The protocols are published. You can implement them without us.
INTYGA is built on two specifications written to be read, criticized, and implemented by other people — including our competitors. An architecture whose security depends on its details staying private is not an architecture we would ask you to trust.
Pre-execution. Binds a human signature to the exact bytes of an action.
An open, transport-agnostic protocol for proving a human approved specific execution parameters immediately before an irreversible action — verifiable offline, with no call back to the issuer.
Post-execution. Proves the record was not altered, backdated, or selectively deleted.
An open specification for tamper-evident audit logs: domain-separated Merkle hashing, a two-tier log tree, gapless per-tenant sequencing, and offline inclusion proofs verified against independently anchored roots.
Every claim on this site reduces to something you should be able to check. That a signature covers the exact parameters. That a receipt verifies without calling us. That a daily root was witnessed by parties with no stake in the outcome. None of those are checkable if the format is undocumented.
The specifications also draw their boundaries explicitly. DIV does not define identity, key distribution, or transport. DEWP does not define storage engines or anchor transports, and it states plainly that it cannot detect an event that was never committed in the first place. A specification that claims less is easier to verify, and a security protocol you cannot verify is a brand, not a guarantee.