wrong, the row would say so.

Launch the live demo →
The demo asks for a username and password. We issue those directly — ask us for access.
Don't trust us — verify.

What it is

One seed, the whole business stack, end to end.

A single fixed seed drives the entire stack through the real modules — not mock-ups of them: membership, a service agreement co-signed by two parties, delivery, an invoice, a dispute, the routing of that dispute to the right tier, a resolution reached by several signers, an anchored root, and finally verification performed offline.

Because the seed is fixed, the run is deterministic. You can reproduce it, and so can anyone who doubts it.

Around that golden path sits the scenario matrix: twenty attacks, each with an outcome written down before the run, each row proven against its own declaration.

What you can check yourself

The intact package — and its tampered twin.

Both are downloadable. The verifier re-runs live when you click: valid for the intact package, invalid for the twin, with a named reason. A tool that cannot tell the two apart is not a verifier, it is a decoration.

You are not required to run it here, either. Take both packages, check out the verifier clean, and run it yourself — which is the only version of this claim that should ever convince you.

01

The golden run

Membership to anchored root to offline verification, driven end to end through the real modules.

02

Twenty declared attacks

Altered documents, forged approvals, missing quorum, a lying anchor, a failed key store, statutory holds, duplicates.

03

The tampered twin

Download both packages. Watch one verify and the other fail with a reason. Then do it yourself, offline.

The scenario matrix

Twenty attacks, each outcome declared before the run.

Four scenarios walk the lifecycle; thirteen are attacks; the rest exercise idempotency and release. Every row states its expected result up front, and the run proves the system matches it. A failure is explicit and machine-readable — silent fallback, pretending all is well, is forbidden by design.

CodeScenarioDeclared outcome
NSBX-01Complete flow, no disputePasses · VALID
NSBX-02Flow with complaint and valid resolutionPasses · VALID
NSBX-03Third-party release with valid approvalAllowed · logged
NSBX-04Mutual retirement, conditions metErased · proof survives
NSBX-05Document changed after signingRefused · nothing stored
NSBX-06Evidence hash rewrittenVerification fails
NSBX-07Missing counterparty signatureRefused
NSBX-08Well-formed but cryptographically invalid approvalRefused
NSBX-09Unsupported suite or contract versionRefused · fail-closed
NSBX-10Unknown member attempts a governed actionRefused · audited
NSBX-11Suspended member attempts a future actionRefused · audited
NSBX-12Unapproved third party requests releaseRefused · audited
NSBX-13Resolution without the required quorumDoes not exist
NSBX-14Unilateral retirement attemptRefused · needs two
NSBX-15Retirement under statutory holdRefused · never in-app
NSBX-16Audit-history tamperingDetected
NSBX-17Key service unavailable mid-operationFail-closed · no insecure path
NSBX-18Write accepted but finality unconfirmedNot reported as success
NSBX-19Reviewer unavailable / timeoutBounded failure · logged
NSBX-20Duplicate / replayed submissionIdempotent · no double effect
Green — permitted or valid. Red — refused or failed verification. Amber — bounded, fail-closed states (holds, outages, unconfirmed finality). Each row also carries an explicit reason code in the run output.

What this does not claim

We don't sell trust us. We sell check for yourself.

Infrastructure that oversells itself is worse than none, because people rely on it for things it was never built to do. So, plainly:

Experimental and local — assurance, not certificationThis is a proving ground, not an accredited assessment of anything.
The anchor here is self-attestedIn this demo mode there is no external witness. The anchor proves internal consistency, not that a third party saw it.
Referenced is not verified · Anchored is not settledA record being pointed at is not a record being checked, and a record having a place in history is not money having moved.
Verified is not business successThe cryptography can be flawless while the deal underneath it was a bad one. That judgement stays with people.
Everything here is syntheticThe keys, the actors and the documents are all invented for the exhibit.

Declare the outcome first. Then prove it.

Twenty attacks, twenty declarations, and an evidence package you can carry off and check on your own machine without asking us anything.

Request access