Capture
SDK and CLI
A change ships — a new prompt, a swapped model, an edited policy — and it is recorded at the moment it happens, not written up afterwards by hand.
Northwind Cipher · System-of-record for AI change
Private by default. Provable by design.
Every change your AI makes — prompts, models, policies, tool grants — captured the moment it ships, sealed with post-quantum signatures, and verifiable by anyone, offline, across any provider.
Open verifier
Instead of asking anyone to trust a claim we make, CooL emits a sealed record that software can check on its own. The verifier needs no CooL account and no network connection — it reads the receipt and the maths either holds or it doesn't.
Two of the seven domains depend on confidential hardware we have not deployed yet. They are marked sim on every receipt, in the open — never hidden, never counted as passes.
The Studio · runs in your browser
This is not a video and not a mock-up. The panel beside this text runs real SHA-256 canonical hashing, a real ECDSA P-256 signature over the digest, and a real Merkle log with real inclusion and consistency proofs — in your browser, with no server involved.
Seal a few changes. Then press Tamper and verify again: the signature still passes, because it was made over the original digest — but binding, inclusion and consistency all fail. That precision is the product.
The browser signs with ECDSA P-256 because that is what browsers expose natively. Production seals with hybrid ML-DSA-65 + Ed25519. The difference is stated here rather than glossed over.
Why now
We have no customer logos to show you yet. These are the obligations doing the pushing instead — each one a public document you can read yourself.
Requires automatic recording of events over the lifetime of high-risk AI systems. Not notes — automatic, lifetime logging.
Continuous logging, multi-year retention and independent audit, with financial penalties for gaps.
US model-risk supervision expects documented, defensible records of what a model was and when it changed.
Model-risk expectations arriving for Indian financial institutions on the same documentary spine.
Regulation mandates records and logs. It does not — yet — mandate that those records be cryptographically tamper-proof, and we don't claim it does. The narrower, true claim: the volume and rigour now required is beyond what manual, editable processes reliably produce.
Product
Capture
A change ships — a new prompt, a swapped model, an edited policy — and it is recorded at the moment it happens, not written up afterwards by hand.
Log
Records are appended to a Merkle log built the way Certificate Transparency builds one (RFC 6962). Tampering isn't prevented by access control — it's made detectable by anyone.
Verify
Anyone can check a receipt on their own machine — no CooL account, no network call, nothing of ours in the loop. Trust the maths, not the vendor.
Verification
A receipt is not a single yes/no. It is seven separate checks that can fail independently — which is what makes a failure diagnostic instead of merely alarming.
The record still hashes to the digest that was signed. Edit one character and this fails.
The digest carries a valid signature from the sealing key. Hybrid ML-DSA-65 + Ed25519 in production.
This leaf is genuinely inside the published log, provable by path, not by our say-so.
The log only ever grew. No earlier entry was rewritten to make a later one look clean.
An independently computed root agrees with the published one — a second pair of eyes on the same maths.
Hardware quote proving which enclave produced the record. Simulated until we deploy on genuine TEE hardware.
Proof the measured environment is the one claimed. Also simulated, also labelled on every receipt.
Finishing attestation and enclave on real TEE hardware flips the last two from sim to real.
These are the only numbers on this page. There are no user counts, run counts, uptime percentages or latency figures here, because CooL has none to report yet — and a number invented to fill a gap would undo every real one beside it.
Platform
The weeks a year lost to change-paperwork come back as engineering time, because the record is a side effect of shipping rather than a task after it.
Evidence assembled by hand for an audit becomes evidence produced continuously. Audits stop being fire drills and become an export.
Hybrid post-quantum signing means a record sealed today still stands when the security assumptions of today have moved on.
Market
AI governance and AI-operations software overall — everything enterprises buy to manage, monitor and document AI.
How we get there: published category forecasts (Grand View Research; Next Move Strategy) at their 2030 horizon, expressed as a range rather than a point.Organisations running production AI in regulated sectors — banking, healthcare, insurance, legal, government — where a provable change record is a requirement, not a nicety.
How we get there: the regulated, production-AI slice of that category — roughly a fifth to a quarter of TAM, which is where logging and audit obligations actually bind.The portion CooL could credibly serve as the neutral evidence layer — not the whole governance suite.
How we get there: a low single-digit share of SAM, reflecting that CooL sells one specific layer and expects to sit alongside GRC platforms rather than replace them.Estimates, not measured benchmarks. Demand today is loudest for records and logging; demand for the specifically cryptographic version is earlier-stage. Our bet is on which standard is already in place when it matures — and the roadmap owns that this is a bet on timing.
Position
01
The record spans a real enterprise's messy multi-provider reality. A tool tied to one model vendor structurally cannot be the system of record.
02
Everyone else keeps evidence in a database you have to trust. Ours verifies offline, with no account and no network.
03
Hybrid ML-DSA-65 + Ed25519 means evidence sealed today still stands in ten years. Retrofitting that is a rewrite.
04
Published post-quantum research — ML-KEM mapped into IKEv2 in C with liboqs — plus TEE and distributed-systems depth. One click to verify, which is the point.
05
The moat isn't a patent; the primitives are open standards. It's being the neutral standard already integrated when the requirements mature.
06
We mark the two simulated domains in the open. For a product whose promise is "verify it yourself," that restraint is what makes every other claim believable.
Landscape
These are real, funded, useful companies. Most of them are things CooL sits under rather than replaces — the table is about one specific job, not overall merit.
| Capability | AI observabilityLangfuse, Datadog | Governance / GRCCredo AI, OneTrust | Compliance automationVanta, Drata | Build in-house | CooL |
|---|---|---|---|---|---|
| Auto-captures every AI change | partial | no | no | manual | yes |
| Tamper-evident, provable evidence | no | no | no | no | yes |
| Neutral across every provider | no | partial | partial | — | yes |
| Verifiable with no account or network | no | no | no | no | yes |
| Proves which model actually ran | no | no | no | no | on the roadmap |
The last row is the honest one: proving which model actually ran needs the hardware tier, and that tier is not finished. Confidential-compute platforms already do this for a single run — they are complementary, not competitors. CooL proves the ongoing history of change across many runs and many providers, and does not host inference.
Compliance
CooL is designed to produce the evidence a SOC 2 audit asks for. It does not hold the certification today.
Same position. The architecture targets the evidence requirements; the attestation of compliance does not exist yet.
Planned alongside the enterprise packaging work, not before it.
Launch prices are published in the open on the pricing page, but hosted billing is not wired yet and no one is paying them.
Founders
Founder & CEO · Post-quantum cryptography & blockchain
Co-Founder & CTO · Trusted execution environments & AI inference
Nothing here is claimed beyond what is listed, and every line is one click from being checked. On a deep-tech team page, one exaggeration a reader can disprove poisons every true line next to it.
Roadmap
npm i -g cool-nwc is live today. Automatic capture and the reference integrations are the active build — making it genuinely easy to adopt and proving it works end to end.
Scoped deployments with design partners in the sectors that feel the pain — including finishing the hardware-attestation tier on genuine TEE hardware, so the two simulated domains flip to real.
Single-tenant and on-prem packaging, the security and certification work, and the org-wide licence motion. We do not hold SOC 2, HIPAA or ISO today — CooL is designed to produce the evidence those audits require.
Long-term: every change, across every provider, documented, governed and provable. The layer every AI change flows through.
Questions
A change to the behaviour of an AI system: an edited prompt, a swapped model, a changed policy, a granted tool. Each one is serialised deterministically, hashed, signed, and appended to a transparency log. It records the change, not your users' data.
You take a receipt file and run the open verifier on your own machine, with the network switched off. It recomputes the digest, checks the signature, checks the inclusion path and the consistency of the log. Nothing of ours is contacted, so nothing of ours has to be trusted.
Attestation and enclave depend on confidential-compute hardware we have not deployed yet. Simulating them lets the full receipt format exist today; labelling them sim everywhere means nobody mistakes a placeholder for a proof. When the hardware tier ships, they flip to real and old receipts stay honest about what they were.
No. Your model runs wherever it already runs, on whichever provider you already use. CooL sits beside it and records what changed. That neutrality is the point — a system of record tied to one vendor cannot be the system of record.
Because evidence has a long shelf life. A record sealed for a seven-year retention obligation has to survive the whole seven years, and "harvest now, verify later" is a real problem for signatures that outlive their assumptions. Hybrid ML-DSA-65 + Ed25519 holds if either scheme is broken.
npm i -g cool-nwc is published and installs the verifier. Automatic capture is the active build, and there is no billing yet, so there is nothing to buy — which is also why there are no prices on this page.
Install the verifier, or send us a change you'd want on the record and we'll walk it through end to end.