umfr.ioPrivate credit / verification layer

The independent verification layer for private credit.

A deterministic engine that recomputes what borrowers report against the documents that govern them — and refuses to judge what it cannot verify.

Private credit has crossed ~$3Tand is still climbing — and in 2025 it posted a record 9.2% default rate (Fitch, reported March 2026), a systemic asset class without the verification infrastructure public markets take for granted.

Verification resultRECOMPUTE
Reported adjusted EBITDA$100.0M
Recomputed (one add-back removed)$92.4M
Exception surfaced$7.6M
Add-back not supported — flagged for review
MockupIllustrative example. Not a real company.
Why now

Private credit has reached ~$3Tand is still climbing. As of mid-2026 it had become a systemic asset class — without the verification infrastructure public markets take for granted. Yet it still runs on PDFs, spreadsheets, and trust.

Why now: the asset class outgrew its own verification infrastructure — it scaled to trillions faster than the machinery to trust its numbers was built. The credit events of the past year turned the cost of that gap from theoretical to concrete. And the regulatory direction — the FSB flagging the opacity of private-credit markets, diligence expectations tightening — runs toward more independent verification, not less.

In late 2025, that caught up with the market.

First Brands

Collapsed into Chapter 11 in September 2025, estimating liabilities of $10-50B on its own petition. A court-appointed examiner later alleged roughly $2.3Bof factoring fraud — fabricated invoices and the same receivables pledged to more than one lender.

Tricolor

Collapsed in 2025 after DOJ charges that the same auto collateral was pledged to multiple lenders — roughly $2.2B pledged against $1.4B of real collateral.

Both were diligenced. Both reported clean.

The lesson the market drew: reported and verified are not the same thing.

The case that made it concrete

From First Brands' public Chapter 11 filing alone, UMFR's engine certifies a debt floor of $8.4B and reconstructs a ceiling of $10.7B — the gap driven by ~$2.3B of factoring disclosed only in prose, invisible to a headline reader (+27.2%floor to ceiling, every figure cited to its source page). The court-appointed examiner's report (filed April 27, 2026) independently alleges ~$2.3Bof factoring fraud — external corroboration of the scale and direction the engine surfaces from public documents alone — and names the enabling failure, in the examiner's words: lenders 'typically did not see the actual underlying invoices or verify the data.' First Brands' founders were separately charged by the DOJ (SDNY, January 2026; not adjudicated).

We do not claim to have predicted the fraud. We claim something more useful: the verification that would have surfaced it was mechanically possible, on documents lenders already had — and no one was positioned to run it.

The questions a credit team asks

Five questions every credit review turns on. Each one maps to a surface you can open and read — a directory of evidence, not a promise.

Completeness
parsed from the filing

Is every material item accounted for — and does the tool say what it did not verify?

The coverage statement resolves every material item into one of five states, and states what it did not verify as clearly as what it did.

See the coverage statement
Definition
parsed from the filing

Does the covenant math follow the agreement's own definitions?

Covenant-defined EBITDA recomputed against the credit agreement's own definition, term by term — and how much of it a lender cannot independently recompute.

See the covenant card
Collateral
reconstructed — no document parsed

Does the pledged asset exist, and exist once?

The arithmetic that catches a double pledge — several claims summing past the value of the pool behind them — shown on a reconstructed public case. Detecting the same asset pledged across different lenders needs a cross-lender record, which public data cannot provide; this is the mechanic, not that detection.

See the register lens
Consistency
reconstructed — no document parsed

Do the documents hold together — and agree with one another?

The same figure reconciled across two documents — a clean pair stays silent, a disagreeing one is surfaced for review.

See cross-document reconciliation
Arithmetic
parsed from the filing

Do the reported numbers actually recompute?

A full series of executed compliance certificates recomputed from the borrower's own components — reconciled, or declined, never guessed.

See the compliance-cert recheck
Proof

Proven on real public data — across how credit reporting fails

One engine, run deterministically — each proof below is a shipped output, every figure traced to source. Every report and covenant card carries a receipt you can recompute in your browser to confirm it is unaltered since generation.

Tier 1 — deterministic-public · public SEC XBRL · zero compute cost · reproducible

These run on an issuer's own public SEC filings at zero compute cost. The worked cases are open on the demo; running the engine on a new issuer is by request.

The engine reads IFRS filers by their home ticker at the financial-statement tier — demonstrated on a real Form 20-F reporter (Ads-Tec Energy) — and is architecturally standard-agnostic. Definition-level covenant support for IFRS is a bounded extension, to be measured on a real IFRS agreement before it is claimed.

The composite — the flagship, live

The whole deterministic-public battery on one issuer's own public filings — a real, publicly-adjudicated collapse next to a clean baseline. On Synchronoss Technologies (SEC-adjudicated, $12.5Mpenalty), the engine surfaced that later filings restated previously reported figures for the same fiscal years — revenue FY2015 revised down 35.6% ($578.8M to $372.6M), net income down 92.3% — a material self-disclosed revision, surfaced deterministically. Beside it, a clean public issuer: the same battery, no restatement surfaced. The difference is the signal.

Synchronossnamed (adjudicated)

Material self-restatement surfaced

Revenue FY2015: $578.8M → $372.6M (-35.6%)
Net income FY2015 (-92.3%)
Clean baselineby sector

No restatement surfaced

The same battery on a clean public issuer — the difference is the signal.

Restatement discontinuity

A restatement is the public-visible trace an accounting revision leaves in the structured record — the filer revising its own reported figures for a closed period through an amended annual report. The engine surfaces it deterministically, on public data alone, as an anomaly warranting a question — never an assertion of cause.

The Coverage Statement — live

Every material item resolved into one of five states — VERIFIED (recomputed, reconciles), DISCLOSED (filer-tagged, read and surfaced), INFERRED (structurally derived), DECLINED (present, not classifiable, explicitly not clean), ABSENT (not tagged). The tool states what it did NOT verify as clearly as what it did.

See the live coverage statement →

What runs on public data — and what needs the documents

Tier 1 runs on an issuer's own public SEC filings, deterministically, at zero compute cost — the worked cases are open on the demo; a run on a new issuer is by request. Tier 2 goes deeper, on the source agreements and schedules public data does not carry — the document path is built and running today, on the borrower's own documents. Both are deterministic in their output. Neither uses a language model to decide the numbers a reviewer sees. We are as clear about which tier a result comes from as we are about the result.

Tier 2 — document / agreement forensics

The deeper checks the engine runs on a borrower's own agreements, schedules and source documents — built and shipping, demonstrated here on real public cases, every figure cited to its source.

What the document path does today

A lender hands over the credit agreement, its amendments, and the compliance certificates. The engine reads them in memory and returns a structured read in which every layer lands in one of three explicit states — run (a built check consumed a supplied document and produced a result), reserved (a check we have not built yet, named as a reserve, never omitted), or absent (a built check with no document to consume, a gap the lender can close). Nothing is silently skipped, and a state is never a verdict.

Before it computes anything, the engine identifies what each document actually is by reading it — a credit agreement, a compliance certificate, a borrowing-base certificate, or something it sets aside with context; and within the credit-agreement family, a base agreement, an amendment, an amended-and-restated, a joinder, or a conformed copy, telling a guaranty apart from an amended-and-restated.

A covenant is recomputed against the operative amended text, and where the chain cannot be shown complete the engine declines to certify completeness and says so. All three public cases resolve as chain-complete, so the decline does not fire on them — the same discipline the rest of the page runs on: silent when things are clean, speaking only when they are not.

On a real resolved Consolidated-EBITDA definition, ~90% of the terms are borrower-certified or defer to GAAP and cannot be independently recomputed by anyone — the measured size of the problem, and why the private documents are the business.

How your documents are treated
Receipt-provenance honesty. A private result is marked as the unverified-provenance class, visibly distinct from a public SEC-filed receipt — the system says, on its own output, that the source was your private document and not an independent public filing.
No persistence. The bytes live only in memory; nothing is written to disk or blob storage; logs carry counts and states only, never document contents or a filename.
Session isolation. The raw filename is never read; files are handled positionally; only the anonymised borrower label is carried.

The office-format front end — a scanned-PDF, spreadsheet, or OCR'd certificate from a private borrower, with no public XBRL to cross-check — is scoped, not built: it will be measured on a real lender certificate before it is claimed.

1

Definition-level covenant forensics

A covenant is only as good as its definition. UMFR recomputes each ratio the way the credit agreement defines it, from disclosed dollar components.
  • Invesco— the agreement's Covenant Adjusted EBITDA runs +50.7% above plain GAAP EBITDA ($1,557.0M vs $1,033.0M); both covenants recompute as comfortably compliant — a difference of definition, not a deficiency.
  • Flow — an agreement-governed add-back of 31,400 is larger than the entire 25,486 Adjusted EBITDA it sits inside. Surfaced for review, never asserted as a breach.
  • Yellow— a capped add-back appears to exceed its stated cap: a cap-breach signal on a presented measure (a management deck under waiver), never an in-force or adjudicated breach.

See a covenant teardown on Paya Holdings — from its public credit agreement

A finished covenant read on a named public issuer, assembled from its public SEC filings — the share of the resolved Consolidated EBITDA definition a lender cannot independently recompute, with a receipt whose output hash you can recompute in your browser. A signal for review, not a credit rating.

See the Paya Holdings teardown →
2

Hidden leverage

Off-balance-sheet financing is where reported leverage and true leverage part ways. From First Brands' public Chapter 11 filing the engine reconstructs roughly $10.7B of obligations, lifting leverage from an on-balance 5.38x to a certified 7.46x and an uncertified ceiling of 9.49x. Across the public filer universe, UMFR maps $68.1B of disclosed supplier-finance obligations across about 140filers — the disclosure category implicated in 2025's failures.Figures as reported for Q4 2025; pinned snapshot retrieved June 21, 2026.
3

Document authenticity

Some documents foot internally and are still forged. Peregrine's customer-account statement tied out on its own — the fabrication (~$221.8M reported against ~$6.3M actually on deposit) surfaced only when the same figure was reconciled across two documents. Single-document checks pass it; cross-document reconciliation catches it. The same check has caught an adjudicated case: the SEC found Satyam had reported $379.6M in one Bank of Baroda account that actually held $10.8M— a fabricated statement against the bank's own record, on an SEC-settled matter.
4

At-scale discipline

Discipline is staying silent when the data is clean. Run across 346,646 real loans from 7public securitization sponsors — prime and subprime — the engine returns zero false positives. Seed synthetic fabrication into the same pools and every signal trips. The engine stays silent where things are clean, and speaks only where they are not.Pinned snapshot retrieved June 21, 2026.
5

Compliance-certificate recheck

We ran every one of the twenty consecutive quarters of Flow International's executed compliance certificates available on EDGAR — the whole series, not a chosen window. Eleven consecutive quarters, Q4 FY2011 through Q2 FY2014, reconcile: the recomputed leverage ratio and the re-summed EBITDA build-up match the borrower's own stated figures in every one, across ratios moving from 0.13 to 1.14. The nine older quarters use a layout carrying no itemized calculation, and the engine declines all nine rather than guessing. Both outcomes are committed as fixtures.

Structural early-warning — a capacity read, not a recompute

Some risks are structural — written into the agreement before anything goes wrong. UMFR reads agreement text for the capacity for a liability-management move: J.Crew's 2011 term loan grants the structural room for a dropdown, so the reader fires; Kontoor's 2019 agreement carries the blocker, so it stays silent. A read on capacity, not a claim that anything occurred.

See it run

Thirty-one worked cases are open to read — finished verifications on real public records, every figure traced to source. Running the engine on an issuer of your choosing is by request, so the compute goes to people who are actually evaluating it.

Different issuers, different credit types, one engine — every figure traced to source.

The layer

As of 2026, several entrants now stake out this ground. The field is contested, not empty. Setpoint and Cascade Debt both build verification infrastructure for private credit — and both work at the collateral and loan-tape layer: validating the asset pool a borrower submits, checking pledged collateral, reconciling loan-level data against supporting files. That layer matters. UMFR works at a different one: it verifies the issuer's own reported financials, recomputed from the public source directly — not from a tape the borrower chose to submit — and commits publicly to deterministic verification with no language model in its output. Independent, at the issuer level, reproducible by anyone. That combination we have not seen an incumbent commit to.

At the document tier — on the source agreements public data does not carry — UMFR recomputes covenant-defined EBITDA against the credit agreement's own definition, and states how much of a borrower's covenant headroom rests on management-certified figures that cannot be independently recomputed. That definition-level covenant forensics we have not seen an incumbent offer.

One engine, six layers

Verification is the foundation, not the whole building — the first of six modules, and where the build has to begin. A verified record makes a registry meaningful, a registry makes monitoring possible, and only a verified, registered, monitored market can be trusted enough to trade. VERIFY is the wedge; UMFR is building the infrastructure layer for private credit, and verification is module one.

VERIFYBuilt

Independently recompute what borrowers report against the documents that govern them.

REGISTERRoadmap

A registry of verified instruments — a corporate-credit lien-leakage focus, with privacy-preserving collision checks.

COMPLYRoadmap

Turn verified data into the regulatory and compliance reporting lenders and insurers must produce.

EXPANDRoadmap

Independent credit assessment and indices built on verified data.

CONNECTRoadmap

The deterministic fact layer any AI tool can call to ground an extracted figure.

TRADERoadmap

A neutral venue where verified instruments can change hands.

Detectors get copied; institutions compound.

Five verification levels

An open framework UMFR publishes and uses — and one the market may adopt — but not an industry-adopted standard. Each level states what it claims, what it does not, and where liability sits. A case earns its level from its own artifacts; a level is never granted.

L1Document Present
Claims

The document has been received and stored in the system.

Does not claim

Does not claim the document is authentic or complete.

Liability

None beyond storage.

L2Data Extracted
Claims

These values were extracted from the document text by the pipeline, each carrying a source page and quote.

Does not claim

Does not claim the values are correct or the document truthful.

Liability

Extraction quality only.

L3Cross-Referenced
Claims

The extracted data is consistent across the documents provided and passes the internal recompute / reconciliation checks that ran.

Does not claim

Does not claim the underlying business reality matches the documents.

Liability

Cross-reference accuracy.

L4Anomaly-Cleared
Claims

No statistical anomalies, fabrication signals, or duplicate-pledge patterns were detected in the data.

Does not claim

Does not claim the absence of sophisticated fabrication that the data patterns may not surface.

Liability

Methodology, not outcomes.

L5UMFR Verified
Claims

The full pipeline ran and every check passed or its warnings were acknowledged; the documents meet UMFR's verification standards under the stated methodology.

Does not claim

Does not claim investment suitability and does not constitute advice.

Liability

Per the disclaimer model.

Who it's for

Primary

Lenders & credit funds

Direct lenders and credit funds verifying collateral and borrower reporting before they commit — and monitoring it after.

Secondary

Insurers & allocators

PE-owned insurers and institutional allocators who must now demonstrate independent diligence as regulators tighten (NAIC's framework takes effect in 2026).

Channel

Fund administrators & advisors

Fund administrators, ODD teams, and lenders' counsel who run diligence on others' behalf and need a verifiable, repeatable record.

Founder

Who's building it

UMFR is built by a founder with two decades of executive and board-level leadership in banking, financial services, and beyond — 15 institutional board seats across 8 jurisdictions.

At BTA Bank he served on the Management Board through the bank's $11.1B international debt restructuring — advised by Lazard and White & Case — worked at executive level on the recovery from the Ablyazov fraud, one of the largest fraud cases in English legal history, and supervised the bank's full group of subsidiaries across eight jurisdictions. A forensic audit had uncovered a ~$10B hole; the recovery — pursued through Hogan Lovells and White & Case with international forensic accountants, across multiple jurisdictions — returned over $6B across seven of them.

That fraud was found the only way it could be found then: forensically, after the collapse, by people reading documents against each other across jurisdictions. Working that collapse from the inside is where UMFR comes from: he saw first-hand how far a borrower's reported numbers can sit from the real ones before a credit event surfaces the gap, and how hard independent verification is exactly when it matters most — the problem UMFR is built to solve. UMFR does the same reconciliation before — deterministically, on the source documents, every figure cited.

What UMFR is — and isn't

A signal, not a rating.

The VERIFY Score is a triage signal that tells a reviewer where to look. It is not a credit rating, and UMFR is not a rating agency.

An exception, not an accusation.

UMFR surfaces what does not reconcile, for a human to review. It does not allege wrongdoing by any company.

Not assessed is not a pass.

Where a document or figure cannot be verified, UMFR says so. It never treats silence as clean — a coverage line states what ran and what did not.

Deterministic in the output.

The figures in a UMFR report are recomputed by deterministic logic and traced to source. No language model decides the numbers a reviewer sees.

Public-filer demonstrations, not cross-lender detection.

The cases here run on public filings. Detecting the same asset pledged across different lenders needs a cross-lender network, which public data cannot provide (borrower identifiers are stripped by regulation). The $68.1Bsupplier-finance study maps a disclosure category across public filers — it is not a "First Brands detector" (First Brands was private and never appeared in these filings).

Reported and verified are not the same thing. UMFR is the independent verification layer for private credit.

Contact the founderSee a finished verification