Skip to content

Trust manifest · the standard we hold ourselves to

Trust is architecture, not a promise.

Six commitments, each one enforced by a system rather than a sentence. Identity is verified before money moves. Money sits in licensed custody. Every material action is signed. Your data is encrypted and row-isolated. Nothing is designed to trick you. And if we disagree, there is a stated forum.

HACP™ receipts liveLicensed escrow custodyRLS on every table
01

Identity verified

Persona KYC before any money moves.

Every party is identity-verified through Persona before a fee, an assignment, or a distribution is processed. Verification status is a state on the record — not a checkbox someone can claim. Where a transaction requires it, entity documents and authorized-signer proof are collected too.

Provider
Persona (government ID + liveness)
Screening
OFAC / SDN on every party
Threshold
Doc P AML program at $10,000+ cash
02

Money in licensed custody

Stripe and Qualia/Endpoint escrow — never CookinCap directly.

Transaction funds are held and disbursed by a licensed escrow and title company. Subscriptions run through Stripe. CookinCapital does not take custody of client transaction funds, and brokerage trust funds at CookinCap Real Estate LLC sit in a DRE-compliant trust account with monthly reconciliation and an annual CPA audit.

Escrow / title
Qualia · Endpoint (licensed, insured)
Card + subscription
Stripe (PCI DSS Level 1)
Brokerage trust
DRE-compliant · monthly reconciliation · annual CPA audit
03

Every action audit-signed

An HACP™ Ed25519 receipt on every material action.

Analyses, document executions, fee agreements, disclosures, routing decisions and distributions each emit a cryptographic receipt: actor, action, inputs hash, model and version, timestamp, and an Ed25519 signature. The chain is append-only, so a record can be verified later — including by you, and including against us.

Signature
Ed25519 · append-only chain
Patent
HACP™ US #10,290,222 · pending #19/296,986
Export
Receipt export available on every plan
04

Your data encrypted

KMS envelope encryption, row-level security on every table.

Data is encrypted in transit (TLS 1.2+) and at rest, with sensitive fields under KMS envelope encryption and per-tenant keys. Row-level security is enforced on every table, so authorization is a database guarantee rather than an application promise. Access is least-privilege, logged, and reviewed.

At rest
AES-256 · KMS envelope · per-tenant keys
In transit
TLS 1.2+
Authorization
Postgres RLS on every table · least-privilege access logs
05

No dark patterns

Full fee transparency. Disclosure BEFORE decision.

Fees are published, then signed in Doc H before engagement. Consent boxes are never prechecked. Cancellation is as easy as signing up. There are no fake countdowns, no confirmshaming, no hidden auto-renewal, and no marketing claim of a return, an approval, or a closing date that we cannot guarantee — because none of us can.

Fees
Published on /pricing · fixed in Doc H before engagement
Consent
Never prechecked · versioned and timestamped
Exit
Cancel in-app · written withdrawal honored at no cost
06

Disputes → JAMS arbitration

Orange County, California. Binding. Jury waived.

Doc Q governs disputes: binding arbitration before JAMS in Orange County, California, under California law, with the right to a jury trial and to participate in a class action knowingly waived by both sides. Small-claims and injunctive carve-outs are stated in the document rather than buried.

Forum
JAMS · Orange County, California
Governing law
California law governs. Venue for any proceeding not subject to arbitration is Orange County, California.
Waivers
Jury trial waived · class action waived · mutual

What we will and will not do

Six sentences you can hold us to

These are not aspirations. Each one maps to a control in the platform or a clause in a document you can read on this site.

  1. 01

    We will not claim an outcome we cannot control — no guaranteed approvals, returns, valuations, or closing dates.

  2. 02

    We will tell you which entity you are dealing with, and which of them holds the license for the work being done.

  3. 03

    We will disclose a dual role under Doc J before a deal proceeds, or the deal does not proceed.

  4. 04

    We will attach Doc M to every AI analysis, because an estimate is an estimate and an appraisal is not.

  5. 05

    We will honor a written withdrawal at any time, at no cost, without asking you to justify it.

  6. 06

    We will answer a security or privacy question from a real person, in writing, within one business day.

Read the documents

Every policy, in full text, on this site

Nothing here is a summary of a document held somewhere else. These are the operating documents themselves.

Doc L

Terms of Service

Doc N

Privacy + CCPA

Doc M / G

AI + Investment Disclosures

Doc O

Fair Housing

Doc Q

Arbitration

Doc P

AML Acknowledgment

Full technical detail on request

Security architecture, key management, receipt verification, subprocessor list, incident response, and audit posture — ask and a person sends the document. security@cookincap.com

Privacy requests: privacy@cookincapital.com · Legal notices: legal@cookincapital.com

HACP™ Patent 10,290,222Persona KYCStripe PCI DSS L1Qualia / Endpoint EscrowPostgres RLSJAMS · Orange County CA