Skip to content
GateCoreAI
Product evidence

See what happened.
Inspect the record.

A recorded local demonstration follows one fictional company-data request through GateCore, including permission checks, revocation and receipt verification.

The homepage animation is an interactive illustration. The walkthrough below contains recorded outputs from a separate run of GateCore product code.

Open the recorded walkthrough

What the run showed

  • An authorized read reached a local sample-provider API.
  • Requests outside the granted scope, above their signed price ceiling, replayed, or made after key revocation did not call that provider.
  • Recorded receipts passed independent signature and request-binding checks. An altered receipt failed verification.
  • A deliberately failed provider response was recorded as a failure.

The demonstration’s scope

  • An isolated local environment with fictional provider data and temporary test keys.
  • Configured test responses for policy, trust, provenance and the 15-cent price.
  • No live vendor integration, customer deployment or real payment.
  • Price limits were checked per request. Aggregate spending budgets and customer-specific row or field permissions were not demonstrated.
Recording and source details

Recorded September 23, 2026, US Central time. Nine demonstration checks passed, followed by an independent local reproduction. This is evidence for the recorded source snapshot and configuration.

Source snapshot: fae09e76a6e81f12f63ea971760f56f274417f44

Read the recorded run summary (JSON). The walkthrough also exposes the original request, response, receipt and verifier outputs.

What a receipt establishes

A valid signature and matching request binding help establish that the signed record has not been changed and relates to the corresponding request. A matching result digest connects the signed record to the recorded JSON result. These checks do not establish that the underlying data is factually correct or that a payment settled.

What has to be configured for an integration

The governed path must route through GateCore. An integration needs a provider endpoint, agent identity and granted scopes, configured capability terms, and an execution path. Existing access controls still matter: observing this route does not establish coverage of another credential or route that bypasses it.