AI trades now — sizes positions, picks entries, runs live capital — and it does it on nobody's proof. You are asked to trust a model's track record on the word of the people who built it, and you can't see inside the model to check. MIZAN closes that gap the same way it closes it for humans: the model's conduct becomes checkable without its weights ever being exposed. A compact model's inference is recomputed inside the proof; any model — up to frontier scale — proves its behaviour through the sealed path.
We put a neural network through the gate on NVDA. It returned +895% — and the gate refused it: a 38% drawdown and a Sharpe of 1.02, under the 1.20 bar. That verdict is published on the wall, credential 6b767764…, next to everything else.
That is the whole point. Anyone can claim their AI is honest. To our knowledge, nobody else can show you their own model, cryptographically examined, publicly failed, and left on the record. A gate that passes everything certifies nothing — as true for a machine as for its maker. When a model's record does pass, an allocator knows exactly what that is worth, because they can see what it refused.
A compact model's inference is recomputed inside the zero-knowledge proof itself — the gate re-runs the model on the committed data and proves the result. The weights are an input the proof consumes and never reveals. What it decided is checkable; what it is stays sealed.
A frontier-scale model can't be recomputed in-circuit — so it proves behaviourally: the model emits its committed positions, and the gate runs over that committed stream. The architecture, the parameters, the prompts never enter the room. Its conduct becomes a credential; its internals never leave the machine.
Either way, the record is minted to the model's operator, verifies forever against the era that judged it, and can be chained forward — a live pulse proving the model kept behaving, not just that it once backtested well. A self-improving agent's track record becomes a thing the world can check instead of take on faith.
The boundary is printed, as always. In-circuit inference today covers compact models; frontier-scale models are covered behaviourally via the sealed path, not internally. A sealed model cannot prove what it is not using — it proves what it did, not the absence of a given input. And no credential — human or machine — asserts future returns, capacity, or crowding. What it proves is conduct on committed data, honestly, against the true trial count. How the gate works → · the full boundary →
Mint a credential on what your model actually did — its weights never leave your machine, and the verdict is yours to publish or not. It may refuse you; it refused a net that returned +895%. Either way you learn, in a day, for free, exactly where your model stands. Minting is free while open testing lasts, and your number on the wall is permanent.
Research and verification artifacts. Not investment advice; no offer or solicitation. Backtested and hypothetical performance is not indicative of future results and is net of committed trading costs only. A model submitted for proof — its weights, parameters, and prompts — is never transmitted, stored, or revealed by MIZAN. · for quants → · for allocators →