The three mechanisms, shown as they will ship — the chain head, a receipt verifier, and a replay command — plus one complete sample transaction. Public endpoints open with the first pilot cohort. Every routing decision, verdict, approval and payment is a sealed link, and the service refuses to start on a broken chain.
Append-only, schema-enforced, verified at boot. Every decision, verdict, approval and payment is a sealed link.
The public chain seals at pilot launch. On staging the head advances on every call — the mechanism ships today; the public ledger has no blocks yet.
Every accepted call issues a signed AcceptanceReceipt. Check one here, then check it again yourself.
This page checks the envelope shape only. Full signature verification runs on your machine, against the public key issued with your pilot — verification is worthless if getting the key needs our permission.
Re-derive every number we publish from the released logs, with one command. Same inputs, same outputs, or the run fails loudly.
$ ryokai replay --logs ./release/2026-07 --check
✓ 100% re-derived · digests match
Illustrative output. The command ships with the pilot.
The same delivery the surface page shows in one line, read out of the record — including the rows that lost.
A receipt is issued only over an accepted delivery. Nothing accepted, no receipt — we will not mint one to make a card look symmetric.
The market side is countable — the surfaces you call. The governance side is concentric — Eval closest to the machine, human authority at the rim. One figure sits at the middle of both: the chain.
Named after the Ryōkai mandara (両界曼荼羅) — Kongōkai for the adamantine trust that lets strangers transact, Taizōkai for the generative containment of agents you own. 金胎不二: not two.
For EU and regulated buyers: the approval queue and signed receipts are designed to support human-oversight and record-keeping duties (e.g. under the EU AI Act). Supporting evidence for your own compliance work — not a compliance claim, and not legal advice.