Independently verified: Petro Retail Analytics × AT-1DB— 26/26 across six adversarial rounds
Petro Retail Analytics put AT-1DB through a six-round adversarial verification battery— 26 of the hardest real-world query cases (hazard cases like era resets, rollover re-keys, and corrected running totals), sealed and queried through the shipped client driver and checked byte- and value-exact against a full-scan reference.
- 26 / 26
- query cases value-exact through the shipped client driver
- 6 rounds
- adversarial verification battery
- 0 mismatches
- 0 errors, end-to-end
- 0 egress
- monitored throughout the battery
26/26 value-exact. 0 mismatches, 0 errors — end-to-end, through the customer’s own driver.
Not our benchmark on our hardware. An independent, adversarial partner sealed real data, queried it through the driver we ship, and checked every answer against a full scan — and every answer was exact.
The discipline behind the number
A green checkmark is only worth what the process behind it demands. Petro Retail Analytics held AT-1DB to four rules across the battery.
Every claim was checked per-release and had to pass before the release was accepted — no result taken on trust.
Intake was cross-checked three ways — the API, the manifest, and what actually landed on disk all had to agree. The check confirmed two releases running.
Signed Ed25519 receipts were verified, and the verifier rejected tampering: an altered receipt does not pass.
Data egress was watched throughout the battery and stayed at zero — nothing left the box while the queries ran.
“The read path is verified end-to-end… genuinely good engineering.”
Why it matters
AT-1’s premise is that data — and the software handling it — should be provable, not trusted. This case study is that premise verified by an independent, adversarial partnerrather than by us: real data, the shipped driver, the hardest cases, checked against ground truth. When the party trying to break it can’t, the claim stops being marketing and becomes evidence.
What was verified?
- What did Petro Retail Analytics verify about AT-1DB?
- That AT-1DB's read path is correct end-to-end under adversarial conditions. Across a six-round battery, 26 of the hardest real-world query cases were sealed and queried through the shipped client driver and returned value-exact against a full-scan reference — 26/26, with 0 mismatches and 0 errors.
- Who ran the verification?
- Petro Retail Analytics — a real, consenting design partner that builds retail analytics for fuel and convenience retailers (product: ForecourtFlow). They ran the battery themselves, adversarially, through their own client driver. This is AT-1's premise verified by an independent partner rather than by us.
- What were the hardest cases?
- Real-world hazard cases: era resets, rollover re-keys, and corrected running totals. These are exactly the situations where a naive read path silently returns the wrong number — the battery targeted them deliberately, and every one came back value-exact.
- How were the results checked?
- Byte- and value-exact against a full-scan reference. Each sealed query's answer through the shipped client driver had to match the answer a full scan of the source data produces — no tolerance, no rounding. 26 of 26 matched.
- Was tampering tested?
- Yes. Ed25519 receipts were verified and the verifier rejected tampering — an altered receipt does not pass. Dual-hash intake (API = manifest = disk) confirmed two releases running, and monitored data egress stayed at zero throughout.
Want the same standard applied to your data? Start with what “verifiable” actually buys you, then see the platform it rides on.