Custody: none
No funds, no accounts, no counterparties, and no reach-through to either. There is no payment path to a broker, sportsbook, or exchange anywhere in the product.
Trust and posture
Trust here is a list of things the system does not do, stated as product constraints rather than caveats. No custody, no customer data, no released hosted service, and no live effect in the shipped adapter.
Not liveNothing customer-facing is hosted yet.
Today
Four answers, all of them short, because the hosted surface does not exist yet and the local one touches nothing external.
No funds, no accounts, no counterparties, and no reach-through to either. There is no payment path to a broker, sportsbook, or exchange anywhere in the product.
The shipped decision paths are local. There is no customer data set behind this site, because the hosted surface is not released.
The operator entry point runs on your machine against sealed corpora and checked-in fixtures. There is no account to create, no key to hold, and no service to sign in to.
The shipped effect adapter is simulation-only. No order, wager, transfer, or deployment exists in it, and every receipt states this in its own encoding.
Limits
These are constraints the kernel enforces, not statements of intent. Each one is also the reason a run can refuse instead of acting.
The refusals that enforce these limits are named and reachable: the refusal reference maps every boundary to the scenario token that shows it, and the verification method lists what would falsify each claim on this site.
Security
Security reports go to a human address, not to a form. Write to us if you believe any claim on this site is wrong, or if you find a path that fails open.
Reporting channel
Include the surface you were on, the steps you took, and what you observed. If a receipt is involved, send the fields you can share: the field names are stable and describe the behaviour better than a summary does.
Anything that breaks a stated limit: an effect that reaches something external, evidence admitted after the decision clock, a settlement credited to the wrong run, a replay that re-calls an adapter, or a claim on this site that the product cannot support.
There is no hosted service to test against, no account, and no customer data. The shipped paths are local and simulation-only, so reports about hosted behaviour would describe a surface that does not exist yet.
NoteNo bounty programme is advertised
We do not publish a bounty, a response-time promise, or a disclosure timeline here, and this page is not a substitute for a vulnerability policy. What is published is the channel above.
Data handling today
No analytics, no trackers, no third-party scripts. On the public pages the only thing kept in your browser is your theme choice. Signing in is the one exception, and it stores the session described below.
No analytics, no trackers, and no third-party scripts. The only thing kept in your browser is your theme choice, so a reload does not flash; clearing site data removes it.
There is no customer data set behind these pages, and no hosted decision surface exists to hold one.
The local entry point writes the run history file you name and nothing else. Receipts stay on your machine.
Sign-in is handled by Sylphx Identity. This site keeps only the session Identity hands back: subject, optional organisation, optional display name, and the expiry, sealed in a host-only, HttpOnly cookie for up to eight hours. No password, no user record, no refresh token.
Supply-chain honesty
The rule this site holds itself to: a claim appears only when the thing it describes exists, and it is withdrawn when the thing changes.
A posture is only worth the checks behind it. The verification method lists the checks a run must pass and what would falsify each claim made here.