Don't take our word for anything. Every litre is signed into a Verified Water Record that you can check yourself, on your own machine, with the internet switched off.
A zip of raw readings, the hash-chained ledger, signatures, and the open verifier. Everything needed, nothing hidden.
Turn the internet off. The verifier needs no server, no account, and no permission from us.
It recomputes every hash, walks the chain, checks every signature, and tells you exactly what holds and what it cannot verify.
A bounded slice of time: 15 minutes of operation with its intake, output, energy and quality readings.
Which sensors produced the numbers, their calibration state, and how much they can be trusted.
Each window is hashed over the previous one. Rewrite history and every later link breaks visibly.
Signed on site by the unit's key. Anyone can check it; nobody, including us, can quietly change it.
A perfect chain of hashes proves nobody tampered with the data. It cannot prove a sensor was honest. That is why the record carries instrument trust and calibration state inside it, and why the verifier refuses to certify anything it cannot check. Where coverage is partial, the verdict says INCOMPLETE, in capital letters, instead of pretending.
Outcome-based programs need evidence that water was actually delivered safe. The record is that evidence, auditable by anyone they choose.
Compliance stops being self-reported. A regulator can verify the record independently, even with no connection to us.
The people drinking the water can hold the proof of what was delivered, not a promise from a company far away.
The pack below runs on simulated site data with real cryptography. The first pilot site makes it real.