Differential verification
We did not ask you to trust our implementation.
A valuation engine is only as good as the evidence that it computes what it claims to compute. Most engines are checked against themselves. This one was checked against an answer set that existed before it did — and it is checked again, continuously, every time anything changes.
The answer set
Twenty instruments. Three hundred and twenty-five values.
Each mark to the right is one expected value in the frozen answer set — a specific number, on a specific instrument, that the engine must reproduce exactly to be accepted. Not a sample. Not a tolerance. Every one of them, every time.
- Instruments
- 20
- Expected values
- 325
The frozen answer set
325 values · 25 × 13
A grid of 325 marks, one for each expected value in the frozen answer set. All 325 currently reproduce exactly.
One mark = one expected value
The method
How the answer set was built — and why the order matters.
An engine that is tested against expectations written after it was built tests only its author’s memory. The sequence below is the whole point.
- 01
The specification came first
Twenty test instruments were fully specified in writing, spanning the instrument universe the platform covers — before any engine existed to value them.
- 02
Independent implementations, built in isolation
Every expected value was computed by multiple independent implementations, built in isolation from one another, working only from the written specification. None of them could see the others.
- 03
Disagreement was traced, not averaged
Where the independent implementations disagreed, the disagreement was traced to its root cause and resolved by an explicit, recorded ruling. No value was settled by taking a middle.
- 04
The answer set was frozen
Only when all implementations agreed exactly — on every one of the 325 values — was the answer set frozen. Then, and only then, the engine was built against it.
- 05
Acceptance is exact
The engine is accepted only when it reproduces all 325 values exactly. To the cent, to the basis point. There is no tolerance band and no partial pass.
End to end
Nothing between the engine and the page you read alters a number.
A verified engine is not the same thing as a verified deliverable. So the same test runs again through the full platform — from data entry to rendered exhibit — proving that every transformation between the calculation and the exhibit in your audit file preserves the value exactly.
- 01Data entry
- 02Engine
- 03Attribution
- 04Roll-forward
- 05Rendered exhibit
The same 325 values, asserted at every stage
The stop condition
A single mismatch stops the system.
This verification is not an acceptance gate that was passed once and filed away. It runs continuously. If any one of the 325 values ceases to reproduce exactly — for any reason, at any stage — the system stops. Not a warning, not a flagged variance to be reviewed later. It stops.
That is the property worth having. It means the question “is the engine still right?” has a standing answer rather than a periodic one.
Send this page to your auditor.
Then bring us your instrument mix, and we will show you what the attribution and the audit file actually look like.