
Product
Microsoft Teams Notifications Are Now Available in Socket
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.
Cryptographic dispute evidence for autonomous fleets. Tamper-evident spatial receipts for AV insurance, logistics proof-of-delivery, and AR anti-cheat. 91% spoof detection in stress tests at fleet scale.
Cryptographic dispute evidence for autonomous fleets.
When a robot causes an incident — a delivery goes missing, an AMR damages inventory, an AV is involved in a collision — the question that decides who pays is always the same: where was it, exactly, and can you prove it?
GridStamp is the evidence layer. Every operation produces a tamper-evident spatial receipt: HMAC-signed camera frames, Merkle-rooted memory, cryptographic proof-of-location. The receipts hold up under replay, adversarial patches, depth-injection, and GPS spoofing — tested at fleet scale.
In a 92-day simulation with 5,500 agents across 20 fleets and 8 cities, parameterised with publicly disclosed fleet data from Waymo, Tesla, Starship Technologies, Coco Robotics, Serve Robotics, and commercial drone operators (GridStamp is not affiliated with or endorsed by any of them; parameters come from public filings and press releases):
Receipts are designed to be admissible-grade evidence for insurance disputes, SLA audits, and regulatory investigations. Final admissibility is jurisdiction-dependent and should be confirmed with counsel for your underwriting market.
| Buyer | Problem GridStamp solves |
|---|---|
| AV / robotics insurance underwriters | Reduce loss ratio by resolving location-of-incident disputes with cryptographic evidence instead of he-said/she-said. |
| Logistics visibility platforms (freight, last-mile) | Give shippers verifiable proof-of-delivery their customers can't dispute — upgrade ETAs from claims to receipts. |
| AR gaming & location-based apps | Stop the ~9% of top players who GPS-spoof. Our stress test catches 91% of spoof attempts. |
If you're evaluating GridStamp for a pilot, contact: omiagbogold@icloud.com.
Six layers, each cryptographically isolated:
| Layer | What it does |
|---|---|
| Perception | HMAC-signed camera frames, stereo depth fusion, dual-camera support |
| Memory | 3-tier spatial memory (short/mid/long-term) with Merkle tree integrity |
| Navigation | A* and RRT* pathfinding on 3D occupancy grids, place cells + grid cells |
| Verification | SSIM + LPIPS + depth comparison for spatial proof-of-location |
| Anti-Spoofing | Replay detection, adversarial patch detection, depth injection, canary honeypots |
| Gamification | Trust tiers, capability badges, streak multipliers, zone mastery, fleet leaderboard |
npm install gridstamp
import { createAgent } from 'gridstamp';
const agent = createAgent({
robotId: 'DLV-001',
cameras: [{ type: 'oak-d-pro', role: 'foveal', /* ... */ }],
hmacSecret: process.env.GRIDSTAMP_SECRET, // min 32 chars
}, cameraDriver);
// Capture and verify
const frame = await agent.see();
const proof = await agent.verifySpatial();
// Settle payment only if spatial proof passes
const settlement = await agent.settle({
amount: 15.00,
currency: 'USD',
payeeId: 'merchant-001',
spatialProof: true,
});
Robots earn trust through verified operations, similar to a credit score:
| Tier | Points | Fee | Max Tx | Verification |
|---|---|---|---|---|
| Untrusted | 0 | 2.5x | $10 | Every operation |
| Probation | 100 | 2.0x | $50 | Every operation |
| Verified | 500 | 1.5x | $200 | Every 3rd |
| Trusted | 2,000 | 1.2x | $1,000 | Every 5th |
| Elite | 5,000 | 1.0x | $5,000 | Every 10th |
| Autonomous | 10,000 | 0.8x | $25,000 | Spot checks |
All tier changes are HMAC-signed. Spoofing attempts result in immediate two-tier demotion.
Every spatial proof links to the previous via SHA-256 hash chain. A robot's entire operational history becomes a tamper-evident linked list — if any proof is modified, the chain breaks.
import { ProofChain } from 'gridstamp';
const chain = new ProofChain();
chain.append(proof1); // genesis
chain.append(proof2); // links to proof1
chain.append(proof3); // links to proof2
const result = chain.verify();
// → { valid: true, chainIntegrity: 1.0, length: 3 }
This means a fleet operator or insurance underwriter can verify the complete history of a robot's spatial claims — not just individual proofs, but the unbroken chain between them.
deriveKey(master, 'frame-signing'))LocationSpoofDetector) catches GNSS/GPS spoofing and teleport attacks on the pose claimgridstamp # Full SDK
gridstamp/perception # Camera + depth
gridstamp/memory # Spatial memory + place/grid cells
gridstamp/navigation # Pathfinding
gridstamp/verification # Spatial proofs + settlements
gridstamp/antispoofing # Threat detection
gridstamp/gamification # Trust tiers + badges + leaderboard
Apache 2.0 — see LICENSE.
Copyright 2026 J&B Enterprise LLC.
FICO is a registered trademark of Fair Isaac Corporation. GridStamp's trust tier system and MnemoPay's Agent Credit Score (300–850, FICO-style behavioral scoring) are not affiliated with or endorsed by Fair Isaac Corporation.
GridStamp ships a first-class Claude-driven agent wrapper that orchestrates the full verification pipeline without any manual glue code.
Quick start (5 lines):
import { runProofAgent } from 'gridstamp/agent';
const result = await runProofAgent({
robotId: 'DLV-001',
hmacSecret: process.env.GRIDSTAMP_SECRET,
sensorReader: async (sensorId) => myCameraDriver.read(sensorId),
});
// result.status → 'pass' | 'fail' | 'spoofing_detected'
The agent (claude-sonnet-4-6) runs four tools in sequence — read_sensor → verify_spatial_proof → check_antispoofing → write_attestation — and returns a typed AttestationResult with confidence score, spoofing signals, and chain length.
Audit log: every write_attestation call appends an NDJSON record to ./proof-audit.ndjson (path configurable). This is the file your claims team reads — immutable, timestamped, one record per robot attestation.
See the full runnable example: examples/agent-proof-of-presence.ts
ANTHROPIC_API_KEY=sk-... npm run example:agent
FAA Part 108 (BVLOS) requires every operator to keep tamper-evident position logs alongside their existing Remote ID broadcast. GridStamp signs each of the five F3411-22a message types (BasicID, Location/Vector, SelfID, System, OperatorID) with an Ed25519 identity key persisted at ${GRIDSTAMP_PERSIST_DIR}/remoteid-ed25519.key, then batches them into a COSE Merkle Tree Proofs-style receipt (tracking draft-ietf-cose-merkle-tree-proofs-18).
import { remoteid } from 'gridstamp';
const key = remoteid.loadKey();
const log = remoteid.sign(
{ kind: 'operator_id', operatorIdType: 0, operatorId: 'FA1234567890' },
key,
);
const ok = remoteid.verify(log, key.publicKey);
const batch = remoteid.batchRoot([log]);
FAQs
Cryptographic dispute evidence for autonomous fleets. Tamper-evident spatial receipts for AV insurance, logistics proof-of-delivery, and AR anti-cheat. 91% spoof detection in stress tests at fleet scale.
The npm package gridstamp receives a total of 74 weekly downloads. As such, gridstamp popularity was classified as not popular.
We found that gridstamp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.

Security News
Socket CTO Ahmad Nassri joins AppSec leaders at Black Hat to discuss active malware, package manager risks, and software supply chain defense.