VERIFIER CORE · CLAIM-VS-SOURCE VERIFICATION
It compares what a text claims against what its source says, and returns one of six states plus the evidence.
Verifier Core is a kernel, not a chatbot. Give it a claim, a resolver that knows how your domain names its sources, and the canonical text to check against — it tells you whether the claim holds, and shows the evidence either way.
Deterministic: no language model sits in the verdict path. Same text, same source, same verdict, reproducible a year from now — which is what makes it usable as evidence rather than as an opinion.
WHAT IT IS NOT
The market has several things that sound like this and are not.
Not a hallucination detector
No model is judging plausibility. It checks one specific claim against one specific source, nothing upstream of that.
Not a confidence score
It returns a state and the evidence behind it, not a number between 0 and 1. A score just moves the hard decision — where to set the threshold — onto whoever has to read it.
Not a search engine
It does not go find documents for you. You supply the corpus; it compares the claim against what you gave it.
Not a reasoning checker
It verifies individual claims against their source, not what gets inferred from them. Two correctly cited premises that lead to a wrong conclusion still pass — the inferential step is not what this checks, and this page says so rather than let the name imply otherwise.
BUILT TO BUILD ON
A kernel, not an application. You bring three or four small pieces and it does the rest of the run.
Every vertical differs in exactly one place: how a source is named in that domain. Pulling the canonical text, checking whether it was still in force on the relevant date, comparing meaning, and composing the result — that part is common to a law firm, a pharmacy and a maintenance shop alike, so it lives once in the kernel instead of once per integration.
ReferenceResolver
12 lines
How a source is named in your domain.
CorpusPort
~20 lines
Where the canonical text comes from.
DomainPack (optional)
~40 lines
The magnitude vocabulary of your vertical.
LanguagePack (optional)
all four, or none
Your language's negation, omission, date and orthographic-folding layers.
SemanticAdvisor (optional)
—
A second opinion that can soften a verdict — it never promotes one to verified.
The twelve-line resolver is most of the argument. It is real code, not a promise — copied from the test suite that runs in CI, for a fictional domain invented for that test (technical-leaflet section references):
const fichaTecnica = {
id: "demo:ficha-tecnica@1",
resolve(text) {
const out = [];
const re = /secci[oó]n\s+(\d+\.\d+)/gi;
let m;
while ((m = re.exec(text)) !== null) {
out.push({
id: `smpc:${m[1]}`,
raw: m[0],
span: [m.index, m.index + m[0].length],
});
}
return out;
},
};The only thing that changes between a law firm, a lab and a maintenance shop is this first step: recognizing what a source reference looks like in their documents. The rest — fetching the canonical text, checking it was in force, comparing meaning, composing the verdict — is the kernel's job, done once.
THREE THINGS THAT DON'T COMPUTE THEIR WAY OUT
Measured cases, not illustrations built to make the point look easy.
If a page shows demos, these are the ones worth showing: none of the three is caught by a plain numeric or textual-similarity check on its own.
The figure that doesn't change — Air Canada Flight 143
Source: "Uplift 22300 kg of fuel before departure today."
Text: "Uplift 22300 lb of fuel before departure today."In 1983, a Boeing 767 was fuelled in pounds while the ground crew's calculation assumed kilograms, and the aircraft ran out of fuel at 41,000 feet over Manitoba. The digits are identical in both texts, so no numeric check that only compares magnitudes can catch this — it has to know the units differ. This is a historical illustration of the failure mode, used here for that reason alone: not a client, not an incident this engine prevented.
The word that means two things — the gallon
A gallon is 4.546 L in the UK and 3.785 L in the US, a 20% gap, and both documents can be in English. Without a declared region, the engine abstains and says so rather than guessing. Declare GB, the pair resolves one way; declare US, the same pair becomes a real discrepancy. Same text, two different answers — not an inconsistency, an incomplete question that a declared region completes. Language and measurement convention are separate axes here, the way a phone's region is separate from its language.
The half-truth — what gets left out
Source: "contraindicated in hepatic impairment, severe renal impairment, and during pregnancy"
Text: "contraindicated in hepatic impairment, severe renal impairment"Pregnancy is dropped. Textual similarity between the two: 1.000 — not one word is altered, one clause is simply missing. A similarity score alone would have called this verified.
SIX STATES, NOT A BOOLEAN
Most of the market returns true or false. The distinction is the product.
A binary engine that does not know something has to round toward one side or the other, and both directions are dangerous. Six states keep "this source doesn't exist" — a real finding against the text — separate from "we couldn't look" — a gap of ours — separate again from "outside what we cover" — a scope decision, not a failure.
verified
the claim holds against the source
mismatch
the source says something else
not_found
the corpus works and that source does not exist — a finding against the text
derogated
it existed, but did not govern on the date in question
pending
we could not look — a gap that is ours, not the text's
not_verifiable
outside what this deployment covers
Not knowing is not the same as accusing. Returning not_found when the honest answer is pending produces a false accusation dressed up as a finding — the most expensive mistake a verifier can make, because to the person reading it, it looks exactly like a real catch. So the corpus declares which one it is, rather than leaving the engine to infer it from the shape of a failure.
AGNOSTIC BY CONSTRUCTION, NOT BY SLOGAN
Domain, language, corpus and model are all ports, none of them wired in.
Sector knowledge enters through a resolver and an optional domain pack, never hardcoded into the kernel, so the same engine that checks a pharmaceutical leaflet checks a maintenance log or a credit agreement without touching its core. Six languages carry full, certified support today — English, Spanish, French, German, Italian and Portuguese — each with its own complete negation, omission, date and orthographic-folding layers. A language registers with all four layers at once or not at all: a shared policy with per-language exceptions is exactly how cross-language contamination gets in, so there isn't one.
Language and measurement convention are declared separately, the way a phone's region is separate from its language: a British and an American document can both be in English and still disagree on what a number means. Leaving the measurement system undeclared is not the same as assuming metric — it is a genuine third answer, and the engine gives that answer instead of guessing.
WHAT WE SHOW ANYWAY
The corpus publishes its own known gaps.
A stress-test leaderboard runs the reference engine against baselines and publishes the misses alongside the catches — including baselines that outscore the reference on a single column, because a verifier that rejects everything shows zero leaks on paper, and that is not a virtue worth hiding behind. Separately: zero runtime dependencies, and an air-gapped install-and-verify check that runs with no network access at all, so the determinism claim above can be tested rather than taken on trust.
A certificate with no declared gaps is either perfect or it is lying, and neither one is believable.
VERIFIER CORE AND GRUNDNORM
Complementary, not competing — opposite ends of the same problem.
Grundnorm seals who verified a record and when: cryptographic provenance that survives the record being touched after the fact. Verifier Core checks whether one specific claim holds against its source: the comparison itself. One proves a record was not altered after it was sealed; the other proves what the record stated was actually true when it was sealed.
See how Grundnorm worksBuilding a vertical that needs this layer?
@veredicto/core is not distributed as an installable package — it is built into applications, not downloaded into them. Tell us what you need to check claims against, and we will walk through the ports with you.