When regulated controls are executed outside your organisation's direct operational boundary, the evidence must be independently verifiable — not simply produced by the party being evaluated.
The primary artifact produced by the platform.
Built for organisations responsible for proving controls executed outside their direct operational boundary.
The parties who must establish that the control ran — without being asked to take the producer's word for it.
One organisation executes. Another organisation needs to verify.
Runs inside a partner, a vendor, or a platform you do not operate.
Sits with an institution that has no direct visibility into that execution.
Remains with the regulated entity regardless of who pressed the button.
Now has to happen across a boundary the evidence was never designed to cross.
Existing evidence was largely designed for environments where execution and accountability lived closer together.
Not because anyone is dishonest, but because the artifacts in circulation were built to describe work rather than to prove it. A report asserts. A dashboard asserts. A log asserts. Each one is only as good as the infrastructure and the goodwill behind it — and both sit on the producer's side of the boundary.
The definition that ran is not the definition on file today.
Records that were never in scope leave no trace of their absence.
Lists, thresholds and models move; the evidence does not say which moved when.
An upstream feed fails and the run completes as though it did not.
The state of the past is rewritten by the systems that hold it.
Existing evidence mechanisms often stop short of independently proving what executed, against which population, under which control definition.
| Category | What it does | What it cannot independently prove |
|---|---|---|
| Compliance Platforms | Manage policies, workflows, obligations and compliance processes. | The historical execution state of a specific control and its declared population. |
| AML & Screening Systems | Execute screening and identify potential risks. | That historical execution, population coverage and control state remain independently verifiable. |
| Audit Logs & SIEM | Record operational events. | Completeness and integrity of the underlying control execution population. |
| External Audits | Provide independent assessment and assurance. | A portable execution artifact that can itself be independently reverified years later. |
These categories are complementary. Ellipe 3 supplies the artifact they each depend on and none of them produce.
The relying party can verify the evidence without trusting the producer's infrastructure.
Evidence can move between organisations without requiring access to the originating system.
Verification can remain possible after the original execution environment changes or disappears.
A VCEP produces independently verifiable evidence of control execution, so that a relying party can establish what control ran, what population it covered and what execution evidence resulted — without relying solely on the producer's assertion.
Identifies the exact control definition governing the execution.
States the population covered and declared exclusions.
Records evidence of what occurred during execution.
Provides what an independent verifier needs to establish validity.
An Evidence Packet is designed to be independently verified without access to the originating infrastructure.
Explore the Evidence Packet →These are the control types Ellipe 3 is being built and validated against.
Evidence for controls executed by fintech and program partners.
Evidence supporting independent verification of screening execution and declared coverage.
Evidence supporting verification of reconciliation controls and population coverage.
Portable execution evidence for internal audit and assurance functions.
Applications under build and validation. Not claims of production deployment.
The primary artifact produced by the platform. It is a bounded, self-describing record of one control execution: the definition that governed it, the population it covered, what happened, and everything a third party needs to check the first three for themselves.
Everything else on this site exists to produce, move, or verify this object.
Identifies the exact control definition that governed this execution — not the control as it is described today, but the version that actually ran: its parameters, thresholds, reference data and declared scope, bound to the execution rather than referenced from a mutable registry.
Answers: which rule ran? Withstands a rule being modified, renamed or retired after the fact.
States the population the execution covered and, explicitly, what it did not. Exclusions are declared rather than inferred from absence, so a verifier can distinguish a record that was deliberately out of scope from a record that silently went missing.
Answers: over what? Withstands silent gaps and undeclared partial coverage.
Records evidence of what occurred while the control ran — outcomes, dispositions and the conditions under which they were reached — in a form fixed at execution time rather than reconstructed afterwards from systems that have since moved on.
Answers: what happened? Withstands historical overwrites and post-hoc reconstruction.
Carries what an independent verifier needs to establish that the first three claims hold — inside the packet, so the check can be performed by someone with no relationship to the producer, no access to the originating environment and no live connection to anything.
Answers: why should anyone believe it? Withstands the producer becoming unavailable.
A definition is fixed and versioned.
It runs against a declared population.
The artifact is sealed and leaves the boundary.
The relying party checks it themselves.
It is retained as an ordinary file.
The same check runs again and returns the same answer.
A log records what a system chose to write down, in the format it happened to use, for as long as retention allows. It carries no declaration of the population it should have covered, and no way to establish that nothing was dropped.
A report is a summary authored by the producer for a reader. Its accuracy rests on the producer's process. Re-reading it later tells you what was claimed, not whether the claim was true.
An attestation transfers trust to a signer — it is a statement that someone competent looked. A packet does not ask the relying party to trust a signature over the underlying facts; it lets them check the facts.
All three describe execution. A packet is constructed so that execution can be established by someone who was not there.
A VCEP executes a control and, in the same operation, produces evidence that a third party can check independently. The two are not separable steps: the artifact is a by-product of execution, not a report written about it afterwards.
The platform's job is narrow and deliberate — bind a control definition to a run, declare the population, capture what occurred, and package all of it so the check can happen elsewhere, later, by someone else.
One packet describes one execution across four claims: control identity, population declaration, execution evidence, verification information. The canonical definition of each lives on the Evidence page — this page assumes it.
Canonical definition →The packet arrives by whatever channel already exists — a portal, a share, an email attachment.
The packet is self-describing: its contents are checked against the commitments carried inside it.
The declared population is reconciled against the execution evidence, including declared exclusions.
The result is deterministic. The same packet and the same procedure return the same answer, on any machine, at any time.
Layers 01–02 run inside the producer. Layers 04–05 run inside the relying party. Layer 03 is the only thing that moves between them — and it is the only layer this site's business architecture shows.
A packet that has been altered does not verify. There is no partial credit.
What produced the evidence, under which definition, is bound into the artifact rather than asserted alongside it.
Exclusions are declared. An undeclared gap is a verification failure, not a silent omission.
Given the same inputs, the same result — which is what makes an independent re-check meaningful.
The check runs on the verifier's terms, on the verifier's hardware, without the producer in the loop.
The procedure is documented and stable, so a packet checked in 2026 can be checked again in 2033.
Cryptographic commitments and zero-knowledge techniques are how several of these properties are achieved. They are implementation, not proposition — the guarantees above are what a relying party is being offered.
If the check runs on the producer's systems, the producer is inside their own audit.
An endpoint that is deprecated, rate-limited or offline takes the evidence with it.
Companies are acquired and wound down. Retention obligations outlast both.
If the past can be edited, evidence about the past is a snapshot of an opinion.
No. The packet and the verification procedure are what a relying party needs. Our involvement is not a dependency of the check.
No. That is the point of the boundary. Verification runs on the verifier's side with no connection back to the producing environment.
Packets already issued remain verifiable. The format and procedure are documented so that the check does not depend on the company continuing to operate.
No. Your screening system continues to execute screening. Ellipe 3 makes that execution independently provable to whoever has to rely on it.
No. A packet is designed to establish coverage and execution without exporting the underlying records to the verifier.
The relying party — a sponsor bank, a third-party risk function, internal audit, or an external auditor acting on their behalf.
For as long as the packet is retained and the documented procedure can be run. Durability is a design constraint, not a service level.
Three kinds of conversation, and they are genuinely different. Tell us which one you are starting so it reaches the right person.
The selected role is captured with the submission — it is the site's segmentation signal.
No demo funnel. A person reads this and replies.