Evidence-gated USDG working capital for physical trade, released milestone by milestone when the cargo's own signed sensor evidence clears an on-chain policy.




A financier's Paxos USDG reaches the exporter milestone by milestone, only when the cargo's own signed sensor evidence clears an on-chain policy. When something goes wrong the facility pauses itself, a zero-knowledge proof resumes it, and the buyer's single payment settles everyone and hands over the electronic bill of lading in one transaction. Live on Robinhood Chain Testnet, ten contracts source-verified. Production build, ready for use; mainnet release is next.

https://cargoflow-mcp.adoranto737.workers.dev/mcp (25 tools, holds no keys) · add it to claude.ai
The Asian Development Bank puts the global trade finance gap at $2.5 trillion in 2025, about 10% of global trade, with 41% of SME applications rejected. In India half of B2B sales are on credit with 52-day average payment terms (Atradius, 2025), and biopharma loses about $35 billion a year to cold-chain failures (IQVIA). A lender advancing money against a reefer container sees paperwork, not the container, so it lends blind or not at all. CargoFlow lets the cargo's own sensor evidence decide how much capital is available, on chain, milestone by milestone.

Meera ships vaccines from Pune through Nhava Sheva to Singapore at 2 to 8 °C. Daniel would lend against the shipment if he could see it. Wei Lin buys it. Everything they do below is a real contract call on Robinhood Chain Testnet.
Reference numbers: a 100,000 USDG invoice, a 40,000 USDG facility in five milestones of 8,000, a 3% fee. The live runs use the same mechanics at testnet scale.

Meera registers the shipment and reveals a commit-reveal cold-chain policy (2.0 to 8.0 °C, evidence score ≥ 75, conflict ≤ 30%, humidity ≤ 85%, shock ≤ 3 g). Daniel deposits the whole facility in USDG into the ReceivableVault. Milestones can be tied to a place on the route.

The reefer's logger signs every reading with its device key. Eight readings per sensor close an epoch; the probes are fused with Dempster-Shafer, their disagreement measured and the epoch scored out of 100. Only a salted Poseidon root and the score go on chain.

Pass the policy in the right place and a tranche goes to Meera. The FinancingController re-checks the committed epoch against the on-chain policy itself. Wrong place? The milestone waits: neither a failure nor a pause.

Off Sri Lanka probe-1 reaches 11.7 °C while probe-2 holds at 4.6. Conflict hits 74.8%, the score falls to 48 and the facility pauses: releases revert. The AI monitor can only make an outcome stricter, through a key that can do nothing but pause.

Once probe-2 has eight fresh in-band readings, the service proves in zero knowledge that they sit inside the band without revealing any of them. Meera gets a “Proof ready” alert and signs once; the contract verifies the Groth16 proof, bound to this exact pause, and releases resume.

Wei Lin confirms delivery and pays once. That payment runs the waterfall: principal plus fee to Daniel, the rest to Meera, in one transaction.

The carrier's electronic bill of lading (ERC-721) is bound into escrow and leaves for Wei Lin inside her payment transaction: documents against payment, enforced by the contract.

An insurer's default cover pays min(cover, drawn principal). Parametric cover pays after N consecutive failed epochs, proven from the EvidenceRegistry's commit order.

Wei Lin signs in with a passkey (no extension) and pays from a ZeroDev Kernel smart account: three ERC-4337 user operations on the live testnet, using Robinhood Chain's RIP-7212 P-256 precompile.

Add the remote MCP server as a custom connector and ask. Claude reads the fleet, explains a pause and prepares unsigned transactions with a link to sign in the app. It never holds a key.
What makes it different:

Paused, in plain words. Why the facility paused (score 48, conflict 74.8%) and what each party does next.

Recovered. “Groth16 proof verified on-chain”: eight hidden readings proven in band, none revealed.

Settled with a passkey. CF-SG-VAX-0401, paid by Wei Lin's passkey smart account.
Also live: exporter wizard with cold-chain templates, financier portal with settlement preview, carrier bills of lading, a financing market with fee guidance, the arbiter console, settlement certificates (PDF), GS1 EPCIS 2.0 export and import, and an in-app notification centre.

Recorded on a real phone during a live testnet run: two RELEASED alerts and a PAUSED alert arrive with their transactions within seconds of the chain events, then RECOVERY_READY with a link that opens the shipment on the recovery card for Meera to sign. Also email, Slack and signed webhooks. Bot: @Cargo_FlowBot.

A public remote MCP server (25 tools) lets Claude read shipments, evidence, cover and the market, and prepare unsigned transactions with a link to sign them in the web app. Claude Code: claude mcp add --transport http cargoflow https://cargoflow-mcp.adoranto737.workers.dev/mcp

The chain is the financial source of truth. Each party signs its own money moves from the web app, straight to the contracts. The Go service scores evidence and acts on chain only through three role-limited keys (commit epochs, pause only, release and submit proofs). Postgres holds operational evidence and is reconciled from chain events; the facility view reads the chain directly, so a lagging indexer can never show money that did not move.
Stack: Solidity 0.8.28 + Foundry + OpenZeppelin 5.4 · Circom + Groth16 · Go 1.26 · Next.js 16 on Cloudflare Workers (wagmi, viem) · ZeroDev Kernel passkeys · Rust Stylus engine · TypeScript and Python SDKs.
Contracts v3, deployed 3 October 2026, every source verified on the explorer:
0x06DaF9462eCF2434ED0314a005Bf762cCDEd7Fe10x167783DB96E27f36f78C8E5F6f1575b0c45a81510x3930f06dC9Deb7b7587AD5a04B05350CaACc7BA20x74be1E30bEeDc004447F0427Dd6EBC62CCDabA250x2B9E2B70b6fF48DaD9847944bbEcE16c9f4396F30xF00eE4c686cE4EaC0B161dEe757e19A1C600d0f60x4e4f09Da01f466275b586b0cc32613a90b1B69e50xD176E4e02f97F12462e68014F92B2A13A664552e0x72278056f6537e4F3437b96898BB439ab7BF68A90x6b334b4C73c27CB297470140c86311075408b0500x7E955252E15c84f5768B83c41a71F9eba181802FArbitrum Sepolia extensions (Sourcify-verified):
0x5c1C12448D27c2E8519c1E471078Bf42E685D2070xE0E90F3E57e3a040AD99FE4384bE96Dd97002f740x2f7cac603654ec106da242cd0b16044b31f7608dLive runs, every transaction linked:
CF-SG-VAX-0202, the film's shipment through the live website: register, deposit, bill of lading, two releases, excursion and pause, resume with a Groth16 proof, three more releases, settlement.CF-SG-VAX-0401, a passkey payment: smart account 0xBCf2…5E56 deployed, confirmed delivery, approved and settled as three ERC-4337 user operations, paying 0 gas.CF-LIVE-1791029236301, the v3 reference run through the hosted API: open the settled dashboard.


366 contract tests (unit, fuzz, eight invariants, real-proof integration) · 25 circuit tests · 296 frontend unit and 18 Playwright end-to-end tests · SDK 92, MCP 27, gateway 36, Python 25, Fhenix 19, GMX 20 · circuit of 13,494 constraints proving in about 1 s · ZK resume about 0.25 M gas · Slither triaged.
▶ Watch the film (5:30): the cast, the real source pages, the mechanisms animated, the live website recorded end to end, the Telegram alerts on a phone, CargoFlow inside claude.ai, and the proof on chain. Built in code with Remotion.
Arpit Singh, founder. Designed and built CargoFlow end to end: contracts, ZK circuit, Go evidence service, web app, SDKs, MCP server and the film.
MIT licensed. Full README, docs and role guides on GitHub.
Built from scratch during the Buildathon (30 Sep to 4 Oct 2026, 278 commits). Everything below was designed, built, deployed and tested in that window:
Smart contracts v1 to v3 on Robinhood Chain Testnet: 10 contracts source-verified (FinancingController, ReceivableVault, EvidenceRegistry, PolicyEngine, ShipmentRegistry, Groth16Verifier, CoverPool, DeviceRegistry, EBLRegistry, CargoFlowAccess), settling in Paxos USDG; 366 tests incl. fuzz and eight invariants.
Zero-knowledge recovery: Circom circuit (13,494 constraints, ~1 s proofs) verified on chain in ~0.25M gas; proofs are prepared automatically and the exporter signs once.
Go evidence service on Render: signed telemetry, Dempster-Shafer fusion and scoring, a stricter-only AI monitor, prover worker, outbox, indexer, REST + WebSocket API (OpenAPI 3.1).
Next.js 16 web app on Cloudflare Workers: exporter, financier, buyer, carrier, arbiter and market portals; ZeroDev passkey smart accounts (a live passkey payment via 3 ERC-4337 user operations).
Developer platform: remote MCP server (25 tools) used from claude.ai; @cargoflow/sdk, @cargoflow/mcp, @cargoflow/gateway on npm and cargoflow on PyPI; Telegram, email, Slack and webhook alerts.
Arbitrum Sepolia extensions: Stylus EvidenceEngine (Rust) 0x2f7cac603654ec106da242cd0b16044b31f7608d, Fhenix ConfidentialInvoiceTerms 0x5c1C12448D27c2E8519c1E471078Bf42E685D207, GMX GMXHedgeVault 0xE0E90F3E57e3a040AD99FE4384bE96Dd97002f74.
Proof: full lifecycles settled live on testnet (excursion, pause, Groth16 resume, settlement, bill of lading to the buyer) with every transaction linked; v1.0.0 release, a 5:30 film and a 21-slide funding deck.
Not raised yet: bootstrapped by the founder, pre-revenue. Applying for the Buildathon prize and a milestone-based Arbitrum grant. Plan for the funds: 35% audit and public ZK ceremony, 25% real logger pilots and hardware, 20% Robinhood Chain mainnet launch and first facilities, 10% legal (MLETR opinion on the bill of lading), 10% team and infrastructure, released milestone by milestone. A pre-seed round follows the first mainnet facilities with an outside financier.