Legal

Provider identification

Swarrm (swarrm.ai) is operated by
capXholding AG
Oberallmendstrasse 18, 6300 Zug, Switzerland
UID / VAT: CHE-493.168.511
Contact: proof@swarrm.ai

The single contact address is deliberate — it reaches the team behind this, for security reports, privacy requests, partnership and press alike.

What this site claims — and doesn't

Swarrm is available now. The offline verifier currently proves the integrity of the presented authenticated history: receipt signatures, key-log replay, Merkle inclusion and consistency, and the checkpoint chain. The assurance mark and qualified-timestamp label remain unavailable. Higher evidence profiles are cumulative and established from explicit verifier inputs: public commitment requires a covering checkpoint re-read from Base or Base Sepolia plus an RFC 3161 token rooted in a TSA certificate supplied independently by the relying party; then dual attestation through an evidence-issuer signature and a co-signature from an active non-issuer registered recorder, verified under recorder-key trust supplied independently by the relying party. Counterparty Assurance v1 uses CWT/COSE only, and its public API converts every otherwise favourable result to INDETERMINATE/PASS_NOT_ENABLED until its external review, compromise drill and limited-rollout gates close.

Anchor and timestamp fields are producer-supplied claims: anchoring uses Base Sepolia staging, timestamps are non-qualified, and offline verification does not query the chain or use an independently supplied TSA trust root. The verifier is open source (github.com/capxholding/swarrm-verify, Apache-2.0) so its technical checks can be inspected and rebuilt.

Verification is a technical integrity result, not a legal opinion, statutory audit, admissibility ruling, insurance decision, or guarantee that a captured statement is true or complete.

Counterparty assurance proves identity and current authority for an exact nonce-bound action at a signed checkpoint, and evaluates durable replay requirements. Until its external gates close, it always emits should_execute=false and cannot authorize execution. It does not predict behaviour, certify an outcome, evaluate source/coverage/history in v1, or award a score or mark. A cached unexpired authorization can be checked locally; obtaining a new one requires the online delegated Action Authority.

The hosted service runs on our own hardware and carries no contractual SLA; the record of what it does — including its gaps — is public at api.swarrm.ai/status. No external security audit has been completed.