Skip to main content

The Trust Layer

Proof you can verify yourself — not proof you have to take on faith.

Every service request, assignment, completion, verification, and payment is signed with keys we can’t misuse, made append-only, and sealed with an independent timestamp. Auditors, insurers, and regulators — and you — can independently confirm a record was done, done right, and billed honestly. No trust in us required.

No token, no wallet, no cryptocurrency — nothing to buy, hold, or manage. Just evidence that holds up.

Don’t take our word for it

Open a real record and check it yourself.

This is the whole point. Click through to a live service record and independently verify its tamper-evident chain and cryptographic signatures — no login, no account, no trusting us. Every competitor asks you to believe their logs. We hand you the math.

How anyone can independently verify a recordFour checks: open the record at a public URL with no login; recompute the SHA-256 hash and confirm it still matches; check the signature against a key held in a hardware module; and check the independent timestamp. All four run on the verifier’s side, so the record is verified without trusting FacilityOpsIQ.1Open the recordPublic URL — no login,no account, no API key.2Recompute the hashSHA-256 of the payload stillmatches. Nothing was changed.3Check the signatureSigned by a key inside a hardwaremodule we can’t extract or copy.4Check the timestampIndependently sealed — it can’t bebackdated or forged, even by us.Verified — withouttrusting FacilityOpsIQ.Every check runs on your side. Works offline.

What you get

Benefits first. Mechanism second.

Verified completion

AI reviews before/after photos and returns a pass or fail against the actual work — so "marked complete" has to mean something.

Tamper-evident chain of custody

Every lifecycle event is hashed and chained to the one before it. Alter or delete history and the chain breaks — visibly.

Vendor & payment integrity

All vendor-reported costs enter as pending approval. Nothing lands in your totals until a human approves it.

Audit-ready exports

Produce a complete, verifiable record for an auditor, insurer, or regulator — with hashes and transaction IDs attached.

You can’t change history. You can’t fake completion. You can’t bill for work that wasn’t done.

For the technical reader

Isn’t “real” trust just putting everything on a blockchain?

We looked hard at that, and built something more sustainable — and better for the operations we serve. Here’s the honest trade-off, not a hand-wave.

Putting everything on a public blockchain
  • Your photos, notes, pricing, and PII sit on a public ledger — a privacy and compliance problem you can never undo.
  • Every record costs gas to write; costs swing with a volatile token and balloon as you scale.
  • Energy-heavy: a transaction per record.
  • Locks you to a specific chain and token that may not exist in ten years.
  • A mistake written on-chain is effectively permanent.
The FacilityOpsIQ approach
  • Operational data stays private in your database — only a hash ever leaves.
  • Signed with keys in a hardware module: publicly verifiable, impossible for us to copy or misuse.
  • One timestamp attests to unlimited records — essentially free and energy-trivial.
  • No token, no wallet, no lock-in, nothing to buy or hold — and no crypto exposure of any kind.
  • Optional direct on-chain anchoring if you ever want it — your choice, not a requirement.

You still get exactly what a blockchain promises — an immutable, independently-verifiable public record no one can backdate or forge — without the cost, the data exposure, or the crypto baggage. That isn’t a shortcut. It’s the sustainable, audit-friendly way to do it.

Under the hood: SHA-256 hash-chained events · ECDSA signatures with a non-extractable KMS key · append-only Postgres · Merkle batching · OpenTimestamps → Bitcoin aggregation · optional Polygon PoS. Every record is verifiable offline.

How it works

From event to sealed, independently verifiable record.

Plain language first — the mechanism underneath, if you want it. Expand each step.

1. Payload hashing

When a lifecycle event happens — created, assigned, completed, verified, paid — the platform builds a deterministic snapshot of that event and computes a SHA-256 hash of it. The hash is a fingerprint: change any detail and the fingerprint changes.

2. Hash-chaining

Each event stores the hash of the previous event for the same job, linking them into a chain. Edit or delete an event after the fact and the chain no longer lines up — the tampering is detectable, not silent.

3. Asymmetric signing (keys we can’t misuse)

Each event is signed with a private key held in a managed hardware security module (AWS KMS). The key never leaves the module — our own systems can request a signature but can never read or copy the key — and anyone can verify a record with the public key. On-record proof-of-presence (captured signatures and photo evidence) stays attached to the operational record.

4. Append-only storage

The database itself blocks deleting or altering a sealed event — an attempt to rewrite history fails at the storage layer, not just in the application. History is add-only by construction.

5. Merkle batching

Events are periodically gathered into a Merkle tree and sealed under a single root that attests to the whole batch at once — an efficient anchor for large volumes, with a per-event proof stored for each record.

6. Independent timestamping

Each batch root is sealed through a public timestamping network, so a record can’t be backdated or forged — even by us. Only the hash is ever published: never your operational data, photos, notes, or pricing. There is no token, no wallet, and no cryptocurrency involved on your side or ours. Technically, this uses OpenTimestamps, which aggregates proofs into the Bitcoin blockchain — chosen because it is free, keyless, decentralized, and verifiable by anyone, forever. An optional Polygon path is available for organizations that specifically want direct on-chain anchoring.

Records are signed with keys held in a hardware security module and each batch is sealed with an independent timestamp — anyone can verify a record independently, and no one (including us) can alter or backdate it. Only hashes and proofs are ever published; your operational data, photos, notes, and pricing stay in your database.

Who it’s for

Verifiable proof, mapped to your stakes.

Property & insurance

A defensible record for every vendor job across the portfolio — the evidence that matters at claim time and renewal.

Enterprise & finance

Audit-ready proof that work was done and money was well spent, with a chain of custody that holds up to SOX-style scrutiny.

Regulated & life-safety

Inspection and compliance history you can produce on demand — with timestamps and hashes attached.

Vendor accountability

Reputation scored from verified outcomes and pending-approval cost control, so payment follows proof.

Make “done” mean something.

See the Trust Layer turn everyday work into proof you can hand to an auditor, an insurer, or a court — and that anyone can check.