A verification layer that oversells its own guarantees is worth nothing. Here is the exact line between what a MIZAN credential proves, what it does not, and what belongs to no proof system — ours included.
The temptation for any verification company is to imply that its stamp means more than it does. We take the opposite view, because in this business it is the only defensible one: a credential is only worth what its issuer refuses to sign. If MIZAN certified everything, it would certify nothing. So this note is a list of the things we will not claim, and why each limit is a feature of an honest standard, not a gap in a weak one.
The most important boundary, and the one we lead with everywhere. When you prove a strategy over historical data, the credential establishes something real and precise: your committed strategy, run on committed prices, at committed costs, cleared (or failed) the gate. Tamper with any of it and the proof breaks.
What it does not establish is that the positions were formed without hindsight. A one-shot seal on history is still self-reported history. Nothing in a single backtest proof stops a researcher from having peeked at the future while designing the rules. We say this in plain language on the mint screen itself.
The no-lookahead guarantee is not asserted; it is earned forward, by extending an anchored track in which positions are committed before the bars they trade come into existence:
A growing anchored track is the closest thing to a cryptographic live track record that exists. It is the credential an allocator should ultimately weight most, and the one we most want quants to build. A seal earns attention; an anchored track earns capital.
MIZAN's core claim is narrow and exact: a committed stream of positions, compounded on committed prices, after committed costs, cleared a pinned gate. Everything the product can and cannot verify follows from what that sentence can express. Mapped against the strategy universe, it looks like this:
Counted as strategy classes rather than tiers, the map is precise: thirteen classes provable today, three in build or on the roadmap, and one we refuse on principle. (Thirteenth as of 28 July 2026: point-in-time US equities — survivorship-free US equity data live, first proof verified on it; the receipt is a refusal, which is the point.) Two of the boundaries are worth stating without euphemism. Execution alpha: HFT and market-making — we refuse permanently: a backtest's counterfactual fills cannot be proven by anyone, because they never happened, so a proof of them would be a proof of fiction. That is physics, not a limitation of our engine. And non-priced assets have no bar-by-bar price series to compound, so there is nothing to prove in the MIZAN sense; the only honest path there is attested live cash flows, a different trust model entirely.
We publish the ~10% we will never reach, because a standard that hides its own ceiling is not a standard; it is a sales pitch.
Data provenance. Pinning proves the exact bytes were fixed and shared by everyone, it does not prove the vendor's history is point-in-time perfect. Exchange- or vendor-attested data signing is a roadmap milestone, not a current claim.
Capacity. The disclosed cost model is a flat per-side charge; it does not model market impact. A credential certifies a track at pinned costs, not that the strategy scales to arbitrary AUM.
The oracle bit. A pass/fail gate leaks one bit per attempt; many proofs against varying gates form an oracle. This is documented in our threat model and bounded by design — we would rather name it than let a reviewer discover it.
Circuit soundness. The mathematics that a MIZAN proof is itself valid — that the STARK cannot be forged — is the domain of an external zero-knowledge audit, which precedes any claim of "audited" or "production-ready." We do not use that language until that review is done.
Every limit above could be papered over with softer wording, and most verification pitches would. We publish them because our entire value rests on a single asset that marketing cannot manufacture: the belief that when MIZAN certifies something, it is true. That belief survives exactly as long as the list of things we won't certify stays honest. The refusals are not the fine print beneath the product. They are the product.
A credential is only worth what its issuer refuses to certify. Everything in this product follows from that sentence.
The coverage map reflects the audited v10 engine (image id dafad185…); the current live engine is v11 (3ac3b10b…), which carries the same coverage. Roadmap tiers are engineering targets, not claims. Every boundary in this note is enforced in the product itself, not only described here.