Ten pictures. Three minutes. After them, you understand what a MIZAN credential is, what it proves — and, just as exactly, what it does not.
A quant walks up with two things: their data and their strategy. Before anything happens, both get fingerprinted (next picture). Then the backtest runs inside a sealed glass room — a special computer where the calculation itself produces a mathematical receipt. Nobody, including us, can reach in and change a number. What comes out is a tiny 225 KB receipt. Anyone on earth can check that receipt on a laptop in a blink (~81 ms) — without trusting us, and without ever seeing the strategy.
The strategy goes into the room but never out of it — the receipt proves what happened without containing the recipe. That's the whole trick: proof travels, secrets don't.
Take every price bar. Hash each one (a hash = a fingerprint: change one digit anywhere, the fingerprint changes completely). Pair the fingerprints up and fingerprint the pairs, again and again, until one single fingerprint sits at the top. That top one is the Merkle root — the DNA of the whole dataset in 32 bytes.
The room refuses to run unless the data it's fed matches a committed root. And when someone verifies later, they rebuild the root from their own copy of the data — if it matches, the proof was about data identical to theirs. We are not in that trust loop at all.
A thousand monkeys flip coins; one flips ten heads. Every anti-luck statistic corrects for how many monkeys there were — but that number was always self-reported by the monkey seller. Our fix: every strategy you try becomes a numbered leaf on a committed tree, before any evaluation. Now N isn't a claim — it's the leaf count. And the room forces your "winner" to actually be the best leaf on that tree.
Honest boundary, always said out loud: the tree counts the committed search. Trials someone ran and never committed are invisible — closing that fully needs pre-registration (commit the ledger before the out-of-sample data even exists).
Everything that matters happens inside — where nothing can be fudged. The room trades only in whole numbers (no decimals — every value ×1,000,000), and wherever rounding could flatter someone, it rounds against the submitter.
Why split it this way? The room proves "this computation happened, exactly." The checker proves "…and it happened on MY copy of reality, under the published rules." Two honest halves; neither trusts the other.
When anyone verifies a credential, it walks through 17 doors. Every door is about trust — is the proof real, is the data mine, is the engine the named one, were the costs floored, was anything tampered. The verdict — PASS or FAIL — is not a door. It's the lamp above the exit: a cryptographically real FAIL walks through all 17 doors just as proudly as a PASS.
Engines improve. The danger: an issuer quietly changes the judge and yesterday's approvals silently mean something new. Our law: the engine's exact code has a fingerprint too (the era id), it's stamped into every credential, and old engines are archived forever — superseded, never revoked. A 2026 credential will still verify against its own 2026 judge in 2036.
This is governance for a world where the issuer must not be trusted either — including us, about our own engine. Weakness found in an old era? It's disclosed as status on the public errata ledger, never rewritten; the reader decides what the credential is worth.
The oldest deadlock in quant: to be believed you must reveal; to reveal is to donate the edge. The sealed path breaks it. The model runs on the quant's own machine. It sends only its decisions — each one salted and fingerprinted into a growing chain. The room re-derives that chain and judges the performance. Verdict public; model never seen — not even by us.
A backtest is a seal on the past. But the same sealed strategy can be re-proven every time new bars arrive — and each new credential must contain the old one's exact window as its prefix, same strategy fingerprint, parent bound to child. The result: a track record that grows forward in public. New bars arrived after the commitment — so they're forward evidence, un-backfillable, forever.
The strongest question an allocator asks: "what if you're gone?" Answer: the verifier is a small program that carries everything inside itself — the engine fingerprints, the approved-data list, the whole era registry. A holder needs three things, none of them ours:
Even the timestamps are ours-free: OpenTimestamps anchors into Bitcoin itself. New minting dies with us; nothing already issued degrades. The asymmetry is deliberate — the artifact outlives the operator.
A verification standard is defined by its refusals. Learn this page best of all — because naming these before anyone asks is what makes everything else believable.
And the proof of our sincerity is permanent: the first strategy this machine ever judged was mine. It said no. Deflated Sharpe 0.6779, below the bar, published forever beside every pass. The complete assertion set, stated with legal care: what a PASS actually asserts.
"Every number in finance is graded by the person selling it. We built a sealed room where the grading happens in mathematics instead: data fingerprinted, every trial counted by a tree instead of a promise, the whole honesty program of the last twenty years running inside the proof, judged by an engine that can never quietly change, refusing most of what it sees — starting with my own flagship. The receipt fits in an email and outlives the company. Prove the edge. Never reveal the strategy."