← MIZAN Research
№ 09 · SemanticsJuly 2026

What a PASS actually asserts

The most dangerous thing about a credential is not forgery. It is over-reading. So here is the opposite of what a founder is supposed to do with his first pass: its exact assertion set, bounded with legal care — and, at equal length, exactly what it does not assert.

On 2026-07-28, MIZAN minted its first gate-PASS credential: BTC-TREND-4H, era v11, a real STARK proven on an H100, 17/17 independent verifier checks green, the full bundle public at mizan.market/verify. You can re-verify it on any laptop in about 81 milliseconds, against a public 19,585-bar dataset — BTC/USDT 4h candles, 2017-08-17 through 2026-07-27.

This note exists because a cryptographic proof has an aura of totality — "it's proven" — and that aura will, if I let it, quietly expand the claim beyond what the circuit actually checked. If you are an allocator doing diligence, this document is written for you, by the party with the strongest incentive to inflate it. That is the point. The discipline of bounding our own product's claims is the product.

01What the credential asserts

Every item in this section is checked in-circuit — inside the STARK, not in a README, not in marketing copy, not in a spreadsheet I could edit after the fact. If any of these were false, the proof would not verify.

1. A committed strategy was evaluated bar-by-bar on pinned data. The strategy is committed — cryptographically fixed before evaluation — and hidden. The dataset is Merkle-pinned: 19,585 bars of BTC/USDT 4h, and the proof binds to exactly that data. The prover cannot swap bars, trim an ugly month, or evaluate on a friendlier window than the one the commitment names.

2. The evaluation was net of committed costs. The per-side costs — 7bps + 3bps for this run — are committed with the strategy and disclosed on the credential, and the returns are computed net of them. What the circuit does not yet do is enforce a minimum cost floor; that enforcement is roadmap, not a property this credential has today. The numbers below are after the committed costs, not before.

3. The strategy produced these numbers, and no others: Sharpe 1.41. Out-of-sample Sharpe 0.84, computed as a walk-forward on the final 30% of the window. CAGR 23.0%. Net return +542.3%. Maximum drawdown 18.66%. Worst single bar −8.51%. 125 trades.

4. Those numbers clear a locked gate. The gate — Sharpe ≥ 1.20, CAGR ≥ 20%, MaxDD ≤ 25%, no bar worse than −12% — was fixed before the run. The proof asserts the metrics clear it. The gate cannot be re-tuned after seeing the result, because the gate is part of what is proven.

5. Four structural honesty properties hold. The annualization basis is bound to the data itself (constraint C1) — you cannot inflate a Sharpe by pretending 4h bars are daily bars. The exposure accounting is consistent: a leverage rail, and long/flat bars that must reconcile. The regime bucketing is pinned — the prover cannot choose buckets after seeing which bucketing flatters the result. And the strategy specification is provably absent from the proof: the credential demonstrates that the strategy's logic is not recoverable from anything published.

6. The search that produced it is public, including its failures. The configuration was pre-registered in research weeks before minting. The published sizing ladder shows the whole sweep: tv20% FAIL (CagrTooLow), tv25% PASS — the credential — tv30% PASS, tv35% FAIL (MaxDD 25.28%, a breach). Two failures bracket the passes, and both are published under my name. During that search we also discovered a configuration loophole that would have flattered the numbers; we refused it rather than exploited it. That refusal is logged.

That is the complete assertion set. Everything above is either in the circuit or in the public search log. Nothing above requires you to trust me.

02What the credential does not assert

This section must be at least as long as the previous one, because this is where over-reading lives.

It asserts nothing about future returns. A backtest seal is history made honest — it is not foresight. The credential proves that a committed strategy, run over 2017–2026 BTC data at the stated costs, produced those numbers. It does not prove, suggest, or estimate that it will produce anything at all from tomorrow forward. Regime change, edge decay, crowding — the proof is silent on every one of them, because a circuit over historical bars has no access to the future. If someone tells you a MIZAN PASS predicts performance, they are wrong, and I said so first.

It asserts nothing about capacity, market impact, or fill quality beyond the committed costs. The committed cost model charges 7bps + 3bps per side. It does not model order-book depth, slippage that scales with size, partial fills, adverse selection, funding on real venues, or what happens when a position is large enough to move the market. A strategy can pass this gate and be undeployable at meaningful size. The credential does not distinguish those cases, and I will not pretend it does.

It asserts nothing about other assets or other windows. This is one strategy on one instrument over one span. The proof does not generalize to ETH, to equities, to a different timeframe, or to a shifted window of the same asset. Any generalization claim would be a new claim, requiring a new proof.

The out-of-sample number does not clear the gate's bar on its own — and the credential does not pretend it does. OOS Sharpe is 0.84; the gate's Sharpe bar is 1.20. The gate binds the full-window metrics and the walk-forward jointly, per its published policy — that policy is public, and both numbers are visible to any reader. I am not going to launder 0.84 into 1.20 by pointing at the composite pass. You can see the walk-forward degradation yourself: 1.41 in-sample-inclusive, 0.84 on the final 30%. And a related disclosure belongs here: the configuration was not born untuned — it is the winner of an earlier BTC-specific research search, pre-registered before minting; the equity refusals are out-of-domain evidence, the BTC pass is in-domain and carries its own search history. Draw your own conclusion about robustness; the credential hands you the inputs, not the conclusion.

It makes no deflation-for-N claim. This credential class is the gate class: fixed thresholds, one strategy, one dataset. It does not adjust for the number of configurations searched, the number of strategies tried and abandoned, or selection effects across the research program. MIZAN has a separate credential class for exactly that — the Deflated Sharpe class — and I will state the uncomfortable fact plainly: MIZAN's own flagship FAILS that class, at DSR 0.68 against the 0.95 bar, and that failure is published. A gate-PASS and a deflation-PASS are different assertions. This credential holds only the first.

It is not an endorsement. A PASS is a measurement, not advice. MIZAN certifies that a computation happened as stated. It does not recommend the strategy, the asset, or any allocation. Nothing in the bundle is an offer, a solicitation, or a view.

03Why the pass carries information at all

A skeptic's correct first question is: does this gate ever say no? If a certification stamp approves everything put in front of it, its approvals are noise.

Here is the record. The same gate, on the same day, refused the maker's own S&P 500 strategy — Sharpe 0.41, FAIL. It refused 34 US stocks as buy-and-hold histories, including the entirety of NVDA's run: 0 for 34 — one pre-registered configuration evaluated across 34 series, not 34 independent trials. The house strategy failed. The best-performing large-cap stock of the era failed. A gate that refuses — including refusing its own maker — is the only kind of gate whose passes carry information. That refusal record, not the pass itself, is what gives the pass its meaning.

And within the passing search itself: two of four ladder configurations failed, publicly, with named reasons. The credential you can verify sits between two published failures. That is what an honest search looks like from the outside.

04What comes next — and what it is not

Credentials in this system can be re-proven over growing windows: chained tracks, where the same committed strategy is re-evaluated as new bars arrive, each link pinned to the last. That is the honest path from "sealed backtest" toward something much stronger — a live, no-lookahead record, accumulated in public, where the commitment provably predates the data it is scored on.

I want to be precise here too, because roadmaps are where claims inflate: chain-forward is a roadmap for this credential, not a property it has today. As of this writing, BTC-TREND-4H is a sealed backtest with an honest search log. It is history, proven. Nothing more — and, I would argue, nothing less: a backtest that cannot be quietly re-run, re-tuned, or re-told is a rarer object than it should be.

✓ The one-paragraph version

The credential proves: this committed, hidden strategy, run bar-by-bar on this pinned public dataset, net of these stated costs, under these pinned accounting rules, produced exactly these numbers, and those numbers clear this pre-locked gate — and the search that found it is public, failures included. The credential does not prove: future returns, deployable capacity, real-world fills, transfer to any other asset or window, robustness to search-multiplicity (a separate class our own flagship fails), or that you should allocate a dollar to it. If you hold both halves of that sentence at once, you are reading the credential correctly — and you are reading it the way I wrote it to be read.

Every artifact referenced is live: the bundle, the credential card, the dataset, and the registry. The verifier re-derives everything locally from your copies. Prove the edge. Never reveal the strategy.