One system underneath. That's what an operating system is.
The first true Compliance OS.
Construction runs on trust between companies that share jobsites but not databases. A subcontractor's insurance protects the general contractor. A worker's certification protects everyone on the deck. A carrier's pricing depends on conditions it has never once observed. For decades, the industry has managed this web of dependency with PDFs, spreadsheets, and hope.
Verisfort replaces that with an operating system.
What "multi-tenant, event-driven" means, in plain terms
Every company on Verisfort — contractor, GC, carrier — owns its own sealed data domain. Nobody shares a database; nobody sees anything by default. When two companies choose to work together, they form an explicit, consented link — and through that link, exactly the right information flows: the GC sees the sub's compliance state, the carrier sees its insured's risk posture, the worker's badge answers at any linked gate. Every meaningful thing that happens — a certificate validated, a badge scanned, an incident reported, a hazard flagged — becomes an event that updates every entitled view at once. One fact, entered once, true everywhere it should be and invisible everywhere it shouldn't.
Why this had to exist
Certificates of insurance expire silently in filing cabinets while the work continues uncovered. Safety data dies in apps nobody audits. Carriers price billion-dollar exposure from claims history — a rearview mirror — because no forward-looking operational data has ever existed in usable form. The cost of that chaos is paid in uninsured losses, preventable injuries, and premiums that punish the diligent and subsidize the careless. Verisfort exists because every one of those failures is an information failure — and information failures are solvable.
Built by Elkannah
Verisfort is the flagship system of Elkannah, a company founded on a simple conviction: some work is meant to be done, and doing it well is a form of stewardship. Elkannah builds systems that bring order to chaos. There is no industry with more consequential chaos than the one that builds everything else.
The backbone of compliance, safety, and risk for the built world.
Every structure humanity raises will one day stand on a verified chain of competence and coverage: the worker was qualified, the contractor was insured, the site was managed, the risk was priced on what actually happened. Verisfort is building that chain.
A certificate is a claim about the past. Compliance is a state that's true right now — and states should update themselves.
The best predictor of tomorrow's loss is today's jobsite. Verisfort turns gate decisions, credential states, hazard reports, and corrective actions into signals carriers can actually price.
Subcontractors are the industry's backbone, not its suspects. Prove yourself once; be trusted everywhere you consent to be known.
Safety infrastructure that treats the worker as its customer: a badge that just works, alerts that inform without surveilling, and a device that never reports where they stand.
Every number traceable to its source event, every bundle hashed, every derivation inspectable. Data worth underwriting on has to be data worth auditing.
Bring order, truth, and safety to the built world — by building the operating system for compliance and risk.
- We never punish participation. Using Verisfort makes a contractor more trusted, never more billed, gated, or surveilled. The system exists to lower the cost of being diligent.
- We never hide residual risk. Where a guarantee has an edge, we document the edge — in our code, our audits, and our conversations with carriers. Bounded honesty beats unbounded claims.
- We design for the worker first. Every feature that touches a worker's phone is informational, consensual, and private by architecture — while still serving the GC's site and the carrier's book.
- We build to audit grade, always. If a record can't survive an underwriter's scrutiny or a regulator's subpoena, it isn't done.
Seven subsystems. One operating system.
The gate decision — is this worker qualified, insured, and cleared? — runs on the scanning device itself, against an encrypted local ledger. No signal required. Decisions carry freshness rules: recent data decides normally; day-old data can still deny (an expired card is expired) but refuses to fake a green light — it demands human judgment instead. Every offline event is encrypted at rest, carries an idempotency key so it syncs exactly once, and enters the master ledger with the timestamp it actually happened.
Every consequential action — a credential approved, a certificate validated, a badge denied, an incident filed — becomes a classified, routed event. Events append to an immutable store; scores and dashboards are projections of that history, never hand-edited numbers. When an underwriting bundle cites a risk factor, the factor cites its events.
Companies never share a database — they share consented links. A link defines exactly what flows: vendor compliance to the linked GC, insured risk posture to the linked carrier, nothing to anyone else. Revoke the link, the flow stops. This is how one worker's renewed certification updates three companies' dashboards without any of them touching the others' data.
Machine learning reads every certificate — coverage rows, limits, expirations, endorsements — and a deterministic engine (never the model's self-confidence) decides what's proven, what's non-compliant, and what needs human eyes. A reviewer console handles the ambiguous minority with full attribution. Alias matching absorbs the industry's naming chaos — "Acme Electrical Co" and "ACME ELECTRICAL COMPANY, LLC" resolve to the same insured, deliberately.
GCs draw the site's boundary and its zones — crane swings, hot work, excavations, fall hazards — with types, permits, corrective guidance, and automatic expiration. Workers see them on a live map and get local, on-device alerts when they cross into one; nothing about their movement ever leaves their phone. Each morning, a daily briefing assembles the day's zones, operations, weather risks, and GC notes for every worker and subcontractor — authored once, read everywhere, tracked never. Hazard photos taken in dead zones queue on-device and are AI-analyzed the moment signal returns.
On demand or on schedule, Verisfort assembles a machine-readable risk package for a carrier: compliance posture, scored factors, workforce safety, exposure, enforcement history. Every bundle is SHA-256 hashed, audit-logged, and delivered over HMAC-signed webhooks with retries and a dead-letter store — or a scoped, rate-limited API. If it's in the bundle, it's traceable to the events that made it true.
Companies connect by exchanging a connect code out of band — handed over, never guessable. Resolution is rate-limited and rejections are deliberately uniform, so the system can't be mined for who exists on it. Claim tokens are stored as hashes only. Consent is the only door into a company's data, and it swings both ways.
The control panel your jobsites have been missing.
You already carry the responsibility — for every sub's insurance, every worker's qualification, every visitor at the gate, every hazard on the deck. What you've never had is the instrument panel.
Vendor compliance, live
See every subcontractor's insurance and compliance state as it is now — validated by AI, alerted before expiry, scored transparently. The certificate chase ends; the renewal reminder sends itself.
The gate, finally solved
Workers present a badge; your superintendent's phone answers green or red in under a second — with the reasons — online or in a concrete basement. Overrides are possible, documented, and audited.
Hazards that broadcast themselves
Draw a crane swing zone once; every affected worker's phone knows. Attach permits and corrective actions. Set it to expire when the pick is done. The morning briefing writes itself.
Risk you can see coming
Incidents, denials, expirations, hazard clusters, and fraud signals roll into one project risk picture — every factor's derivation one click deep, escalations on an SLA clock.
Less admin, more site
One system replaces the COI binder, the prequal portal, the orientation spreadsheet, the gate clipboard, and the morning-huddle handout — and syncs to Procore where your PMs already live.
Prove it once. Be trusted everywhere.
You've filled out the same prequalification form for the fifth portal this year. You've faxed — faxed — the same COI to three GCs in one week. You've paid to demonstrate, over and over, that you're exactly who you've always been. That era can end.
One consent code
When a GC or carrier wants to connect, you hand them your code. You choose every connection; nothing about your company is discoverable, searchable, or shared without it.
One insurance pipeline
Your COI is read once, validated once, and propagated to every GC you've linked. When it nears expiry, you hear about it before anyone else does — with time to fix it quietly.
One wallet per worker
Your crew's licenses, certifications, and training live in one place — photographed from the field, reviewed by your office, gating their badge automatically. Cleared once, cleared at every linked site.
Scoring you can argue with
Your compliance score isn't a mystery grade — every factor is visible, every input is yours to fix, and improving the input improves the score. Immediately.
And it costs you your diligence, nothing else. Verisfort doesn't charge you to be verified, and it doesn't make you re-verify because someone else's system can't remember you.
Operational risk data. Finally.
You price construction risk on claims history, financials, and experience mods — lagging indicators, all of them. The leading indicators have always existed: who's actually on the site, whether their qualifications are current, how the contractor handles hazards, how fast corrective actions close. They've just never been captured in a form you could use. Verisfort captures them at the source.
From jobsite events to underwriting signals
Every gate decision, credential state change, incident, hazard finding, and corrective action is an immutable, timestamped event. The risk engine transforms them into scored factors — incident rates, denial rates, training gaps, hazard exposure, fraud signals — with the full feature vector persisted per computation. Nothing is a black box; every tier is inspectable down to its inputs.
Delivery you can trust programmatically
Underwriting bundles are SHA-256 hashed and audit-logged at assembly. Webhooks are HMAC-signed per endpoint with automatic retries and a dead-letter store; the API alternative is scoped, rate-limited, and keyed by hash. A bundle you received is a bundle you can verify, replay, and defend.
A complement, not a replacement
Verisfort doesn't compete with claims history or property data — it fills the gap they leave: the operational present. Blend it into your models as the forward-looking signal set your actuaries have been approximating with proxies.
Consent-native by design
You see insureds who have linked to you, and prospects who have opted into visibility — never a scraped or inferred book. That's not a limitation; it's why the data is clean.
We audit ourselves the way you'd audit us.
In August 2026 we ran a full-system reliability audit across every critical subsystem — mobile, server, and shared — with a standing instruction: find the gaps, fix them in code, prove the fixes with tests, and publish the result including anything we chose not to fix. Here is that result, plainly.
| Subsystem | Verdict |
|---|---|
| Offline Access Control | Pass. Freshness rules enforced: stale caches can deny but never fake a green; encrypted store-and-forward with exactly-once replay verified under test. |
| Event-Driven Architecture | Pass, one documented residual. Durable outbox with backoff, dead-lettering, and idempotent consumers. The residual — a microsecond crash window between a domain write and its outbox row — is documented in the code itself, with the closing path identified. |
| Multi-Tenant Isolation | Pass. Every cross-tenant read path is link-gated and covered by rejection tests; fraud records cannot be cleaned up by the org they accuse. |
| COI Intelligence | Pass. Confidence is computed deterministically server-side — the model is never trusted to grade itself. |
| Hazard Zones & Briefings | Gap found, fixed, shipped. Hazard photos taken offline previously failed; they now queue encrypted on-device and are AI-analyzed on reconnect. The fix landed with tests the same day. |
| Underwriting Bundles | Pass. Hashing, audit logging, signed delivery, and event traceability verified; load-tested with zero server errors. |
| Consent-Gated Links | Pass. High-entropy codes, global rate limiting, uniform rejections, hash-only token storage. |
Our standing posture: residual risks are documented, bounded, and never hidden. When we find a gap, the fix ships with tests, and the gap goes in the record — because a system that claims perfection is a system nobody should underwrite on.
Built to underwriting grade.
Verisfort handles the records that decide who works, who's covered, and what risk costs. We treat that responsibility as an engineering specification:
- Encryption everywhere it matters. TLS in transit, encryption at rest — including the offline queues on field devices.
- Isolation by architecture. Tenant separation is enforced at the query layer on every request, not by convention. Cross-tenant flows exist only through explicit, revocable, consented links.
- Integrity you can verify. Underwriting bundles are SHA-256 hashed; webhooks are HMAC-signed per endpoint; badge tokens and session tokens are cryptographically distinct by design; secrets and claim tokens are stored as hashes only.
- An audit trail with no gaps. Every mutating request is logged by a global interceptor; overrides require reasons; exports are themselves logged. The trail is the product.
- Certification roadmap. Our SOC 2 and ISO 27001 programs are in active preparation — control implementation, evidence collection, and monitoring procedures are documented and operating today, ahead of formal certification. We built the discipline first; the certificate follows the practice, not the other way around.