Provider identification
Swarrm (swarrm.ai) is operated by
capXholding AG
Oberallmendstrasse 18, 6300 Zug, Switzerland
UID / VAT: CHE-493.168.511
Contact: proof@swarrm.ai
The single contact address is deliberate — it reaches the team behind this, for security reports, privacy requests, partnership and press alike.
What this site claims — and doesn't
Swarrm is available now. The offline verifier currently proves the integrity of the presented authenticated history: receipt
signatures, key-log replay, Merkle inclusion and consistency, and the checkpoint chain. The
assurance mark and qualified-timestamp label remain unavailable. Higher evidence profiles
are cumulative and established from explicit verifier inputs: public commitment requires a
covering checkpoint re-read from Base or Base Sepolia plus an RFC 3161 token rooted in a TSA
certificate supplied independently by the relying party; then
dual attestation through an evidence-issuer signature and a co-signature from an active
non-issuer registered recorder, verified under recorder-key trust supplied independently by
the relying party.
Counterparty Assurance v1 uses CWT/COSE only, and its public API
converts every otherwise favourable result to INDETERMINATE/PASS_NOT_ENABLED
until its external review, compromise drill and limited-rollout gates close.
Anchor and timestamp fields are producer-supplied claims: anchoring uses Base Sepolia staging, timestamps are non-qualified, and offline verification does not query the chain or use an independently supplied TSA trust root. The verifier is open source (github.com/capxholding/swarrm-verify, Apache-2.0) so its technical checks can be inspected and rebuilt.
Verification is a technical integrity result, not a legal opinion, statutory audit, admissibility ruling, insurance decision, or guarantee that a captured statement is true or complete.
Counterparty assurance proves identity and current authority for an exact nonce-bound action at a signed
checkpoint, and evaluates durable replay requirements. Until its external gates close, it always emits
should_execute=false and cannot authorize execution. It does not predict behaviour,
certify an outcome, evaluate source/coverage/history in v1, or award a score or mark. A cached
unexpired authorization can be checked locally; obtaining a new one requires the online
delegated Action Authority.
The hosted service runs on our own hardware and carries no contractual SLA; the record of what it does — including its gaps — is public at api.swarrm.ai/status. No external security audit has been completed.