Product Verification Pricing Studio Market Compare Company FAQ Book a call

Northwind Cipher · System-of-record for AI change

The black box for AI.

Private by default. Provable by design.

Every change your AI makes — prompts, models, policies, tool grants — captured the moment it ships, sealed with post-quantum signatures, and verifiable by anyone, offline, across any provider.

See the Studio Talk to us
7verification domains
5run for real today
0trust required in us
root e0e0eb0c…3817 bf595e2f…bc96 dff5eb4e…ee02 prompt.update seq 1 · sealed model.swap seq 2 · sealed policy.change seq 3 · sealed tool.grant seq 4 · sealed SHA-256 leaves · RFC-6962 node hashing · append-only
terminal · cool-nwc
$ cool verify receipt.json
reading receipt · no network used
binding record → digest
signature ML-DSA-65 + Ed25519
inclusion leaf ∈ log
consistency log is append-only
witness independent root
~ attestation sim — pending TEE hardware
~ enclave sim — pending TEE hardware
5 / 5 real domains verified · 2 simulated, labelled

Open verifier

Every change can carry proof

Instead of asking anyone to trust a claim we make, CooL emits a sealed record that software can check on its own. The verifier needs no CooL account and no network connection — it reads the receipt and the maths either holds or it doesn't.

What the 7 domains check

Two of the seven domains depend on confidential hardware we have not deployed yet. They are marked sim on every receipt, in the open — never hidden, never counted as passes.

transparency log 0 records
· binding
· signature
· inclusion
· consistency
· witness
· attestation sim
· enclave sim
awaiting verification

The Studio · runs in your browser

Don't trust us. Verify it here.

This is not a video and not a mock-up. The panel beside this text runs real SHA-256 canonical hashing, a real ECDSA P-256 signature over the digest, and a real Merkle log with real inclusion and consistency proofs — in your browser, with no server involved.

Seal a few changes. Then press Tamper and verify again: the signature still passes, because it was made over the original digest — but binding, inclusion and consistency all fail. That precision is the product.

The browser signs with ECDSA P-256 because that is what browsers expose natively. Production seals with hybrid ML-DSA-65 + Ed25519. The difference is stated here rather than glossed over.

Why now

Regulation is turning "nice to have" into "on the record."

We have no customer logos to show you yet. These are the obligations doing the pushing instead — each one a public document you can read yourself.

EU AI Act, Art. 12

Requires automatic recording of events over the lifetime of high-risk AI systems. Not notes — automatic, lifetime logging.

India DPDP Rules, 2025

Continuous logging, multi-year retention and independent audit, with financial penalties for gaps.

SR 11-7 lineage

US model-risk supervision expects documented, defensible records of what a model was and when it changed.

RBI draft AI/ML norms

Model-risk expectations arriving for Indian financial institutions on the same documentary spine.

Regulation mandates records and logs. It does not — yet — mandate that those records be cryptographically tamper-proof, and we don't claim it does. The narrower, true claim: the volume and rigour now required is beyond what manual, editable processes reliably produce.

Product

Three concrete pieces: capture, log, verify.

SDK hooks

Capture

SDK and CLI

A change ships — a new prompt, a swapped model, an edited policy — and it is recorded at the moment it happens, not written up afterwards by hand.

Log

Transparency log

Records are appended to a Merkle log built the way Certificate Transparency builds one (RFC 6962). Tampering isn't prevented by access control — it's made detectable by anyone.

$ cool verify ✓ binding✓ inclusion ✓ signature✓ consistency ✓ witness ~ 2 sim

Verify

Open verifier

Anyone can check a receipt on their own machine — no CooL account, no network call, nothing of ours in the loop. Trust the maths, not the vendor.

Verification

Seven independent domains. Five run today.

A receipt is not a single yes/no. It is seven separate checks that can fail independently — which is what makes a failure diagnostic instead of merely alarming.

real

binding

The record still hashes to the digest that was signed. Edit one character and this fails.

real

signature

The digest carries a valid signature from the sealing key. Hybrid ML-DSA-65 + Ed25519 in production.

real

inclusion

This leaf is genuinely inside the published log, provable by path, not by our say-so.

real

consistency

The log only ever grew. No earlier entry was rewritten to make a later one look clean.

real

witness

An independently computed root agrees with the published one — a second pair of eyes on the same maths.

sim

attestation

Hardware quote proving which enclave produced the record. Simulated until we deploy on genuine TEE hardware.

sim

enclave

Proof the measured environment is the one claimed. Also simulated, also labelled on every receipt.

roadmap

Hardware tier

Finishing attestation and enclave on real TEE hardware flips the last two from sim to real.

7independent verification domains in the open verifier
5of them run for real today, in your browser
2marked simulated until TEE deployment — attestation, enclave
0customer data in our control plane, by design

These are the only numbers on this page. There are no user counts, run counts, uptime percentages or latency figures here, because CooL has none to report yet — and a number invented to fill a gap would undo every real one beside it.

Platform

Capture automatically. Verify offline. Prove for a decade.

Capture automatically

The weeks a year lost to change-paperwork come back as engineering time, because the record is a side effect of shipping rather than a task after it.

Verify offline

Evidence assembled by hand for an audit becomes evidence produced continuously. Audits stop being fire drills and become an export.

Prove for a decade

Hybrid post-quantum signing means a record sealed today still stands when the security assumptions of today have moved on.

Market

Where the money for this is forming.

$12–15B TAM · BY 2030 $2–4B SAM $100–300M SOM
TAM · $12–15B by 2030

AI governance and AI-operations software overall — everything enterprises buy to manage, monitor and document AI.

How we get there: published category forecasts (Grand View Research; Next Move Strategy) at their 2030 horizon, expressed as a range rather than a point.
SAM · $2–4B

Organisations running production AI in regulated sectors — banking, healthcare, insurance, legal, government — where a provable change record is a requirement, not a nicety.

How we get there: the regulated, production-AI slice of that category — roughly a fifth to a quarter of TAM, which is where logging and audit obligations actually bind.
SOM · $100–300M

The portion CooL could credibly serve as the neutral evidence layer — not the whole governance suite.

How we get there: a low single-digit share of SAM, reflecting that CooL sells one specific layer and expects to sit alongside GRC platforms rather than replace them.

Estimates, not measured benchmarks. Demand today is loudest for records and logging; demand for the specifically cryptographic version is earlier-stage. Our bet is on which standard is already in place when it matures — and the roadmap owns that this is a bet on timing.

Position

The unfair advantage

01

Provider-neutral capture

The record spans a real enterprise's messy multi-provider reality. A tool tied to one model vendor structurally cannot be the system of record.

02

Proof, not storage

Everyone else keeps evidence in a database you have to trust. Ours verifies offline, with no account and no network.

03

Post-quantum from day one

Hybrid ML-DSA-65 + Ed25519 means evidence sealed today still stands in ten years. Retrofitting that is a rewrite.

04

Credibility that checks out

Published post-quantum research — ML-KEM mapped into IKEv2 in C with liboqs — plus TEE and distributed-systems depth. One click to verify, which is the point.

05

Timing and position

The moat isn't a patent; the primitives are open standards. It's being the neutral standard already integrated when the requirements mature.

06

Honesty as architecture

We mark the two simulated domains in the open. For a product whose promise is "verify it yourself," that restraint is what makes every other claim believable.

Landscape

Everyone tracks AI. No one proves it.

These are real, funded, useful companies. Most of them are things CooL sits under rather than replaces — the table is about one specific job, not overall merit.

Capability AI observabilityLangfuse, Datadog Governance / GRCCredo AI, OneTrust Compliance automationVanta, Drata Build in-house CooL
Auto-captures every AI changepartialnonomanualyes
Tamper-evident, provable evidencenonononoyes
Neutral across every providernopartialpartialyes
Verifiable with no account or networknonononoyes
Proves which model actually rannonononoon the roadmap

The last row is the honest one: proving which model actually ran needs the hardware tier, and that tier is not finished. Confidential-compute platforms already do this for a single run — they are complementary, not competitors. CooL proves the ongoing history of change across many runs and many providers, and does not host inference.

Compliance

What we hold, and what we don't.

SOC 2 not held

CooL is designed to produce the evidence a SOC 2 audit asks for. It does not hold the certification today.

HIPAA not held

Same position. The architecture targets the evidence requirements; the attestation of compliance does not exist yet.

ISO 27001 not held

Planned alongside the enterprise packaging work, not before it.

Billing not live

Launch prices are published in the open on the pricing page, but hosted billing is not wired yet and no one is paying them.

Founders

Applied post-quantum cryptography, and confidential-compute inference.

ML-KEM · IKEv2 · liboqs

Pranauv Shrinaath S

Founder & CEO · Post-quantum cryptography & blockchain

  • ipsec-pqc-ikev2 — published research mapping ML-KEM into IKEv2 (liboqs / C).
  • Research on decentralising public banks, secured with PQC + Hyperledger Fabric.
  • Onsite research internship, NUS Singapore.
  • Building since 14.
github.com/KenidoesCode ↗
TEE · P2P · distributed compute

Kailosh Kalimuthu

Co-Founder & CTO · Trusted execution environments & AI inference

  • Built BIFROST — a decentralised P2P comms / storage / compute network.
  • Repurposes idle hardware into an encrypted, distributed micro-cloud.
  • 6 months building with US startup Decipher.
  • Building since 16.
github.com/Sk1zmo ↗

Nothing here is claimed beyond what is listed, and every line is one click from being checked. On a deep-tech team page, one exaggeration a reader can disprove poisons every true line next to it.

Roadmap

What is built, what is next, and in what order.

01

SDK and reference integrations

npm i -g cool-nwc is live today. Automatic capture and the reference integrations are the active build — making it genuinely easy to adopt and proving it works end to end.

building
02

Pilots with regulated-AI teams

Scoped deployments with design partners in the sectors that feel the pain — including finishing the hardware-attestation tier on genuine TEE hardware, so the two simulated domains flip to real.

next
03

The enterprise standard

Single-tenant and on-prem packaging, the security and certification work, and the org-wide licence motion. We do not hold SOC 2, HIPAA or ISO today — CooL is designed to produce the evidence those audits require.

then
04

The control plane for enterprise AI

Long-term: every change, across every provider, documented, governed and provable. The layer every AI change flows through.

vision

Questions

The parts people ask about twice.

A change to the behaviour of an AI system: an edited prompt, a swapped model, a changed policy, a granted tool. Each one is serialised deterministically, hashed, signed, and appended to a transparency log. It records the change, not your users' data.

You take a receipt file and run the open verifier on your own machine, with the network switched off. It recomputes the digest, checks the signature, checks the inclusion path and the consistency of the log. Nothing of ours is contacted, so nothing of ours has to be trusted.

Attestation and enclave depend on confidential-compute hardware we have not deployed yet. Simulating them lets the full receipt format exist today; labelling them sim everywhere means nobody mistakes a placeholder for a proof. When the hardware tier ships, they flip to real and old receipts stay honest about what they were.

No. Your model runs wherever it already runs, on whichever provider you already use. CooL sits beside it and records what changed. That neutrality is the point — a system of record tied to one vendor cannot be the system of record.

Because evidence has a long shelf life. A record sealed for a seven-year retention obligation has to survive the whole seven years, and "harvest now, verify later" is a real problem for signatures that outlive their assumptions. Hybrid ML-DSA-65 + Ed25519 holds if either scheme is broken.

npm i -g cool-nwc is published and installs the verifier. Automatic capture is the active build, and there is no billing yet, so there is nothing to buy — which is also why there are no prices on this page.

A product you check, not one you're asked to believe.

Install the verifier, or send us a change you'd want on the record and we'll walk it through end to end.

Open the Studio