Select a removal pathway to see the sensor package, the signing path, the registry mapping, and the modeled unit economics for that methodology. Every reading is signed in hardware at the point of measurement, before it touches a network or an API. Measured, not estimated.
The hardware root of trust does not change between methodologies. What changes is the sensor package, the physical quantity being witnessed, and the registry that accepts the evidence. Pick a pathway to configure the rest of this page. Instrument diagrams, where we have them, open from the sensor table in section 04.
Most environmental data becomes trustworthy by assertion: somebody vouches for a spreadsheet downstream of the sensor. Mālama moves the trust boundary to the sensor itself. A secure element inside the gateway signs each reading with a private key that never leaves the chip, so the question shifts from who to believe to whether the signature verifies.
Each channel exists to close a specific evidentiary gap that a registry auditor would otherwise fill with a model or an assumption. If a channel does not change what a verifier can conclude, it does not belong on the node.
| Reference | Instrument class | Placement | Telemetry | Proof target |
|---|
Legacy figures are drawn from published registry and project cost ranges for this pathway. Mālama figures are modeled targets for a configured deployment, not observed outcomes. Two of these four metrics are determined by registries and verifiers rather than by us, and are marked accordingly.
The single most common failure in tokenized carbon is collapsing a forward claim and a verified credit into one instrument. Mālama keeps them separate on-chain, with explicit conditions precedent between them. Select a stage to see what has to be true before it advances.
Continuous monitoring on stewarded land raises questions that a sensor specification does not answer. Who sees the data. Who can revoke access. Who benefits. These are settled before hardware ships, not after.
Configuration is not commitment. The sequence below is what an onboarding actually looks like, including the two points where the project can stop cleanly.