No funds or transaction
Browser receipt work stays local unless a user chooses the API. API evaluation and optional wallet message signing are also off-chain and do not spend SOL or settle value.
07 / Security
Proof Engine v1, a public stateless Receipt API beta and a deterministic scenario simulator are operational but unaudited. PactVerity will not call a Solana protocol audited, decentralised or production-ready until it is deployed and those claims can be linked to public evidence.
00 / Live off-chain boundary
The browser engine and Receipt API beta strict-parse receipt data, re-run the checks, recompute the digest and validate an optional wallet signature. The API processes submitted JSON through hosting infrastructure; it does not turn supplied evidence into an independent measurement.
Browser receipt work stays local unless a user chooses the API. API evaluation and optional wallet message signing are also off-chain and do not spend SOL or settle value.
The digest protects the recorded payload from undetected change under the published engine version. Receipts contain user-supplied data.
The engine cannot prove honest collection, completeness, trusted time or real-world delivery. Independent evidence collection is a future layer.
01 / Simulation boundary
The deterministic simulator's default $25,000,000 is synthetic nominal volume from 250,000 model agreements at $100 and 1,000,000 checks. Service and escrow volume is $0.
The model stress-tests deterministic computation. Its output does not establish revenue, adoption, settlement capacity, audited performance or protection of real funds.
02 / Threat model
Security work must cover smart contracts, economic incentives, evidence systems, wallets, infrastructure and governance.
Any future Solana programs could expose assets to logic flaws, unsafe upgrades, account validation errors, authority misuse and integration bugs.
Any future verifier layer could produce incorrect outcomes through bad data, collusion, bribery, Sybil identities or unavailable workers.
If deployed, volatile stake value, insufficient stablecoin bonds or concentrated holdings could weaken the intended incentives.
03 / Before value
04 / Token authorities
PVTY has a finalized fixed supply. Mint and freeze authorities are removed; the retained metadata update authority and any future protocol or sale-program authorities are separate disclosures.
| Mint authority | Permanently removed after exactly 50,000,000 PVTY were minted to the published treasury token account. |
|---|---|
| Freeze authority | None. Token accounts cannot be frozen by a PVTY freeze authority. |
| Metadata authority | The selected specification would leave the published owner wallet as update authority for disclosed metadata corrections. That authority would not change a finalised fixed supply or freeze holder accounts. |
| Slashing | Any future slashing must apply only to tokens voluntarily deposited into PactVerity collateral accounts—not to ordinary holder wallets. |
| Upgrade authority | Any future PactVerity protocol or sale-program upgrade authority must be disclosed, protected by appropriate controls and constrained by published delays. |
The sale and escrow audit-candidate source and local validation manifest are public for review. An authenticated vulnerability-reporting channel, response target and disclosure policy must still be published before any buyer funds or protocol value go live. Never include private keys or seed phrases in a report.
Security principle