Skip to the report
MULTIVAC
Launch
DOC 03Security

The line a mind cannot cross

Every request that can move value passes a policy check it cannot edit, and is signed by a key it never sees. A mind proposes; it does not sign.

mind policy signer | | | |--- proposal ------>| | | |-- within ceiling? | | |-- known address? | | |-- rate allowed? | | | | |<-- refused --------| with the reason, | | | and it is published | | | | |--- approved ------>| | | |--- signs |<------------------ receipt -------------| | | | the mind never sees a key, and never | learns one exists beyond this boundary
  1. 01

    A mind never holds a key

    The signer runs in a separate process with the key material, and the mind talks to it over a request that carries no secret. A mind that is prompted into saying anything at all still has nothing to say that a key would answer.

    Checkable from outside once coins exist: every signature on this rail comes from the signer's address, never from an address a mind could have chosen.

  2. 02

    No tool can pay an address the mind chose

    Payment destinations come from a snapshot of the chain or from a list the launcher set, never from a string the model produced. The model names a RULE; the address is resolved after it, from data it did not write.

    Checkable: the destinations in any payout transaction appear in the snapshot it quotes, and the snapshot quotes its slot.

  3. 03

    Every request passes a ceiling it cannot lift

    Size, rate and destination class are checked before signing, against limits the launcher set and the mind cannot read back or edit. A request above the ceiling is refused whatever the reasoning says.

    Checkable: the ceiling is published on the coin's page, and no transaction exceeds it.

  4. 04

    A refusal is published with its reason

    When the policy says no, the reason goes out with the decision. A mind told no in private can keep rephrasing until something slips, and nobody watching would see the attempts.

    Checkable: refusals appear in the same public record as approvals, and the counts of each are printed.

  5. 05

    The split cannot be changed after it is written

    The fee-sharing config is written once at creation and the program revokes its own admin in the same breath. There is no later adjustment, by the launcher or by this rail.

    Checkable right now: derive the config from any mint, read the shares, and see that the admin is revoked.

What you cannot check from outside

The five rules above are claims about code you cannot see, and saying them confidently does not make them true. Four of them become checkable the moment coins exist, and the fifth is checkable today. Until then they are statements of intent, and this page would rather say that than let them sit next to measured figures and borrow their authority.

What is not checkable from outside, ever, without opening the source: that the signer is genuinely isolated rather than a function in the same process. Every rail making this claim has the same problem, including the ones we have dissected, and none of them says so.

No mind has run on this rail yet, so none of the above has been exercised. The boundary is designed, published, and untested.