Customers verify our claims with math, not marketing.
You do not have to take our word for anything: every claim on this estate is independently verifiable, and the harness that proves it ships with the product.
Every operational event carries a SHA-256 fingerprint on a hash-chained log built by tools that ship in this tree. Capabilities are calibrated BUILT, IN PROGRESS, or PLANNED and say so on their face. The Outcome Warranty is contractual. The policies are directly readable below, and this build carries 12,883 automated assertions at 0 failed, recomputed on every release.
Foundation, before the security claims
Why we exist. What we are building toward. How we hold ourselves to it.
A trust center is the contract a company offers itself before any auditor arrives. These statements are the constraints we accept before any pressure does.
Mission
Restore the operator's ability to see the whole enterprise at once, without replacing the systems they have already paid for. Two decades of best-of-breed specialization gave every function its best tool and the C-suite an incoherent picture. We build the layer above the stack so the people who carry the consequences of decisions can see the consequences before they decide. That is the work.
Vision
A decade from now, every consequential enterprise decision will be made on verifiable, source-attributed evidence, and the path from observation to action will be auditable end to end. The default state of enterprise decision-making is opinion masquerading as data. Our vision is the inverse: a working surface where every number traces to the source system that produced it, every recommendation cites its evidence, and every action leaves a record auditors can verify without our cooperation. Trust earned by construction, not by claim.
Values
Six commitments we hold before any deal closes.
Held in writing, each with its enforcement named. The cheapest time to keep a promise is before you make it; the line above is the floor, not the ceiling.
01 Calibration over polish
Every capability is labeled by the exact stage it is at: built and working on the synthetic tenant, built and awaiting activation, declared scaffold, or planned. A polished claim we cannot defend is worse than a calibrated one a customer can verify.
02 Source systems stay authoritative
ERP, MES, WMS, PLM, CRM are the systems of record. We sit on top of them, never between. Read-only by architecture, not by policy; no write path to any system of record exists in the product, so the line cannot be argued past.
03 Hours reclaimed, not headcount removed
Customers commit in writing that hours the platform gives back will fund growth, customer service, training, or new-segment expansion. The dignity of the people doing the work is part of the commitment; the full covenant, with its enforcement, is published on the covenant page.
04 Verifiable, not just trusted
Every operational event carries a SHA-256 fingerprint on a hash-chained log. Customers can verify our calibration claims without our help. Trust is the outcome of construction, not the input to selling.
05 Bring your own intelligence
We do not lock customers into a particular reasoning engine. The platform composes evidence; how a customer chooses to apply judgment on top of it is their architectural choice, not ours. Sovereignty over thinking, not just data.
06 Outcomes binary, remedies real
The Outcome Warranty determination at Day 90 is binary and signed before Day 0. We hold the financial consequence of being wrong. That is the line between conviction and marketing.
Advisory posture, what AssetShop is and is not
Information only. Decisions belong to the customer.
AssetShop surfaces insights, signals, recommendations, and analytical outputs read from customer source systems. The seven clauses below document where our work ends and the customer responsibility begins, explicitly and unambiguously.
01 Not advice. Not execution.
AssetShop surfaces insights, signals, recommendations, and analytical outputs based on data read from customer source systems. AssetShop is not a registered investment advisor, broker-dealer, financial advisor, legal counsel, accountant, or regulatory compliance authority. Information presented should not be construed as investment, financial, tax, legal, accounting, or regulatory advice.
02 Decisions belong to the customer
Customer bears sole responsibility for business outcomes resulting from decisions made on insights, recommendations, or signals surfaced through the platform. All hedging, sourcing, supplier-award, capacity-investment, regulatory-disclosure, treasury, financial, and operational decisions remain with the customer functions that own them.
03 Outcomes vary
No insight or recommendation can promise a specific business outcome. Markets shift, suppliers fail, regulations change, data quality varies. The Outcome Warranty is a remedy on a jointly signed threshold, not a promise of any particular dollar amount, return rate, or business result.
04 Read-only architectural posture
AssetShop does not execute trades, place hedge contracts, issue purchase orders, bind contracts, modify ERP transactions, instruct treasury operations, or commit the customer to any third-party obligation. All execution remains in customer-controlled source systems on the customer normal workflow. There is no write path in the product; the v3.95-era optional approval write-back is superseded by decision D-R62, and approvals live in AssetShop own ledger instead.
05 Verify before acting
Customer is responsible for independent verification of market data, financial figures, supplier information, regulatory deadlines, certification claims, counterparty health signals, and other analytical outputs before acting, and for engaging qualified legal, financial, tax, and compliance advisors for material decisions.
06 Limitation of liability
MSA Section 11 (Limitation of Liability) and Section 12 (Indemnification) document the precise legal boundaries. Standard commercial liability caps apply, typically twelve months of fees paid. AssetShop is not liable for indirect, incidental, consequential, special, exemplary, or punitive damages arising from use of platform insights.
07 Confidentiality of platform learnings
Customer keeps AssetShop proprietary platform features, derivation methodologies, calibration insights, and configuration learnings inside the customer organization: no public RFP responses, conference presentations, benchmark distributions beyond the buying team, or social posts. Internal training, audit-defense preparation, executive briefings, and NDA-bound advisors are expressly permitted under standard flow-down. Compelled-disclosure exceptions apply with notice back to AssetShop. Governed by MSA Section 10 with remedies under Section 12.
Self-service virtual access to the platform is offered and governed by the terms published on this site at the time of agreement; matters not covered follow standard industry terms.
The Outcome Warranty, contractual
If we miss, the remedy is real.
Every pilot is bound by the Outcome Warranty™: a binary Day-90 determination against a dollar-denominated threshold that the customer CFO and the AssetShop founder both sign before Day 0. The fee terms are qualitative here by decision: fixed fee, credited in full toward the pilot, refundable under the warranty; the figure arrives in the room, not on the storefront.
SUCCESS, threshold met
Customer attests to validated value at or above the Day-0 threshold. The engagement converts and the fee credits in full toward year one.
EXTEND, trajectory clear
Joint determination that the trajectory reaches threshold by Day 180. No additional fee. The customer decides at Day 180 whether to extend or elect the remedy.
REMEDY, threshold not met
The warranty applies exactly as written, settled within thirty days, refundable via ACH. Nothing auto-converts, and the customer keeps all derivative work product from the pilot.
How the threshold is set
Three steps, both parties bound before Day 0. First, a CFO and CPO discovery call reviews the customer spend profile, adapter coverage, and operational baseline. Second, the founder proposes a threshold from the calibration methodology and joint negotiation produces the final number. Third, both sides co-sign the MSA exhibit documenting the threshold, the validation methodology, and the sign-off authority.
Customer-side conditions, bilateral by design
The warranty is a two-sided commitment. It applies when six customer-side conditions hold: validated value reaches at least seventy-five percent of the low-end baseline agreed at Day 0; transaction volume runs at least ninety percent of the Day-0 assumption; product-mix gross-profit impact stays within a ten percent decline of baseline; the departments in scope actually use the platform; every layer in scope is exercised during the ninety days; and value is tracked in detail per the exhibit methodology with evidence retained. When both sides hold their end, the warranty applies. When either side does not, the conditions document who needs to do what.
Cryptographic provenance
Every event is anchored; every claim ships with a receipt.
Each operational event produces a one-way SHA-256 fingerprint. The log is hash-chained, and at general availability the chain root anchors to a tamper-evident, independently verifiable external anchor on a configurable cadence. Only opaque hashes are public; event contents stay inside the tenant. The chain proves data existed at anchor time without exposing what it is.
01 OBSERVE
Read-only signal from ERP, procurement, planning, WMS, MES, TMS. Every read is recorded as an event with a SHA-256 fingerprint.
02 CHAIN
Every event links to its predecessor by hash; a Merkle root is computed from the chain at each anchor interval.
03 ANCHOR
The root commits to a tamper-evident external anchor at activation; the anchor receipt is permanent and independently verifiable. Today the chain runs in dry run by the anchor tooling shipped in this tree, and says so.
04 VERIFY
A customer or auditor verifies any event against the anchored root with a pure hash comparison; the stranger path on the verify page re-derives this build claims cold, with no credentials from us.
Connector program, structural
Every adapter ships with a conformance certificate.
Integration is usually a trust black box. Here it is inverted: every first-party connector carries a public calibration entry, a per-connector conformance scorecard documents exactly what it reads and what it cannot do, and a Conformance Certificate publishes per connector as each passes its live gate. Counts are derived from the canonical ladder at page build, never typed: 8 certified and conformance-tested, 9 in active development, 56 on the portfolio. Scaffolds report not-ready until validated on a live tenant, so they can never be mistaken for production.
$ verify conformance CONF-S4-SPECIMEN (format specimen, SYNTHETIC) certificate fetched, signature checked against the production key adapter source hash matches the certificate declaration endpoints listed: all read-only fields extracted: all classified, all in the field map rate limit and residency posture stated RESULT: PASS, certificate valid through its stated window
The CISO pack
The facts a security review asks for, stated plainly.
The specifics procurement and security teams check first. Where a control is in progress rather than complete, it says so; honest calibration is the product. The full questionnaire and security documentation are available under MNDA from the founder.
Data architecture
Read-only by construction: no write path to any system of record exists in the product, which is the strongest possible blast-radius posture. Per-tenant residency in the elected region with no cross-tenant commingling. TLS 1.2 or better in transit, AES-256 at rest, keys managed per tenant.
Identity and access
SSO via SAML 2.0 and OIDC with major identity providers; SCIM 2.0 provisioning with deprovisioning on identity-provider removal; least-privilege role-based access where every action carries an actor on the tamper-evident log.
Framework posture
The attestation program proceeds internally and its exact status ships in the diligence pack on request; control coverage is evidenced from operational signals rather than reconstructed at audit time; framework mappings extend per tenant requirement.
Resilience and operations
Recovery objectives stated in writing per engagement in the MSA; independent penetration testing engaged before first customer data; incident response runbook documented with tenant notification commitments stated in the DPA.
Founder continuity, published
The question every procurement team asks, answered before you ask.
AssetShop is, at this stage, a solo-founder operation. Bus factor is one. Most vendors hide this; we publish the mitigation. The plan is drilled on a stated cadence, contractually bound in the MSA, and the audit chain that proves your data continues to exist stays verifiable against the external anchor even if AssetShop does not.
Tier 1, designated successor
Family or estate executor activates the runbook and coordinates Tier 2.
Tier 2, founder counsel
Credentials held in legal escrow, released on Tier-1 instruction.
Tier 3, escrow agent
The source repository held by a third party, released on objective triggers.
Tier 4, customer custodian
A customer-named technical custodian in the MSA exhibit keeps the tenant operational through transition.
Operational continuity, beyond code custody
If the founder is unreachable, the structural answer is: a standing virtual-CISO relationship handles security triage and customer notifications on activation; a managed production-engineering on-call rotation engages at the first production tenant with credential access controlled through the Tier-2 custodian; cyber and errors-and-omissions coverage scales with customer revenue and includes a breach-response retainer; and the MSA commits to a successor engagement window on a permanent-incapacity trigger, with the read-only access commitment holding throughout. Named providers publish on the sub-processor page the day each activates, and identities are disclosed under MNDA before then.
Services that learn with use, published method
Performance improves over time, without your raw data ever leaving your tenant.
Static thresholds go stale. Operator feedback is the cheapest signal for making detection sharper, and we collect it under two firm rules: per-tenant adaptation stays inside your tenant boundary, and cross-tenant aggregates require explicit opt-in and pass formal privacy gates before publication. This is principled statistics, stated exactly; we do not claim more than we deliver.
Layer 1, per tenant, default ON
When operators mark a recommendation as a false positive, the per-tenant detection threshold drifts toward the correct value under slow exponential adaptation with operator-set hard bounds. Tenants can bound, pin, reset, or opt out entirely; nothing leaves the tenant boundary.
Layer 2, cross tenant, default OFF
Only anonymized aggregates ever cross the boundary, only with explicit opt-in, and only after three formal gates: a K-anonymity floor of at least five contributing tenants, calibrated differential-privacy noise, and a per-day query budget that prevents disclosure by iteration. Every consent change and every aggregate egress is recorded on the audit chain.
What is never collected
No supplier, vendor, customer, or employee names; no email addresses, phone numbers, tax identifiers; no purchase-order or invoice numbers or monetary values; no free text from any system. The schema is a categorical whitelist and PII-shaped values are rejected at ingest as defense in depth.
Policies and evidence
The policies your audit committee actually reads.
Counsel-ready policy drafts, directly readable, each labeled with its status. For operational disclosure beyond what is published, write to the founder.
The policy index lists every draft: privacy, acceptable use, sub-processors, vulnerability disclosure, AI safety, cookies, DMCA, continuity, feedback data processing, terms and IP, the DPA, and the accessibility statement. The status page states the honest deployment posture, and the verify page carries the stranger path.
Platform in depth
The suite, the path in, and the wiring.
The pages a buying team reads next: the module suite with calibration labels, the activation path from first source to first insight, the enterprise onboarding arc to the Outcome Warranty determination, the tenant control plane preview, and the integration map that marks built against live.
Module suite · Activation path · Enterprise onboarding · Enterprise console · Integration map
Talk to the founder
Bring your hardest security questions.
Every conversation is founder-led. Bring your CISO, your auditor, your procurement security review; answers come directly, with the evidence under NDA. Write to Founder@AssetShopEnterprise.com; engagements are read-only and scoped in writing, and nothing on this page creates system access.
Calibrated capability status
The honest status, not the aspirational claim. Every entry is labeled by stage and nothing here is a percentage without history behind it.
Independent attestation program IN PROGRESS
Third-party attestation engagement proceeds internally; the exact status string ships in the diligence pack to anyone who asks. Until the report exists, the substitute proof is the harness a stranger can run.
Tamper-evident audit anchor BUILT, DRY RUN
Hash-chained event roots built and exercised in dry run by tools shipped in this tree; external anchoring activates post security audit with cadence configurable per tenant.
Accessibility conformance IN PROGRESS, TESTED PER RELEASE
WCAG 2.1 AA target; contrast, focus visibility, reduced-motion, and structure checks run as automated assertions in every sealed build; independent manual audit and VPAT are pre-GA roadmap items available on request as completed.
Outcome Warranty STANDARD TERM
Binary Day-90 determination, jointly signed before Day 0, remedy settled within thirty days. Contractual per MSA exhibit.
Adapter conformance certificates BUILT, PER-CONNECTOR GATES
Every first-party connector publishes what it reads and what it cannot do, with a per-connector conformance scorecard; a certificate publishes per connector as each passes its live gate. Counts on this estate are derived from the canonical ladder, never typed: 8 certified, 9 in development, 56 on the portfolio.
Tabular ingestion path BUILT
A hardened validation door for tabular extracts with a case-by-case failure matrix asserted in the battery; the alternative-to-integration path for any system.
Read-only architecture BUILT, BY DESIGN
No write path to any system of record exists in the product. Hard-coded at the adapter contract level and proven by suite.
Tenant isolation BUILT, PROVEN PER RELEASE
Isolation proven by suite against a second dataset on every sealed run; entitlement is absence, not low ranking.
Per-tenant residency AT DEPLOYMENT
Tenant data stays in its elected region with per-tenant keys; region set extends per customer requirement.
Cyber liability, tech errors-and-omissions, general liability insurance BINDING PRE-FIRST-SIGNATURE
Coverage binds before the first customer signature; limits disclosed under MNDA per customer.
Delaware C-Corp transition IN PROGRESS
From the Pennsylvania LLC, counsel-paced, completing before the first customer signature.
Source code escrow PLANNED AT FIRST SIGNATURE
Third-party escrow agent, released on insolvency triggers.
Availability commitments PER ENGAGEMENT
Agreed per engagement in the MSA with recovery objectives stated in writing; no percentage is published before there is history to compute one from, and the reliability page says exactly why.
Ported into the build estate at R53; the Trust Center itself was restored from the sealed v3.95 product of record at R123 after the audit found the route carrying the privacy policy instead, and the restoration is guarded by suite so the retrograde cannot return. You do not have to take our word for anything: every claim on this estate is independently verifiable, and the harness that proves it ships with the product.