The Protocol How It Works Trust & SecurityVerify the Record
Products
⬡ MURAQIB · مراقب ⟳ MASSAR · مسار Talk to an Expert →
Trust & Security

We publish what
doesn't work.

Every limitation documented, in full. A security advisory we raised against ourselves, for a defect nobody reported. The tool to check our claims without asking us.

This page leads with the limits because the capabilities are easy to claim and hard to check. Everything below is either a document you can read or a command you can run.

What doesn't work

The limits, first.

These are not the only ones. They are the ones a reader assessing MURAQIB should resolve before anything else.

There is no enforcement point. MURAQIB returns a verdict. The calling agent honours it. We do not sit in the network path and we cannot stop an action — any claim that a blocked action cannot proceed would be false.

Verification is conditional. Independent verification holds only where you hold verification material obtained separately from the evidence we send you. A party controlling both the evidence and the publication channel could present a rewritten history. That channel is currently ours.

A chain cannot prove it was shown in full. A record truncated at an authentic earlier checkpoint is internally perfect. Confirm the latest checkpoint's date and coverage through a channel that is not us.

The record does not establish truth. The chain establishes what was declared and decided — not that the declaration described the action performed.

Every limitation, in full, in D2 §11 →

Privacy

What this site collects.

We record the page and the time. When you open a page here we write one line on our own servers in Germany: which page, and when. We do not record your IP address in any form, not even hashed. We set no cookies, and no analytics script runs in your browser. Nothing we keep distinguishes one visitor from another — it counts page views, and it cannot count people.

We keep it for 30 days, then delete it. Not archived, not aggregated into something we keep longer.

Two things we do not control, stated because they are true. Cloudflare serves this site as our content delivery network and keeps its own edge logs, which do include IP addresses, under its retention policy rather than ours. Some pages also load fonts from Google and one script from unpkg.com, so those providers see your IP address when a page loads. Neither is something we chose for measurement.

If you request sandbox access, that is different: the email address you type is stored so we can send you a key, and that is described at the point you enter it.

The documents

Read them yourself.

Four documents. No registration, no NDA, no form. Each states its own limitations beside the capability it qualifies.

D2 — Security whitepaper · PDF, 1.4 MB, 89 pages. The architecture, the threat model, and the limitations register in §11. The authoritative count of limitations lives in that section, not on this page.

D3 — Regulatory alignment · PDF, 394 KB, 30 pages. PDPL and NCA-ECC mapping, control by control, including where the mapping does not reach.

D4 — Platform manual · PDF, 256 KB, 11 pages. A strategic overview for a non-technical reader.

D5 — Compliance manual · PDF, 811 KB, 31 pages. Written for compliance, risk and audit readers. Every claim cites the source file and line supporting it.

The advisory

We found it. Nobody reported it.

ADVISORY-2026-001. Between 5 and 9 August 2026, version 1.0.0 of our published verification tool reported a truncated record as intact — the precise failure the tool exists to prevent. It was found internally, reported by no one, corrected in version 1.1.0, and published in full alongside the tool.

We publish it here because a trust page that only lists successes is not evidence of anything.

Read ADVISORY-2026-001 →

Check it yourself

Don't take our word for it.

Every clearance decision is sealed into a tamper-evident record, cryptographically linked to the one before it, and periodically countersigned with a key held offline. The public half of that key, and the tool to check the record, are published on a page of their own.

The verifier is a single file of standard Python. It reads no network, touches no database, and imports nothing beyond the language itself.

Verify the record →

Standards

Stated honestly.

ISO/IEC 42001:2023 — in progress, not awarded. Our governance and evidence model is being built to align with 42001. We are not certified, and we do not display a badge for it anywhere on this site.

ISO/IEC 27001 — targeted. Not begun.

SAMA · NDMO · PDPL — aligned, not certified. The clearance and evidence model is designed around Saudi regulatory expectations. D3 maps this control by control and states where the mapping does not reach.

No certification scheme for agents exists — ours or anyone's. Where this site previously described agents as “certified”, that was wrong and has been removed.

What is running

Scope, precisely.

MURAQIB is the clearance rail. MASSAR is the reference integration built against it.

The control catalogue holds 58 controls as of 31 August 2026. That figure has moved twice this month; it is a snapshot, not a headline, and the authoritative count is D2 — not this page.

Every agent identity in production is governed by the rail. How many exist, how many hold a registered signing key, and how many hold an API credential are three different figures with three different dates — D2 carries each of them. One further identity runs in an isolated sandbox whose records seal to a separate chain and are not anchored. None is certified.