Carnac Gateway™ · Proof at the Door · arrived countersigned
Record requests at your gateway.
Carnac Gateway can countersign requests on an integrated arrival path. The records preserve the request labels and classifications used by your policy.
The arrivals board
This example shows requests arriving at one facility. Labeled requests receive a classification. Unlabeled requests remain visible at the minimum evidence level.
This board is a browser animation that shows the shape of graded arrivals. Real ML-DSA-65 signatures come from the live core. You can sign a real receipt yourself on the Proof Inside window or the live signing lab. For measured, reproducible numbers on the reference core, see the Gateway benchmark.
Connect the gateway
Integrate the Gateway with your existing request path to apply the configured classification and countersigning policy.
Scroll code →
app.use(carnacGateway({ facility: "wy-dc-01" })) // fail-open · sub-ms countersign
What is live now
- Live now. The cryptographic countersigning core and consequence-based routing.
- Real hardware integration required. Placing the Gateway in your facility request path and mapping your providers is a customer-specific integration item, not a shipped appliance.
The v4 economics model explores how request classifications could support scheduling, including deferring eligible work and prioritizing critical requests.
See the v4 economics →CarnacPrompt records the request at its source. The Gateway can add a corresponding arrival record. Compare their signed fields to identify mismatches.
Proof Inside →