Proofborne (opens in a new tab) Proof-Carrying Markets

One price, inspected — a synthetic explainer

A short walkthrough — about ten minutes · everything here is invented

One price, inspected.

When software sets a price and a hard question arrives later, what can anyone actually show?

Hotel D · Standard King · Tue 16 March 2027 Synthetic
$189

Published at 06:00 local by Hotel D, using Vendor V’s pricing software — one of 214 rate decisions that day. Vendor V’s software is also used to price eleven of Hotel D’s competitors in this market.

A single local file. No login or analytics. Once opened locally, the walkthrough sends nothing unless you follow the Proofborne link.

1 of 4 · The record

This is what one decision-level record can look like.

Four findings, each on its own axis, each stating what it was checked against and — where it rests on someone else’s word — whose word that is. Read the small print: it is doing the real work.

REC-2027-0316-D-0061  ·  SHA-256 e91b…4d07 Synthetic
ReconciliationMatched · 212 of 214
Does this record correspond, end-to-end, to a rate recorded in the named downstream system?
The day’s population — 214 rate decisions — was identified from Hotel D’s own property-management system, the named reconciliation source. That source is single-source: it records what the hotel’s systems published, not what any customer was shown. This record is one of 212 matched end-to-end to gateway records — coverage of 99.1%, with the population itself taken from the source, so decisions the source never recorded remain unquantified. The other two were unmatched: their gateway correlation identifiers were never written during a logged event-writer restart (06:41–06:44), and they are INDETERMINATE on every dependent axis.
Deployment bindingMatched
Did the build that ran match the release that was approved?
Build f7a2…9c31 matched approved release 2027.02 under attestation procedure P-3 (nonce-fresh; attested by the platform’s hardware root — trust relocated, not eliminated). The match binds the executable only: the configuration it ran under is set by Vendor V on a path outside observation boundary B, and is not covered by this finding.
Control evaluationConformant
Which rules ran, and what information entered?
Evaluated under profile Y-2027.01 — approved by Counsel C, effective 1 Jan–31 Dec 2027. The approval is an assertion about which rules should run; it is not an opinion that conformance implies lawfulness. Enumerated inputs:
Own reservations & pace
OWN_TRANSACTIONS
Hotel D systems · corroborated
Rate-shopped public prices
PUBLIC_POSTED
retrieval provenance attached · corroborated
Benchmarking report
THIRD_PARTY_BACKWARD_12M
Benchmark Supplier S’s assertion · uncorroborated
Market Demand Index (MDI)
VENDOR_COMPOSITE
Vendor V’s assertion · uncorroborated
Vendor V represents VENDOR_COMPOSITE to mean an index the vendor derives from multiple sources without exposing their composition. The token records what the vendor said the input was. It is a label, not a safeguard: nothing in this record constrains what may sit behind it, and nothing here corroborates the description.
Bounded observationNone observed
Within what the instruments could see, did anything prohibited enter?
Within observation boundary B — Hotel D’s instrumented runtime path only — and within the window 16 Mar 00:00–24:00, no input carrying a prohibited classification was observed.

Outside this record’s sight — INDETERMINATE by design

Vendor V’s own product documentation describes a shared base model retrained on pooled booking data from its client hotels — twelve of them in this market (Vendor V’s description; uncorroborated). If that description is accurate, competitor-originated signal is inside Hotel D’s model by construction — in a form this record does not characterise. The training path, the control-plane path and the human/vendor path all lie outside observation boundary B. The record says so, on its face.

This record does not establish

  • that the price was lawful;
  • that no coordination occurred;
  • that the classifications above are true — two are third-party assertions;
  • that every influence path was observed.

Notice what is missing: there is no aggregate result, no score, no pass. Each badge is one axis’s status; they do not add up to a verdict.

2 of 4 · The disputed label

Six weeks later, one question puts a label in dispute.

A reviewer asks the question nobody had asked. The Market Demand Index is forward-looking — which on its own tells you nothing about provenance, since a forecast can be built entirely from public or historical inputs. So what is this one actually built from?

According to the provenance inquiry, MDI blends public event calendars and search trends with forward-booking pace contributed by the vendor’s twelve client hotels in this market — anonymised and aggregated, at a 48-hour lag, with the top two contributors supplying roughly 45% of the signal. That is the inquiry’s account, and it remains uncorroborated. If accurate, the index would be derived from non-public, forward-looking, competitor-originated inputs.

Aggregation and a 48-hour lag do not, by themselves, establish that the signal is competitively innocuous. Nor do the concentration figures settle the opposite: whether a contribution is attributable to a particular competitor is a case-specific question about the data, not something a percentage decides. On the inquiry’s account, every decision that consumed MDI depended on a classification whose factual basis is now disputed.

A classification this record relied on is Disputed since 28 April 2027 — see correction C-114. The record has not been altered.
REC-2027-0316-D-0061 (unchanged)Synthetic
Market Demand Index (MDI)
VENDOR_COMPOSITE
Vendor V’s assertion · uncorroborated
CORRECTION C-114 · 28 April 2027 Synthetic

The historical control-evaluation finding remains true about the classifications presented at the time. Vendor V’s substantive classification of MDI is no longer relied on: a provenance inquiry reports that MDI’s content includes non-public, competitor-originated forward-booking signal — a finding that is itself an assertion, presently uncorroborated by a second source. Pending resolution, claims about MDI’s actual content — and every result dependent on that content — are Disputed for every decision that consumed MDI. The control evaluation remains evidence that the classifications presented were evaluated against profile Y-2027.01; what CONFORMANT no longer supports, while the MDI classification is disputed, is any claim about MDI’s actual content. The bounded-observation finding rested on those same classifications: it no longer supports “nothing prohibited entered on 16 March,” and returns INDETERMINATE on that question pending resolution. No claim is made as to which account of MDI is correct. The profile question — may such an input be used at all without corroboration? — returns to Counsel C. Benchmark Supplier S’s classification, the other uncorroborated label, was re-examined at the same time and, on the inquiry’s account, stands.

Read the mechanics carefully. The record stays exactly as it was, and remains true about what was presented at decision time. What failed was the record’s ability to rely on the vendor’s classification once that classification was contested — not proof that the vendor’s account was false, or that the inquiry’s account was correct. The record had marked that classification uncorroborated from the moment it was written. Anyone who read CONFORMANT as “clean of competitor signal” was reading more than the record said — though the badge invited the mistake. Uncorroborated is not a warning about content, and not a claim that nobody had looked: it records that this record carries no independent corroboration of the vendor’s classification. That declared dependence is what made the affected claims scopable — identified, dated and corrected — once the classification was contested.

Nothing is deleted, nothing rewritten. Corrections link; they never erase. That is what makes the record worth anything at all.

3 of 4 · The gap

Five weeks before Hotel D’s price, a gateway saw nothing at all.

At Hotel B — another of the vendor’s twelve clients in this market — the pricing system was unavailable for four hours on 9 February 2027. A regional manager changed forty room-nights through nineteen distinct rate decisions, by spreadsheet upload, directly into the property-management system. The pricing gateway recorded nothing during the outage; the nineteen gaps surfaced only later, when reconciliation was run against that system.

Hotel B — coverage, February 2027

Synthetic
Rate decisions identified (source: property-management system)1,880
Matched end-to-end to gateway records1,861
Unmatched — outage window 02:05–06:05, 9 Feb19
Out-of-band register: manager, timestamps, reason codes — self-reported by the acting manager · uncorroborated19 / 19
Information relied on in the 19 out-of-band decisionsINDETERMINATE
Residual risk: changes outside the identified window that the reconciliation source itself missedstated

The register restores who and when. It does not restore what information entered those nineteen decisions — and that is the question the record exists to answer. The uncomfortable rule: “all prices flowed through the controlled path” is itself a claim that needs evidence. A February record claiming 100% coverage would simply have been false. The record that honestly reports its gaps — with the manager named and every timestamp attached — is the one whose scope can be checked.

4 of 4 · What this proves

A chain of custody for a price.

Like a chain of custody, it captures and preserves where the evidence came from and how it was handled — material that can support authentication. And, equally, it never decides the case. The analogy has one more limit, and the record wears it openly: a custody chain tracks identified hands on an item whose identity can be checked independently, while two of this record’s four inputs are issuer assertions this chain does not independently verify. Custody preserved is not content verified.

Before anything else — in one sentence, in your own words: what does this record prove, and what does it not? Say it aloud, or write it down. Your sentence is the test — of this explainer as much as of you.

Within its boundary, it supports

  • the build match against the approved release;
  • which control profile was applied, and the runtime inputs it enumerated;
  • reconciliation against the named source — gaps included.

It rests on

  • labels whose issuers are named — some independently corroborated, some one party’s word;
  • assertions that can fail later — corrections link, they never erase;
  • whole paths outside its sight — which it must state on its face.

It can never establish

  • that the price was lawful;
  • that no coordination occurred;
  • that the market outcome was competitive.

It does not observe every influence on the price — the record itself put the training, control-plane and human/vendor paths outside its boundary. Deciding what these findings mean — and, first, whether they are reliable enough to rest anything on — remains the work of lawyers, economists and courts. A record that offered to do that job for them would deserve nobody’s trust.

Check yourself

No — and the record says so itself. Those are findings about how the price was produced, each limited to what it was checked against. Lawfulness is a legal conclusion; no record of how a price was produced can supply it. And note what C-114 did not do: it does not erase either historical finding. The build match still stands, and the control evaluation remains evidence that the classifications presented were evaluated against profile Y-2027.01. What CONFORMANT no longer supports, while MDI’s classification is disputed, is any claim about MDI’s actual content.

Two answers, and the difference matters. Inside the record: the MDI classification — a vendor’s assertion, marked uncorroborated from day one; its visibility is what let the affected claims be found, dated and corrected. But the larger evidentiary gap lay outside the record: the training path. This record carries only Vendor V’s uncorroborated description that a shared base model was retrained on pooled client data. It cannot resolve that gap; doing so would require vendor evidence, audit access or new instrumentation on that path. A record that fixes its labels has not closed that gap, and does not pretend to.

Nothing — it would have been false. Completeness needs its own evidence. Honestly reported gaps do not make the rest of the record true; they make its scope checkable — a smaller and more useful thing.