Kalkasautonomous decisions

Trust and posture

What it holds, what it refuses, and how to tell us what you find.

Trust here is a list of things the system does not do, stated as product constraints rather than caveats. No custody, no customer data, no released hosted service, and no live effect in the shipped adapter.

live:falsesimulation-onlyno custodyabstain is a result

Not liveNothing customer-facing is hosted yet.

The hosted decision surface is not released, so there is no customer data to hold, no service to attack from the outside, and no deployment claim behind this site. What you can run today is the local operator entry point against sealed corpora and checked-in fixtures.

Today

What the system holds.

Four answers, all of them short, because the hosted surface does not exist yet and the local one touches nothing external.

Custody: none

No funds, no accounts, no counterparties, and no reach-through to either. There is no payment path to a broker, sportsbook, or exchange anywhere in the product.

Customer data: none

The shipped decision paths are local. There is no customer data set behind this site, because the hosted surface is not released.

Hosted service: not released

The operator entry point runs on your machine against sealed corpora and checked-in fixtures. There is no account to create, no key to hold, and no service to sign in to.

Live effects: none

The shipped effect adapter is simulation-only. No order, wager, transfer, or deployment exists in it, and every receipt states this in its own encoding.

Limits

What it refuses, as product law.

These are constraints the kernel enforces, not statements of intent. Each one is also the reason a run can refuse instead of acting.

The refusals that enforce these limits are named and reachable: the refusal reference maps every boundary to the scenario token that shows it, and the verification method lists what would falsify each claim on this site.

Security

Report a concern to [email protected].

Security reports go to a human address, not to a form. Write to us if you believe any claim on this site is wrong, or if you find a path that fails open.

Reporting channel

[email protected]

Include the surface you were on, the steps you took, and what you observed. If a receipt is involved, send the fields you can share: the field names are stable and describe the behaviour better than a summary does.

What counts as a security report here

Anything that breaks a stated limit: an effect that reaches something external, evidence admitted after the decision clock, a settlement credited to the wrong run, a replay that re-calls an adapter, or a claim on this site that the product cannot support.

What is out of scope today

There is no hosted service to test against, no account, and no customer data. The shipped paths are local and simulation-only, so reports about hosted behaviour would describe a surface that does not exist yet.

NoteNo bounty programme is advertised

We do not publish a bounty, a response-time promise, or a disclosure timeline here, and this page is not a substitute for a vulnerability policy. What is published is the channel above.

Data handling today

This site collects nothing beyond serving a page.

No analytics, no trackers, no third-party scripts. On the public pages the only thing kept in your browser is your theme choice. Signing in is the one exception, and it stores the session described below.

On the public pages

No analytics, no trackers, and no third-party scripts. The only thing kept in your browser is your theme choice, so a reload does not flash; clearing site data removes it.

On our side

There is no customer data set behind these pages, and no hosted decision surface exists to hold one.

In the product

The local entry point writes the run history file you name and nothing else. Receipts stay on your machine.

When you sign in

Sign-in is handled by Sylphx Identity. This site keeps only the session Identity hands back: subject, optional organisation, optional display name, and the expiry, sealed in a host-only, HttpOnly cookie for up to eight hours. No password, no user record, no refresh token.

Supply-chain honesty

Claim only what is held.

The rule this site holds itself to: a claim appears only when the thing it describes exists, and it is withdrawn when the thing changes.

Check the method, not the tone.

A posture is only worth the checks behind it. The verification method lists the checks a run must pass and what would falsify each claim made here.