A MIZAN credential is not a PDF you take on faith. It's a cryptographic receipt anyone can independently re-check — without trusting MIZAN, the manager, or the data provider. Run the source-available verifier on a real credential below. Twelve conditions checked independently — sixteen when the credential discloses exposures and regimes. The strategy stays hidden.
The live engine verifies a real STARK credential end-to-end, in front of you, in about seconds. Watch all sixteen conditions clear while the strategy is never revealed.
Universal · nothing to install · the exact same verifier, client-side in your browser — no server involved. The honest demo behind everything on this site.
Download a real credential, the canonical data it was bound to, and the source-available verifier. Run one command on your own machine. This is the whole point of MIZAN: the proof is portable and the issuer is irrelevant.
Tamper test: change a single byte of the bundle and re-run, the digest and receipt checks fail instantly. The proof cannot be forged or edited. · Other platforms: the verifier is source-available Rust — Linux/Windows builds and full source on request for any allocator or reviewer; full public source release is planned. · macOS may quarantine an unsigned binary — clear it with xattr -d com.apple.quarantine mizan-verifier-macos-arm64.
A chained credential re-proves the same committed strategy over a strictly longer data window, the backtest becomes a growing live track, and every link is cryptographically bound: same spec commitment, same guest, the old window a Merkle prefix of the new. Re-verify the first real chain yourself — parent (800 bars) → extension (1,096 bars, +296 new).
What the chain proves, and what it doesn't: the chain check proves the same committed spec was honestly computed over the extended window (same guest, same gate, same costs; old window a Merkle prefix of the new). Provenance of the newly appended bars still rests on the canonical-data allowlist, not an exchange-signed feed — that boundary is printed by the verifier itself, not hidden. · Break test: swap the spec, shrink the window, or forge the parent digest, the verifier refuses with the exact reason. · Every credential minted in the app is chain-ready: one click re-proves it as data accrues. · Verifier eras, honestly: a verifier binary trusts exactly the engine it was built with — verifier v3 (above) verifies everything minted from 2026-07-17; the original binary verifies the sample credential of its own era. Cross-era verification fails by design, not by accident.
Two credential families, both minted as real STARKs on 2026-07-17. Black-box FULL: a hidden model commits its positions forward into an append-only track, and the gate is computed in-circuit over that committed position stream, the credential attests these exact pre-committed positions cleared the gate on this exact data. zkML proven inference: a committed compact model runs its own decisions inside the circuit — every position provably came from that one hidden model. Tampering, curation and re-tuning are refused by construction — alter or drop any period and the sealed track head changes, so the credential fails. Forward-commitment timing: that positions were fixed before each period's outcome — rests on the track head being published or timestamp-anchored ahead of time, not on the circuit alone; anchoring it (OpenTimestamps / RFC-3161) is the honest completion of that claim. The model is never revealed.
Since guest v10 · Fractional positions, a sealed model's sizing is now provable. Positions are no longer just long/flat/short: the committed stream carries a signed leverage per bar (×0.01 steps), a declared cap is enforced inside the circuit, and the parity and fractional commitment formats live in separate hash domains, a track committed one way can never replay as the other. The sample below is a hidden model whose dynamic sizing (avg 0.22×, peaks 1.24×) clears the full institutional gate — Sharpe 1.50 · CAGR 28.8% · MaxDD 20.8% · net +345%, all computed in-circuit. Minted as a real STARK on GPU, 2026-07-22.
Break test: change one byte of the parts file and re-run, the aux binding check fails and the verifier refuses the credential. · Honest scope: the gate-in-circuit and compact-model inference above are proven — their receipts exist. Large-net zkML (proving inference of a big neural net in-STARK) remains a research frontier industry-wide; we don't relabel it. · The original forward-track rail credential (verifies with the era -v2- binary) is kept as the historical artifact.
Try enough strategies and one will look brilliant by pure luck, and no ordinary track record shows you how many were tried. The DSR credential closes that hole: all N candidate trials are committed in a Merkle ledger, every trial's Sharpe is re-derived inside the circuit, and the winner's Sharpe is deflated for the luck of the best-of-N (Bailey & López de Prado's Deflated Sharpe Ratio — here made cryptographic). N is read from the ledger, never declared — understate it and verification fails. Minted as a real STARK on GPU, 2026-07-20. Since guest v10, significance is tested at an autocorrelation-corrected effective sample size: serially correlated returns can only make the test harder, never easier.
And it doesn't flatter its own maker. The credential below is real and verifies, but at the honest significance bar (DSR ≥ 0.95, Bailey–López de Prado's standard, not a coin flip), this particular strategy's edge does not survive the best-of-N correction. Our own verifier says so, out loud. A tool that stamped everything "significant" would be worthless; the whole value is that it tells you the truth, including when the truth is no.
"Verified" is not "significant", and that distinction is the product. The green line certifies the deflation was computed honestly: N is real, every trial's Sharpe is proven, the math is right. What that honest math returns for this strategy is not significant at 95%: and the verifier says so plainly. A DSR of 0.68 means "more likely than not, but below the bar." Most edges land here; that is the entire reason the correction exists. · What this proves, and what it can't: N counts the trials committed to this ledger from the moment it opened; no cryptography can recover experiments run before a ledger existed. The honest claim is "from here on, every trial is counted": never "we fixed history." That forward-only boundary is why the ledger is timestamp-anchored (Bitcoin + RFC-3161, files above): the commitment provably predates the outcomes. · Break test: drop a losing trial from the ledger, fabricate a Sharpe, or restate N, each is refused with the exact reason; under-resolving trials fails closed. · Verifier eras: the -v7- binary verifies engine-v7 credentials (this DSR one); the current era is -v10- (composed PBO · n_eff DSR · fractional sizing); the DSR and PBO credentials below are v10 mints, CPCV remains a v9-era mint and verifies with -v9- — its era's binary, forever; earlier eras keep their own binaries above — cross-era failure is by design.
Even with N honestly counted, the selection itself can overfit: pick the in-sample best and it may sit below median out of sample, a backtest dressed as alpha. The Probability of Backtest Overfitting (Bailey–Borwein–López de Prado–Zhu, via combinatorially-symmetric cross-validation) prices exactly that: split the history into 16 sub-periods, and over every one of the 12,870 balanced train/test partitions — López de Prado’s own published setting — check whether the in-sample best stays above median out of sample. All committed trials are re-derived inside the circuit; PBO is the fraction of partitions where the selection was luck. Bar: PBO ≤ 0.5. Minted as a real STARK on GPU, 2026-07-22.
This one passes, and it's now composed. Since guest v10 each committed trial is its own STARK, and the credential's aggregator proof cryptographically verifies every trial receipt inside itself before running the partition test on committed return moments — proofs checking proofs. That unlock is what pays for the full 12,870 partitions. The flagship trend selection reads PBO 0.0759: the in-sample-best config stays above the median out-of-sample, so the selection is skill, not overfitting. And the padding attacks stay closed — every committed trial must clear the institutional gate, the winner is bound to the maximum-Sharpe trial, the split is canonical, and (new, found by our own red-team before this mint) a ledger padded with clones of the winner is refused outright. Tracked openly as D7 and D9 on the security ledger.
Cross-validation leaks when train and test overlap in time — serial correlation bleeds one into the other and flatters the result. Purged, embargoed combinatorial cross-validation (López de Prado, Advances in Financial ML, ch. 7 & 12) removes it: split into groups, hold out combinations as test, purge the label-overlap bars and embargo the boundary bars — in the circuit, with the purge count committed so a prover can't quietly skip it — then score the strategy across every recombined path for a distribution of OOS Sharpe, not one fragile split. The headline is the honest tail: the 5th-percentile path. Minted as a real STARK on GPU, 2026-07-22.
And this one holds. Across 15 recombined paths with 160 boundary bars purged+embargoed in-circuit, the flagship's 5th-percentile path Sharpe stays positive: the edge survives leak-free cross-validation, not just one lucky split.
All three sins, credentialed, and hardened. DSR (selection bias), PBO (overfitting) and CPCV (leakage) are each real STARK credentials you can re-verify here, the complete López de Prado framework — every correction a re-verifiable STARK credential. We red-teamed PBO and CPCV the same day we shipped them and found two real gaming vectors (D7, D8 on the security ledger): a paddable PBO ledger and an unenforced CPCV purge floor with a prover-chosen schema. Both are closed in guest v9: every PBO trial must clear the gate with the winner bound to the max, and the CPCV purge/embargo schema is a canonical constant with a per-path purge floor the verifier re-checks. We'd rather show you a credential, its holes, and the fix than a clean demo that hides them.
The verifier doesn't take MIZAN's word for anything, it recomputes and re-checks each of these from the raw bundle and your copy of the data. Twelve conditions checked independently — sixteen when the credential discloses its exposures and regimes, as this sample does.
Verifying is milliseconds; minting is not. Generating a proof is heavy, one-time work, a simple strategy on a daily dataset takes roughly 20–30 minutes on our single machine, and a multi-sleeve book on 4h data runs for hours. The Studio measures your exact proof cost up front and tells you before anything is queued; heavy books are minted offline. Verification stays seconds forever — that asymmetry is the whole point.