Arguments that used to run for weeks,
each ended by one file in an afternoon.
loomseal.com · Worked examples
Three real arguments, grouped by which half of proof ends each one. New to the split? Read how it works or the LoomSpan page.
The mechanism is the same every time: someone needs to be believed by someone who has no reason to believe them, and the file does the believing so no one has to. Two of these turn on LoomSeal, that nothing was changed or removed. The third turns on LoomSpan, that nothing was left out. Here is what each looks like when the stakes are real.
LoomSeal proves a record was not edited: signed by the machine that wrote it, chained so nothing can be removed or reordered, and anchored so it could not have been written after the fact. These two arguments turn entirely on that.
A dispute nobody could win
A managed-infrastructure vendor pushes config to a customer's fleet. One Tuesday a change lands, and an hour later the customer's checkout is down for forty minutes. The customer's incident review concludes the vendor altered a firewall rule with no ticket. The vendor's on-call swears the rule was changed by the customer's own team the week before, and that the log they are being shown has since been trimmed. Two internal logs, two stories, a contract with penalties attached, and no way to tell whose export was edited.
The vendor's tooling had sealed every change as it ran, and the head of that chain was committed to a public git repository every hour, long before the outage. The vendor exports the week and sends one file. The customer's own engineer checks it offline, on a laptop, with no account and no call. The verifier confirms the signature, recomputes the chain, and matches the anchor published the previous Wednesday. The firewall rule was changed by the customer's team, at 09:14 the prior Thursday, and nothing in the window was removed. The fight was over in the time it took to drag a file into a browser.
Signed and anchored means neither side gets to rewrite the week after it went wrong.
Proof instead of a walkthrough
A contract says critical vulnerabilities are patched within seventy-two hours. A year in, the customer's security team asks the vendor to prove it, not describe it. The vendor could open its ticketing database and read the dates aloud, but those dates live in a system the vendor controls and could have tidied the night before the meeting. The customer knows this, so the dates settle nothing, and the review sinks into a screen-share walking tickets one at a time.
The vendor's deploy pipeline sealed each patch as it shipped, and the chain has been anchored continuously since the contract began. The vendor exports the patch history for the term and attaches it to the ticket. The security team verifies it on their own machines, offline, with nothing installed from the vendor. Each patch is there, in order, signed, first written at a time that predates any anchor the vendor could have reached. Where an SLA was missed, the file says so plainly, which is exactly what makes the rest of it believable. A week of calls closed in an afternoon of reading.
A record you cannot edit is worth the same to a stranger as to your oldest customer, because checking it never runs back through you.
LoomSpan is a profile of the same format for the other half: proving nothing was left out. On a fixed cadence the producer signs a beat to a public feed, the chain head and the exact count of entries since the last one, so a silent gap becomes either a missing heartbeat anyone can see or a signed false count. This argument turns on that.
Completeness, the expensive half
A company sells to enterprises, and every deal stalls on the same SOC 2 question: prove the quarterly access review covered every system, not just the ones convenient to screenshot. The evidence has always been a folder of exports assembled the week the auditor arrives, and the auditor's hardest hours go to completeness, establishing by hand that nothing was left out of the population, billed hourly.
The review tool now emits a spanned chain. Every sixty seconds it signs a beat to a public feed: the chain head as of now, and the exact count of entries added since the last beat. Switching the collector off during the review no longer leaves a convenient blank. It leaves a missing heartbeat on a feed the auditor can watch, or a signed false count, which is a far worse thing to have put a signature on. The auditor checks one bundle and reads the honest sentence off it: attested every sixty seconds, publicly anchored, longest unattested window seventy-four seconds. The expensive half of the audit became a line of output.
LoomSpan turns a quiet gap into a visible one or a signed lie. There is no third option that stays hidden.
None of the three needed KordLoom in the room. The producer sealed its own records as it worked, the recipient checked the file on their own machine, and the disagreement resolved without anyone extending trust they had no reason to extend. That is the entire point, shown three times. Verify one yourself, or read how it works.