On 28 July 2026 we ported our own trend engine to the S&P 500, ran it through our own locked gate on a licensed, survivorship-free data feed, and the gate said no. This note is the cryptographic receipt — downloadable, independently re-verifiable, and timestamped to Bitcoin.
Every verification company faces one unavoidable conflict of interest: the strategies it most wants to certify are its own. There is exactly one clean answer to that conflict, and it is not a policy document. It is a refusal — issued by your own gate, against your own strategy, in public, with a proof attached. This week our gate handed us one, and it is the best thing we have published since the engine went live.
We recently moved our US equity data onto a our US equity data feed — the survivorship-complete substrate: 28.5 years of SPY, 7,184 daily bars from 1997, alongside 639 single-name series and a point-in-time S&P panel in which the delisted names stay in the data. Then we did the obvious next thing: we took the Donchian trend architecture our own research runs on crypto, pointed it at the S&P 500, and minted a real STARK proof of the backtest on GPU proving infrastructure — the first proof ever minted on this data.
The gate is the same locked policy every submitter faces: Sharpe ≥ 1.20, CAGR ≥ 20%, MaxDD ≤ 25%, no single bar below −12%. The in-circuit verdict:
US-SP500-TREND · verdict: FAIL — SharpeTooLow · CagrTooLow · WalkForwardFailed.
Committed and disclosed: Sharpe 0.41 full window · 0.49 out-of-sample · CAGR 3.3%/yr over 28.5 years · MaxDD 21.1% · 89 trades · costs 7bps fee + 3bps slippage. The strategy specification itself was never committed — the proof carries a sealed commitment, and the verifier confirms the spec is absent. Prove the edge. Never reveal the strategy. Even when the edge isn't there.
No passing credential was issued. The canonical credential.bundle slot is reserved for passes and was not touched. What exists instead is an honest-FAIL bundle — a real proof that this specific strategy, on committed prices at committed costs, did not clear the bar.
We were not surprised by the verdict. Our own internal research has tested US equity trend and momentum five independent times — the last time on this same paid, point-in-time, delisted-complete data — and it failed every time. We have published that finding in our failures ledger. So why spend GPU hours proving a strategy our own corpus says is dead?
Because the interesting question was never whether the strategy works. It was whether the gate would hold when its own maker stood in front of it. A verification layer whose founder can talk his way past his own policy is a marketing channel. The proof that ours is not: the founder submitted, and the circuit — which cannot see who is asking — said no.
The most valuable thing our gate did this week was refuse us.
The first mint attempt produced something even better than a refusal: it exposed a configuration error on our side, and the independent verifier — not us — caught it.
We had declared the annualization basis for US equities as the textbook 252 trading days per year. But the verifier does not take annualization on declaration. It re-derives the true bar spacing from the committed data window and enforces, exactly: ppy × span ≤ seconds-per-year × (n−1). The NYSE holiday calendar over this window implies ~251.5 bars per year — so a declared 252 over-counts, and over-counting inflates a Sharpe ratio by √ppy. The check exists precisely because an inflated annualization basis is a forge vector. It refused our bundle.
We corrected every one of our 641 US datasets to its exact admissible basis — computed per series from its own window, 248 to 252 — and re-minted. Under-counting is permitted by design: it can only deflate the number, and conservatism is free. The second bundle verifies clean: sixteen of seventeen checks green, and the single red line is the verdict itself.
The C1 annualization check was written into the era-11 verifier before we had any equity data to mis-declare. When the mistake arrived, the machine refused it — including from us. A verification system that catches its own operator is the only kind worth trusting with anyone else's numbers.
The receipt is public. Nothing below requires trusting MIZAN — the verifier re-derives everything locally, from your copy of the data.
Precision about what a refusal buys us — and what it does not. The proving engine is unchanged: this ran on the same era-11 guest program, byte-identical, that every current credential pins to; a new data feed does not make a new engine, and we will not number it like one. The our US equity datasets remain flagged test phase until a strategy actually clears the gate on them. Our coverage methodology did move — v2 → v3, ~75% → ~80% — but read carefully what moved it: the receipt, not the verdict. Coverage measures what the engine can certify, and a verifying proof over the new substrate demonstrates that capability in full; the identical bump would have followed a PASS. What a refusal can never buy is the claim we do not make: that anyone — including us — has a passing US equity strategy. Nobody does, and the gate just proved it about its own maker.
The bundle above is a real RISC Zero STARK, minted 2026-07-28 on GPU infrastructure against the era-11 guest program, and re-verifiable offline with the MIZAN verifier against any honest copy of the canonical SPY series. The OpenTimestamps stamp binds its hash to Bitcoin.