Aarloven See a failed run

Software acceptance · EEA

A neutral room that checks delivered software against the contract.

Your data stays with you, their code stays with them, and the room checks the delivery against clauses you both signed.

A recorded sample run

Full demo ↗
Contract · acceptance clauseswaiting
C1 Only users with edit rights on a lead can convert it. draft read · if it fails: reject delivery
C2 Conversion stops when the account already exists. draft read · if it fails: hold milestone 2, 10-day fix
C3 A finished conversion marks the lead Converted. draft read · if it fails: fix before sign-off
Aarloven Room receipt · r-7c21 · replay
— verdict appears
after the run
Sample · EspoCRM lead conversiontime —

The problem

Buying software from outside the EEA? Your data can't leave. Their code won't come in.

So the test happens inside the EEA.

Today · Cloudflare edgeNext · EEA region, then Norway

How it works

The room sits between buyer and seller, so neither has to reveal anything.

Floor plan. The buyer's office and the seller's office sit on either side of the room. Demands come in through the buyer's hatch and the behaviour note through the seller's hatch; customer rows and source code stay in their offices. The receipt leaves through a slot in the room's outer wall. The room sealed during the run 3 signed clauses · note 2 Buyer's office demands, in plain words customer rows stay here 1 Seller's office map and behaviour note source code stays here 1 receipt out verdict · hashes · timings 4
  1. The parties

    Each side shares only what it chooses.

    • BuyerA few demands, in plain words
    • SellerAn architecture map and a behaviour note
    • Stays homeCustomer rows · source code
  2. Clauses

    Plain-word demands become checkable clauses.

    • Checked byCounting, in code, or reading, by the model
    • If it failsA named action: reject, hold, fix window
    • LockedBoth sides sign one hash before the run
  3. The room

    The room checks each clause, out of both sides' reach.

    • InSigned clauses · behaviour note
    • Never inRows · source · weights · prompts
    • UnclearStays unfinished. Never guessed.
  4. The verdict

    The room returns a verdict and nothing else.

    • OutVerdict · hashes · timings
    • TriggersThe action named in the failed clause
    • SignatureAlways the buyer's. The room never signs.
Drawn for
Aarloven
Drawing
The room, in plan
Scale
Not to scale
Notes
1–4, keyed to the plan

From demands to clauses

Say what you need in plain words. Get clauses you can check.

Buyer says

  • Only the right people can convert a lead.
  • Never create the same customer twice.
  • A converted lead should say so.

Seller shares · no code

Lead→ ConvertService→ AccountContactOpportunity
Both sign3 / 3
C1Only users with edit rights on a lead can convert it.if it fails → reject the delivery
C2Conversion stops when the account already exists.if it fails → hold milestone 2, 10-day fix
C3A finished conversion marks the lead Converted.if it fails → fix before sign-off
buyer ✓ seller ✓ sha 4be1…9c02 locked

The room

Six rules the room follows on every run.

Buyer Room Seller demands note rows source demands note ✕ ✕

Neither side sees the other's private data

clause set4be1…9c02
buyer✓ signed
seller✓ signed
room▣ runs this hash only

Clauses are locked before the run

Yes, No, or unfinished. False passes get published.

Today · not yet benchmarkedNext · first public benchmark

behaviour note 598 ch
clauses C1–C3
model replies 3
test rows next
room closes →
Receipt
verdictFAIL
inputs9a1f…e07c
resultd389…eeaa
trained onnothing

Nothing stays but the receipt

Today · not stored by our codeNext · deletion proven by attestation

Only the buyer accepts the software

A failed check leads to a fix and a retest

Today and next

What works today, and what is still planned.

Today
Next
Judged
Behaviour note
Isolation
Basic sandbox
Model
Llama 3.1 8B
Region
Cloudflare edge
Access
50 public runs

Start here

Try a sample acceptance run.