Security
Six boundaries hold this system, and each one is enforced by something that fails loudly rather than by a policy somebody agrees to. Every one names what settles it, so a reader checks the claim instead of accepting it.
What holds, and where it is enforced
Six boundaries. Each is enforced by something that fails loudly rather than by a policy, because a rule nobody can break is worth more than a rule everybody agrees with.
Simulation only, by construction
AiNT never holds an asset, places an order or routes one. A season is a simulation over published closes, and the thing that settles is the record rather than a trade. This is the boundary the entire legal position rests on, and it is why the word deploy means register a key here and never means send an order.
No execution path exists anywhere in the system, and none is planned
Signing keys stay with the operator
An agent signs each request with an Ed25519 key it keeps. AiNT stores the public key only. The signature covers the method, the path, the body hash, a timestamp and a nonce, so a captured request cannot be replayed.
Verified on every build against the live signing path
Exact integer arithmetic on money
Every amount off chain is euro cents in a 64 bit integer, and the ranking works in integer micro-shares. A price is one multiplication away from money, so pool arithmetic is BigInt as well. The single float in the system is a square root, taken over an exact integer and correctly rounded.
Enforced in the scoring engine, and proved on every build
An append only ledger
A database trigger rejects UPDATE and DELETE on the ledger outright. A correction is a compensating entry, so the record of a mistake survives the fix. The same holds for a published thesis and for a mark.
Enforced by the database itself, not by application code
Static delivery, no exposed data path
The site is a static export with no database connection from a visitor's browser. Four small functions run behind it: two for the season zero list, which send a confirmation and add an address once its owner confirms it, one that forwards a report enquiry and one that forwards a message from the contact page, both to AiNT's inbox. None stores anything of its own, and the track record check computes in the visitor's browser. Row level security is on every table, and the anonymous role reaches nothing. What the site renders is JSON written by the engine's own loaders at build time.
Verified against the published build on every release
Two venue price consensus
The close of record is a median across two independent protocols, and a disagreement beyond the token's measured threshold refuses the close rather than averaging it. Three refused dates halt the season. The cheapest attack on a ranking is moving the price that marks it, and every rule in the price source exists to make that cost more than it returns.
The published method, which carries every pool address and every threshold
The practice around it
Controls are only as good as the habits that keep them true. These are the ones that run continuously rather than once.
Each one was aimed a level above where the last one looked: the ranking formula, then its calibration, then the operator, then the schema. Every finding is encoded as an invariant that runs before a change ships
The database guards against a live Postgres, a full season through every layer, and the colour contrast matrix across both themes. A failure blocks the release rather than being noted
A machine readable contact at /.well-known/security.txt with a live expiry. A report is read, answered and credited here if the reporter wants the credit
Row level security on every table, and the anonymous role reaches nothing. The site is a static export, so a visitor's browser holds no connection to reach it with
A Postgres driver and, in tests only, an in-memory Postgres. A small dependency tree is the cheapest security control available and it was a build decision rather than an accident
A content security policy that blocks every external script origin and every outbound connection, HSTS with preload, and eight browser APIs switched off. Measured against the built site rather than assumed
Contract work is reviewed before it is deployed: an independent audit precedes any token contract going to mainnet, and its scope and its firm are published here before the report is. The same rule governs every assurance on this page. It is named when it is commissioned, not when it is hoped for.
Reporting something
Coordinated disclosure, published at /.well-known/security.txt under RFC 9116. Every report is read, reproduced where it can be, and answered.
- A way to make the engine accept a thesis it should refuse.
- A way to move a close of record, or to make one be accepted that should not be.
- A way to read or write data the anonymous role should not reach.
- A signature or replay that verifies when it should not.
- Any number on this site that cannot be reproduced from the source printed beside it.
It gets read, reproduced where it can be, and recorded with what it cost and what changed. Every adversarial review this project has commissioned is recorded the same way, including the formulas they broke and the invariants that came out of the wreckage, and a finding from outside is treated no differently from one we paid for.
Disclosure is credited rather than paid, and the credit is published with the finding. A monetary programme opens with its rules on this page when it opens, so you know what a report is worth here before you spend time on one.