Skip to main content
New: Groundwater program in developmentFor growersFor water sponsors

Verification & Trust Chain

Reading summaries, signed. Check them yourself.

When a GSA auditor, a corporate water-credit buyer, or your bank asks for the record behind a number, a screenshot of a dashboard isn’t enough. Our trust chain keeps reading summaries in a signed, tamper-evident record and signs the water-use certificates built on them. Anyone with the public key can confirm a certificate hasn’t changed since it was issued, without trusting our server. The signature establishes provenance and integrity; the meter, baseline, and methodology are still what a buyer or auditor evaluates. Tamper-evident records preserve attested readings and reports; they do not by themselves establish measurement accuracy, water savings or regulatory compliance.

What runs today

Reading summaries from the sensors and meters are sealed into signed blocks (ECDSA P-256, with a key that never leaves Cloud KMS), each block linked by hash to the one before it, so the record is tamper-evident from the point of signing forward; checking that chain needs the farm’s authorization. Water-use certificates are signed with Ed25519 (RFC 8032) and hash-chained to the certificate before them; anyone with a certificate link can re-check the hashes and the signature against our public key at /.well-known/agwaterai-signer.pub.jwk, and that check runs every time the page opens. On the pilot farms, the draft water order is held back and logged before the adviser makes the call; issued orders are kept with the readings behind them and are not signed.

Layer 01

Sensor reads ingested

Soil moisture probes report every 15 minutes. Where a flow meter with telemetry is installed, pump runtime and volume come in too. Each feed is stored with its time and source.

Layer 02

Decision systems compute figures

Three trained AI models are live in the irrigation decision today (SENTRY, WATCHDOG, PULSE); more are trained and staged behind promotion gates. With the PRESCRIBE rules engine, salinity tracking and a physics water balance, they turn raw sensor data into farmer-facing decisions and water-use figures (allocation usage, same-day stress signals, salt zone trend, the weekly irrigation order).

Layer 03

Cryptographic signing

Reading summaries are sealed into signed blocks (ECDSA P-256, key held in Cloud KMS). Water-use certificates are signed with our Ed25519 private key (RFC 8032). The public key sits at /.well-known/agwaterai-signer.pub.jwk. Anyone can verify a certificate without trusting our server.

What ships today vs the patent-pending roadmap

Live today

Ed25519 signed certs (RFC 8032)

  • · Water-use certificates signed with our private key, hash-chained to the certificate before them
  • · Public key at /.well-known/agwaterai-signer.pub.jwk
  • · Per-site mini-hashes anchor under each certificate
  • · Anyone can verify without our server: fetch the JWK, run compactVerify
  • · Each certificate is re-checked against the public key every time its verify page opens
  • · Issued from the customer dashboard Verification tab

Patent-pending roadmap

Patent-pending verification roadmap

  • · Hybrid signature options after counsel review
  • · Patent-pending chain structure for agriculture workflows
  • · Selective-disclosure layer for grower-controlled privacy
  • · Merkle anchoring across daily site snapshots
  • · Built for buyer-grade audit trails
  • · Gated on counsel review before public rollout

Same dashboard surface today and tomorrow. Swapping the signature primitive from today's Ed25519 signing to future hybrid signing keeps the UI, the verifier, and the workflow familiar. The patent-pending advances are invisible to growers, visible to auditors, and load-bearing for buyer + insurer counterparties down the road.

From soil sensor to verified output.

Sensor → aggregation → verification chain → Merkle attestation → verified output

Don’t trust us. Verify it yourself.

One click fetches a live signed record of our aggregate production stats, pulls the public key, and checks the Ed25519 signature right here in your browser. Our server plays no part in the check and never sees the result.

What you verify contains no private data: the signed record holds six company-level aggregate figures (total sensor readings, active site count, site-years, years of continuous data, and models in production) and nothing else. No farm names, no locations, no field-level readings, no customer information. The record even declares its own scope: aggregate-only; no per-customer data.

Verification happens in your browser with the public key. We never see the result.

Why a checkable record matters to buyers

Most ag-tech dashboards display numbers. Anyone could screenshot them. The trust chain turns those numbers into a verifiable artifact any counterparty can confirm with our public key.

That matters when the next buyer is a corporate water-replenishment program, an independent water-benefit reviewer, or a Gold Standard WBS registry. Those buyers want more than “the vendor says so”: a tamper-evident, independently-checkable record lowers audit friction and dispute risk. No credit volume, price or revenue is established. Any proposed project requires project-specific evidence, an accepted methodology, independent verification and a buyer agreement.

Verify a cert yourself.

Fetch the public key, parse the JWS, verify the signature. No AgWaterAI API call required.

import { compactVerify, importJWK } from 'jose';

const jwk = await fetch('https://agwaterai.com/.well-known/agwaterai-signer.pub.jwk')
  .then(r => r.json());
const publicKey = await importJWK(jwk, 'EdDSA');
const { payload, protectedHeader } = await compactVerify(jws, publicKey);
console.log('verified', JSON.parse(new TextDecoder().decode(payload)));

jws is the compact-form signature shown in the Verification tab of any customer dashboard. The decoded payload includes entity id, acres, allocation AF, water year, and the issuance timestamp. Metered use is not attested by this endpoint.

Why this matters beyond the dashboard

If water-credit markets develop, a documented water-use record is what a buyer will ask for.

A signed water-use certificate is the difference between “our vendor says we saved water” and “here is the cryptographically attested record any buyer can confirm has not been altered since signing.” That distinction is what corporate water-replenishment programs and registries ask for. No credit volume, price or revenue is established; any proposed project requires project-specific evidence, an accepted methodology, independent verification and a buyer agreement.