A MIZAN credential is not a PDF you take on faith. It's a cryptographic receipt anyone can independently re-check — without trusting MIZAN, the manager, or the data provider. Run the source-available verifier on a real credential below. Seventeen conditions checked on a single credential — including exposures and regimes when the credential discloses them. The strategy stays hidden.
▶ Prefer to watch first? The 5-minute demo — real output, zero setup →
The live engine verifies a real STARK credential end-to-end, in front of you, in about 81 milliseconds. Watch all seventeen conditions clear while the strategy is never revealed.
Universal · nothing to install · the exact same verifier, client-side in your browser — no server involved. The honest demo behind everything on this site.
≈81 ms is the canonical verify figure. Individual measured runs on an Apple-silicon laptop, Aug 2026, ranged 24–50 ms depending on artifact (Apple bundle 24 ms · sample credential 38 ms · chained pair 50 ms · registry re-verify 25 ms). Your machine will differ; the asymmetry — milliseconds to verify, minutes-to-hours to mint — will not.
Download a real credential, the canonical data it was bound to, and the source-available verifier. Run one command on your own machine. This is the whole point of MIZAN: the proof is portable and the issuer is irrelevant.
Tamper test: change a single byte of the bundle and re-run, the digest and receipt
checks fail instantly. The proof cannot be forged or edited. · Other platforms: the verifier
is source-available Rust — Linux/Windows builds and full source on request for any allocator or reviewer; full
public source release follows the independent audit. · macOS may quarantine an unsigned binary —
clear it with xattr -d com.apple.quarantine mizan-verifier-macos-arm64.
Minted Aug 2026 · era v11 (image 3ac3b10b…) · re-issued Aug 8 at the corrected annualization basis (the original Aug 4 mints are superseded per the public erratum). We submitted the most famous trades in history to our own gate — Apple buy-and-hold 1997→2026 (+272,548% net, Sharpe 0.89) and SPY buy-and-hold (9.2% CAGR, 99% market beta, proven in-circuit). Both REFUSED, both published. The verifier prints the sealed verdict exactly as proven — GATE VERDICT : FAIL — and marks it as a published failure whose proof is valid: a refusal can never be dressed as a pass, and a verified failure is the Standard working. Full analysis: the survival table.
Expected output: every integrity check passes, the metrics re-derive on your machine — and the verdict line reads GATE VERDICT : FAIL. That is the point.
Minted Aug 11, 2026 · era v11 · real STARK, H100. The strategy's commitment 93c385b1… was pre-registered and timestamp-anchored (RFC-3161 landed; Bitcoin OTS confirming) before any future bar existed. Every future re-proof of this track runs on data that did not exist at commitment — the "was it made in hindsight?" question is closed by construction, not by trust.
Expected output: every check green, and GATE VERDICT : PASS ✓ — Sharpe 1.40 full window · 0.88 out-of-sample · net +930% over 9.0 yrs · MaxDD 23.27% · 125 trades · after 7+3 bps costs · strategy never revealed. (The same strategy's Jul 28 credential remains on the registry: real and PASS, but minted before pre-registration was wired into the mint path, so it can never be chained. That contrast is what this standard exists to fix.)
The chain is growing — link 1 is live. Minted the same day, the moment the next 4h bar closed: the same committed strategy re-proven over 19,671 bars. The appended bar did not exist when the commitment was anchored — for every bar from here on, hindsight is structurally impossible.
Each future extension re-proves the same commitment over a strictly longer window and is re-judged by the same locked gate — pass or fail, it lands on this page and on the registry wall. The next extension is publicly due ≤ 30 Nov 2026 — the live chain.
We flipped one bit — a single 0 to a 1, byte 100,000 of the live-track credential — and published the tampered file next to the real one. Run both. The intact bundle returns seventeen green checks. The tampered one is caught by the STARK itself, and the verifier tells you exactly which condition died.
This is what "cryptographic" means in practice: not our promise, but a mathematical object that refuses to mislead you even when we try to make it. Swap the spec, shrink the window, forge the parent digest, alter one bar of data — the verifier names the exact failure every time. There is no edit that survives.
A chained credential re-proves the same committed strategy over a strictly longer data window, the backtest becomes a growing live track, and every link is cryptographically bound: same spec commitment, same guest, the old window a Merkle prefix of the new. Re-verify the mechanics on the original chain pair from the v3 era — parent (800 bars) → extension (1,096 bars, +296 new).
What the chain proves, and what it doesn't: the chain check proves the same committed spec was honestly computed over the extended window (same guest, same gate, same costs; old window a Merkle prefix of the new). Provenance of the newly appended bars still rests on the canonical-data allowlist, not an exchange-signed feed — that boundary is printed by the verifier itself, not hidden. · Break test: swap the spec, shrink the window, or forge the parent digest, the verifier refuses with the exact reason. · Every credential minted in the app is chain-ready: one click re-proves it as data accrues. · Verifier eras, honestly: a verifier binary trusts exactly the engine it was built with — verifier v3 (above) verifies everything minted from 2026-07-17; the original binary verifies the sample credential of its own era. Cross-era verification fails by design, not by accident.
Two credential families, both minted as real STARKs on 2026-07-17. Black-box FULL: a hidden model commits its positions forward into an append-only track, and the gate is computed in-circuit over that committed position stream, the credential attests these exact pre-committed positions cleared the gate on this exact data. zkML proven inference: a committed compact model runs its own decisions inside the circuit — every position provably came from that one hidden model. Tampering, curation and re-tuning are refused by construction — alter or drop any period and the sealed track head changes, so the credential fails. Forward-commitment timing: that positions were fixed before each period's outcome — rests on the track head being published or timestamp-anchored ahead of time, not on the circuit alone; anchoring it (OpenTimestamps / RFC-3161) is the honest completion of that claim. The model is never revealed.
Since guest v10 · Fractional positions, a sealed model's sizing is now provable. Positions are no longer just long/flat/short: the committed stream carries a signed leverage per bar (×0.01 steps), a declared cap is enforced inside the circuit, and the parity and fractional commitment formats live in separate hash domains, a track committed one way can never replay as the other. The sample below is a hidden model whose dynamic sizing (avg 0.22×, peaks 1.24×) clears the full institutional gate — Sharpe 1.50 · CAGR 28.8% · MaxDD 20.8% · net +345%, all computed in-circuit. Minted as a real STARK on GPU, 2026-07-22.
Break test: change one byte of the parts file and re-run, the aux binding check fails
and the verifier refuses the credential. · Honest scope: the gate-in-circuit and
compact-model inference above are proven — their receipts exist. Large-net zkML (proving inference of a
big neural net in-STARK) remains a research frontier industry-wide; we don't relabel it. · The
original forward-track rail credential
(verifies with the era -v2- binary) is kept as the historical artifact.
Try enough strategies and one will look brilliant by pure luck, and no ordinary track record shows you how many were tried. The DSR credential closes that hole: all N candidate trials are committed in a Merkle ledger, every trial's Sharpe is re-derived inside the circuit, and the winner's Sharpe is deflated for the luck of the best-of-N (Bailey & López de Prado's Deflated Sharpe Ratio — here made cryptographic). N is read from the ledger, never declared — understate it and verification fails. Minted as a real STARK on GPU, 2026-07-20. Since guest v10, significance is tested at an autocorrelation-corrected effective sample size: serially correlated returns can only make the test harder, never easier.
And it doesn't flatter its own maker. The credential below is real and verifies, but at the honest significance bar (DSR ≥ 0.95, Bailey–López de Prado's standard, not a coin flip), this particular strategy's edge does not survive the best-of-N correction. Our own verifier says so, out loud. A tool that stamped everything "significant" would be worthless; the whole value is that it tells you the truth, including when the truth is no.
"Verified" is not "significant", and that distinction is the product. The green line
certifies the deflation was computed honestly: N is real, every trial's Sharpe is proven, the math is
right. What that honest math returns for this strategy is not significant at 95%: and the verifier
says so plainly. A DSR of 0.68 means "more likely than not, but below the bar." Most edges land here; that is
the entire reason the correction exists. · What this proves, and what it can't: N counts the
trials committed to this ledger from the moment it opened; no cryptography can recover experiments run
before a ledger existed. The honest claim is "from here on, every trial is counted": never "we fixed
history." That forward-only boundary is why the ledger is timestamp-anchored (Bitcoin + RFC-3161, files above):
the commitment provably predates the outcomes. · Break test: drop a losing trial from the
ledger, fabricate a Sharpe, or restate N, each is refused with the exact reason; under-resolving trials fails
closed. · Verifier eras: the -v7- binary verifies engine-v7 credentials (this DSR
one); the current era is -v11- (image 3ac3b10b… · both schools in-circuit;
superseded eras verify forever); the DSR and PBO credentials below are v10 mints (composed PBO · n_eff DSR ·
fractional sizing), CPCV remains a v9-era mint and verifies with -v9- — its era's binary, forever;
earlier eras keep their own binaries above — cross-era failure is by design.
Even with N honestly counted, the selection itself can overfit: pick the in-sample best and it may sit below median out of sample, a backtest dressed as alpha. The Probability of Backtest Overfitting (Bailey–Borwein–López de Prado–Zhu, via combinatorially-symmetric cross-validation) prices exactly that: split the history into 16 sub-periods, and over every one of the 12,870 balanced train/test partitions — López de Prado's own published setting — check whether the in-sample best stays above median out of sample. All committed trials are re-derived inside the circuit; PBO is the fraction of partitions where the selection was luck. Bar: PBO ≤ 0.5. Minted as a real STARK on GPU, 2026-07-22.
This one passes, and it's now composed. Since guest v10 each committed trial is its own STARK, and the credential's aggregator proof cryptographically verifies every trial receipt inside itself before running the partition test on committed return moments — proofs checking proofs. That unlock is what pays for the full 12,870 partitions. The flagship trend selection reads PBO 0.0759: the in-sample-best config stays above the median out-of-sample, so the selection is skill, not overfitting. And the padding attacks stay closed — every committed trial must clear the institutional gate, the winner is bound to the maximum-Sharpe trial, the split is canonical, and (new, found by our own red-team before this mint) a ledger padded with clones of the winner is refused outright. Tracked openly as D7 and D9 on the security ledger.
Cross-validation leaks when train and test overlap in time — serial correlation bleeds one into the other and flatters the result. Purged, embargoed combinatorial cross-validation (López de Prado, Advances in Financial ML, ch. 7 & 12) removes it: split into groups, hold out combinations as test, purge the label-overlap bars and embargo the boundary bars — in the circuit, with the purge count committed so a prover can't quietly skip it — then score the strategy across every recombined path for a distribution of OOS Sharpe, not one fragile split. The headline is the honest tail: the 5th-percentile path. Minted as a real STARK on GPU, 2026-07-22.
And this one holds. Across 15 recombined paths with 160 boundary bars purged+embargoed in-circuit, the flagship's 5th-percentile path Sharpe stays positive: the edge survives leak-free cross-validation, not just one lucky split.
All three sins, credentialed, and hardened. DSR (selection bias), PBO (overfitting) and CPCV (leakage) are each real STARK credentials you can re-verify here, the complete López de Prado framework — every correction a re-verifiable STARK credential. We red-teamed PBO and CPCV the same day we shipped them and found two real gaming vectors (D7, D8 on the security ledger): a paddable PBO ledger and an unenforced CPCV purge floor with a prover-chosen schema. Both are closed in guest v9: every PBO trial must clear the gate with the winner bound to the max, and the CPCV purge/embargo schema is a canonical constant with a per-path purge floor the verifier re-checks. We'd rather show you a credential, its holes, and the fix than a clean demo that hides them.
The verifier doesn't take MIZAN's word for anything, it recomputes and re-checks each of these from the raw bundle and your copy of the data. Seventeen conditions checked on a single credential — including exposures and regimes when the credential discloses them, as this sample does.
Verifying is milliseconds; minting is not. Generating a proof is heavy, one-time work, a simple strategy on a daily dataset takes roughly 20–30 minutes on our single machine, and a multi-sleeve book on 4h data runs for hours. The Studio measures your exact proof cost up front and tells you before anything is queued; heavy books are minted offline. Verification stays seconds forever — that asymmetry is the whole point.