Skip to content

Differential verification

We did not ask you to trust our implementation.

A valuation engine is only as good as the evidence that it computes what it claims to compute. Most engines are checked against themselves. This one was checked against an answer set that existed before it did — and it is checked again, continuously, every time anything changes.

325 / 325 exact — continuously

The answer set

Twenty instruments. Three hundred and twenty-five values.

Each mark to the right is one expected value in the frozen answer set — a specific number, on a specific instrument, that the engine must reproduce exactly to be accepted. Not a sample. Not a tolerance. Every one of them, every time.

Instruments
20
Expected values
325

The frozen answer set

325 values · 25 × 13

A grid of 325 marks, one for each expected value in the frozen answer set. All 325 currently reproduce exactly.

All 325 reproducing exactly

One mark = one expected value

The method

How the answer set was built — and why the order matters.

An engine that is tested against expectations written after it was built tests only its author’s memory. The sequence below is the whole point.

  1. 01

    The specification came first

    Twenty test instruments were fully specified in writing, spanning the instrument universe the platform covers — before any engine existed to value them.

  2. 02

    Independent implementations, built in isolation

    Every expected value was computed by multiple independent implementations, built in isolation from one another, working only from the written specification. None of them could see the others.

  3. 03

    Disagreement was traced, not averaged

    Where the independent implementations disagreed, the disagreement was traced to its root cause and resolved by an explicit, recorded ruling. No value was settled by taking a middle.

  4. 04

    The answer set was frozen

    Only when all implementations agreed exactly — on every one of the 325 values — was the answer set frozen. Then, and only then, the engine was built against it.

  5. 05

    Acceptance is exact

    The engine is accepted only when it reproduces all 325 values exactly. To the cent, to the basis point. There is no tolerance band and no partial pass.

End to end

Nothing between the engine and the page you read alters a number.

A verified engine is not the same thing as a verified deliverable. So the same test runs again through the full platform — from data entry to rendered exhibit — proving that every transformation between the calculation and the exhibit in your audit file preserves the value exactly.

  1. 01Data entry
  2. 02Engine
  3. 03Attribution
  4. 04Roll-forward
  5. 05Rendered exhibit

The same 325 values, asserted at every stage

The stop condition

A single mismatch stops the system.

This verification is not an acceptance gate that was passed once and filed away. It runs continuously. If any one of the 325 values ceases to reproduce exactly — for any reason, at any stage — the system stops. Not a warning, not a flagged variance to be reviewed later. It stops.

That is the property worth having. It means the question “is the engine still right?” has a standing answer rather than a periodic one.

All values reproducingNo tolerance band · No partial pass

Send this page to your auditor.

Then bring us your instrument mix, and we will show you what the attribution and the audit file actually look like.