Home Protocol Architecture Tokens Roadmap FAQ Whitepaper Economics GitHub ↗
Readiness overview · engineering estimates, not release guarantees
Mar 2026
Development/test foundation complete
not production
Jul 2026
Toccata runtime + exact signing handoff
✓ verified
Current
H-001 Testnet-10 canary confirmed · operator receipt · independent evidence · non-promotable
→ next gate
After canary
Six state deployments · oracle · release evidence
gated
After core
Real ZK · P2P · Phi-3 · LLaMA · Fed-DART
planned
After AI/P2P
Desktop beta · signed installers · operations
planned
After desktop
iOS + Android · mobile security review
planned
0
Phase 0 · Development foundation
Repository foundations accepted, not production operation. March–August 2026 Test foundation
Sprint 0–1
Setup, Testnet & Contracts
  • Testnet-10 development baseline and one later non-promotable H-001 canary
  • Repository structure + CI/CD
  • 6 Silverscript contracts, 54 tests
  • ValidatorStaking, GuardianReputation, RuleStorage
  • GovernanceAutoTuning, DevPool, Donations
Sprint 2–5
Client, AI & Voting
  • Rust client: Kaspa RPC, custom matcher, bounded byte triage, owner-local byte vault, ZK stub
  • Byte triage has no malware authority; the vault never moves or deletes source files and performs no automatic isolation
  • Phi-3 is a bounded fail-closed safe-default stub; no ONNX session, loaded-model claim, quarantine authority or real-sample evidence
  • Fed-DART gradient client (stub)
  • Guardian YARA generator + analyzer development foundation
  • GH-144 reproducible local vLLM runtime hardening merged and exact-main verified as 95d05cc; no live model evidence or production authority
  • Commit-Reveal, bond, quorum, and slashing state machines; no operated validator network
Sprint 6–7
E2E + Documentation
  • Development-stub lifecycle fixture <60s; accepted as test foundation, not production evidence
  • Quadratic-weighting arithmetic fixture; not proof of Sybil resistance
  • Synthetic FP-flood policy fixture; not real-model quality evidence
  • Audit dashboard, README, whitepaper.html
  • Landing page live on GitHub Pages
Sprint 8
Documentation & Wiki
  • CONTRIBUTING.md
  • 5 wiki guides (user, validator, guardian, dev, faq)
  • Full deployment roadmap
  • AI architecture documentation
  • Session checkpoint — crash recovery
A
Phase A · Post-Toccata Verification
Runtime gates and the funded H-001 Testnet-10 canary pass; six state deployments remain. Current · readiness-gated Active
Sprint 9
Canary, State Contracts + Real ZK-Proof
  • Current-Silverscript runtime transitions and H-001 LE encoding verified
  • H-001 Testnet-10 externally signed, fully verified, confirmed, receipted, and independently observed
  • Deploy all 6 state contracts only after canary evidence passes
  • Implement manifest-pinned active-KIP-16 BN254/Arkworks Groth16 verification engine and owner-only bounded service adapter
  • PROM emission contract: minting logic
  • Planned KAS/PROM secondary-market pool after token and deployment gates
  • Initial operator-controlled Guardian + Validator scenario; not decentralized operation
Sprint 10
Real KRC-20 Reader + P2P Network
  • Merged GH-42 Guardian ballot core: exact-main-verified direct QUIC/libp2p request/response, static peers, bounded resources, cancellation-safe swarm progress, and owner-only collector bridge
  • Merged/exact-main-verified GH-44: atomic owner-only persistent transport identity, strict bounded routes, data-minimal health events, and a bounded relay service
  • Isolated three-node evidence: relay reservation/delivery, AutoNAT state, DCUtR relay fallback, and disconnect handling
  • Merged and exact-main-verified GH-48: strict Guardian/relay process roles, owner-only local submission, bounded JSON health, graceful drain, and separate-process same-host relay evidence
  • Merged and exact-main-verified GH-52: explicit canonical relay bootstrap advertisements with bind/advertise separation
  • Merged/exact-main-verified GH-55 ThreatHint core: shared canonical schema, development-only Light Client builder, and an independent bounded request/ACK protocol
  • Merged/exact-main-verified GH-58 ThreatHint verifier ingress: separate owner-only IPC, trusted network/domain binding, persistent freshness/replay admission, and atomic durable analyzer outbox; production Groth16 remains fail-closed unavailable
  • Merged and exact-main-verified GH-63 real Groth16 engine: canonical manifest/VK trust anchors, exact proof parsing, complete ThreatHint statement binding, bounded owner-aware adapter/service, and fail-closed operation without approved production artifacts
  • Merged and exact-main-verified GH-74 bounded analyzer adapter: canonical outbox digest/network/time revalidation and exact non-submittable handling of hash-only v1 without fabricated IOC, LLM, or YARA output
  • Merged and exact-main-verified GH-77 bounded drain isolation: failed jobs stay pending, later safe jobs progress, and reports expose only fixed category/index plus a validated digest or none
  • Merged and exact-main-verified GH-82 Threat Observable v2 draft: separate artifact hash and observable commitment, strict canonical bounds, deny-by-default disclosure classes, and exact non-claims
  • Public or multi-host relay/NAT operation and broad discovery; mDNS is held while its compatible dependency path has unresolved RustSec advisories
  • KRC-20 UTXO queries for "PROM-RULES" tick
  • Rule content download from IPFS via CIDv1
  • GH-190: fail-closed local Raw-CIDv1/sha2-256 binding of caller-supplied exact rule bytes, bounded simple-matcher parsing, atomic snapshot activation, and beta/mainnet rejection; no Kaspa/IPFS source or production YARA
  • GH-193 merged and exact-main verified: strict development-only decoding of exact caller-supplied current-Silverc RuleStorage constructor state; no chain provenance, covenant authentication, finality, live IPFS retrieval, or production authority
  • GH-197/PR #198 merged and exact-main verified at 28da2d4: development-only owner-pin manifest-to-caller-observation consistency for one Testnet-10 RuleStorage UTXO, with unique outpoint, covenant, script, amount, block-DAA, checked maturity-proxy, and exact constructor-byte checks
  • GH-203/PR #204: bounded development-only acquisition of exact node network/current virtual DAA and one explicit address's UTXOs through the existing connected client before unchanged GH-197 verification; one node response is not independent RPC truth/history, consensus finality, manifest authority, IPFS availability, deployment, or production readiness
  • GH-205: callable-only development composition of one owner-pinned complete snapshot through injected/live Testnet-10 observation, a credential-free loopback-only local IPFS gateway, exact Raw-CIDv1 content binding, and one atomic scanner replacement
  • GH-207: owner-local POSIX checkpoint with minimum verified virtual-DAA ordering, exact-identity digest binding, restart-persistent rollback and same-order equivocation rejection, and exact replay recovery
  • GH-209: explicit opt-in development coordinator with one immediate attempt, a fixed interval after success, sequential retries with capped exponential failure backoff, bounded timeout, cancellation, single-flight admission, and non-sensitive status; no CLI/product-runtime wiring, autonomous provider, canonical manifest authority, independent RPC truth/finality, availability/replication proof, production YARA, deployment, or production readiness
  • GH-211: strict canonical development/Testnet-10 complete-snapshot envelope authenticated with BIP340 against a separately owner-pinned x-only key, external nonzero minimum sequence, and separately trusted clock rechecked on every fetch; one owner-authorized snapshot envelope only, with no signer, key-authority/rotation proof, persistent sequence authority, canonical L1/RPC/finality proof, availability proof, deployment, or production readiness
  • Merged and exact-main-verified GH-213/PR #214 at bbe7efb: explicit operator-invoked Development/Testnet-10 rule-sync preflight/run CLI with private no-symlink config and signed-envelope files, ASCII TOML configuration, offline non-mutating preflight, loopback-IP-literal RPC/IPFS, redacted status, and SIGINT/SIGTERM cancellation; CI 31950806131, Security 31950806118, and Pages 31950805653 pass; no autonomous authority, wallet, chain write, key governance, persistent sequence authority, deployment, Mainnet, or production readiness
  • Merged and exact-main-verified GH-216/PR #217 at 13c1812: test-only real-binary loopback E2E evidence covers offline/connected preflight, private checkpoint commit, SIGTERM/SIGINT drain, restart exact replay, rollback/equivocation rejection, and malformed, timeout, or disconnected peers; CI 31978132036, Security 31978132044, and Pages 31978131647 pass. This is local Development evidence only, not public Testnet operation, independent RPC/IPFS truth or availability, deployment, Mainnet, or production readiness
  • Merged and exact-main-verified GH-86 provides isolated Rust/Python canonical bundle validators with one shared byte-exact valid/invalid corpus; no v1, P2P, proof, analyzer, committee, IPFS, chain, or public-rule wiring
  • Merged and exact-main-verified GH-90: local Rust file_sha256 production from exact caller-supplied bytes plus typed scope, with Python validation of shared vectors; no path API, transport authorization, external provenance, privacy approval, or proof binding
  • Merged and exact-main-verified GH-94: local Rust byte_pattern production from exact caller-supplied bytes, checked offset, boolean wildcard mask, and typed scope, with mandatory local-only review_required_v1 and Python validation of shared vectors; no pattern/path API, transport authorization, external provenance, privacy approval, or proof binding
  • Merged and exact-main-verified GH-103: bounded local Rust Linux ELF api_import production from exact bytes plus a checked sorted/deduplicated import index; 16 MiB and 4096-dynamic-symbol parser limits, internally derived scope, mandatory review_required_v1, and independent Python parsing of shared exact-byte vectors; no path/string/generic builder, transport authorization, external provenance, privacy approval, or proof binding
  • Merged and exact-main-verified GH-121: the same isolated api_import boundary for exact PE32/PE32+ bytes, with 16 MiB, 4096-import-descriptor, and 4096-thunk-entry limits, fail-closed ordinal/grammar checks, fixed windows/pe scope, architecture-specific Rust coverage, and independent Python parsing of a synthetic shared PE32+ vector. Library names never become observables; no path/string/generic, transport, proof, analyzer, wallet, chain, or promotion behavior.
  • Merged and exact-main-verified GH-107: matching local Rust/Python verification of one canonical, maximum-one-hour BIP340 approval statement bound to the exact review-required bundle, separately trusted approver key, recipient-scope digest, network, report nonce, and separately trusted current time that must never be attacker-controlled; no signer, replay ledger, transport, promotion, disclosure, analyzer, proof, wallet, or chain action
  • Merged and exact-main-verified GH-111 local durable consumption: owner-only fixed authority/scope/network policy, same-call verification, atomic approval-ID and authority-nonce consumption, persistent clock high-water, and restart/concurrency/lock/path hardening; no pairing, promotion, analyzer, outbox, wallet, or chain action
  • Merged and exact-main-verified GH-114 isolated local Rust/Python canonical ThreatHint v2 statement parsers and one shared exact-byte corpus: separate artifact hash and observable commitment plus confidence, disclosure class, nonce, time, and separately trusted network under a new length-prefixed, domain-separated digest; no relation, proof acceptance, pairing, transport, analyzer, wallet, or chain action
  • Merged and exact-main-verified GH-117, not production-deployed: strict Rust/Python ThreatHint-v2 proof-envelope and RelationManifest-v2 parsers plus an atomic raw-manifest-anchor/network/domain/public-input compatibility binding; Groth16 verification, approved artifacts, transport, analysis, promotion, and rollout remain separate gates
  • Merged and exact-main-verified GH-117, not production-deployed: silent Rust verify-v2 binds owner-only manifest/relation-source/verifying-key bytes and performs real canonical BN254 verification over binding-derived inputs; runtime loads no proving key, all generated artifacts are test-only, and production relation/key/ceremony approval plus atomic acceptance remain open
  • Merged and exact-main-verified GH-117, not production-deployed: an owner-only read-only v2 preflight pins network, approver, recipient-scope, and manifest anchors and verifies statement/bundle/approval compatibility without proof verification, approval consumption, SQLite mutation, disclosure authority, or operational side effects
  • Merged and exact-main-verified GH-117, not production-deployed: a POSIX-only Guardian verified-preflight service owner-pins the absolute Rust verifier by exact SHA-256, reuses the preflight policy network and manifest anchor, runs approval/privacy checks first, and sends the same envelope bytes to verify-v2 under bounded, scrubbed, shell-free, fail-closed process control; its receipt is data only and no SQLite access or approval consumption occurs
  • Merged and exact-main-verified GH-117, not production-deployed: a raw-input-only Guardian acceptance service proves exact policy identity before ledger creation, runs verified proof/privacy preflight first, and binds the approval ID plus observable commitment before final durable consumption; failed verification never consumes or advances ledger time
  • Merged and exact-main-verified GH-117, not production-deployed: an owner-only exact-schema promotion boundary requires review-required disclosure, exact platform/format, allowed observable kinds, and a count cap before forwarding the same raw wires into atomic acceptance; rejection never reaches proof verification or the ledger, while success remains restricted local data
  • Merged and exact-main-verified GH-117, not production-deployed: an owner-only retention policy declares recoverable local bundle form, durable kinds, pending cap, and retention cap without creating a queue or effect
  • Merged and exact-main-verified GH-117, not production-deployed: enforceable authority/privacy governance binds network, key, scope, epoch/window, same-Guardian recipient semantics, denied external disclosure, and explicit per-kind risk decisions; all three policy digests and authority state pin or advance atomically with valid consumption
  • Merged and exact-main-verified GH-117, not production-deployed: governed schema v4 binds canonical statement/digest, trusted nonce, bundle, approval, lease and retention; atomic completion stores one canonical non-actionable result before deleting work. The bounded worker uses only a deterministic test analyzer and has no LLM/YARA, actionable rule, transport, publication, chain, reward, deployment, or external effect
  • Merged and exact-main-verified GH-152, not production-deployed: governed schema v5 permanently enforces one-to-one-to-one statement-digest, approval-ID and observable-commitment pairing across outbox/result retention; v4 migration requires empty outbox and result tables, preserves authority/high-water/consumption state, and fails closed unchanged for any retained work or result
  • Merged and exact-main-verified GH-155: Guardian sidecar process integration tests serialize shared cases, bound diagnostics and waits, coordinate EOF/ACK shutdown, and deterministically kill and reap a child on timeout; this is test reliability only and changes no rollout percentage or production behavior
  • Merged and exact-main-verified GH-167 bounded ThreatHint-v2 repository transport: shared exact Rust/Python payload corpus, independent /prometheus/threat-hint/2.0.0 channel, trusted-network parsing before owner-only IPC, trusted session/time resolution before governed promotion, strict accepted/rejected/busy acknowledgements, shared admission budgets, and separate-process same-host evidence. PR #168 published exact main 7c62608; Prometheus CI 31645624623, Security Audit 31645624601, and Pages 31645623547 pass. No production proof approval, semantic/actionable analysis, disclosure, public multi-host claim, model/YARA, wallet, chain, reward, or deployment effect is added.
  • Merged and exact-main-verified GH-170 replaces substring-only candidate-rule checks with exact-pinned, compile-only YARA-X validation: one bounded ASCII rule, no imports/includes/modules, zero compiler errors or warnings, and no scan. PR #171 published exact main 8d8e29c; CI 31650123073, Security 31650123055, and Pages 31650122593 pass. Structural validation only; semantic quality, actionable analysis, and production authority remain open.
  • Merged and exact-main-verified GH-173: one optional governed-worker analyzer deterministically derives a bounded memory-only YARA draft from already approved local API-import and byte-pattern observables, compile-checks it through GH-170, and atomically stores only exact bindings, per-kind counts, a nonce-bound candidate-binding SHA-256, and compile status in a non-actionable v2 result. Existing v1 reads remain valid. PR #174 published exact main 1107b11; CI 31654308969, Security 31654308964, and Pages 31654308875 pass. No source, model, scan, submission, publication, chain, reward, deployment, semantic-quality claim, or production authority is added.
  • GH-177 merged and exact-main verified, not production-deployed: an isolated offline evaluator scans only 20 bounded deterministic synthetic in-memory buffers with one fixed GH-173-shaped rule under pinned YARA-X 1.4.0. Its canonical authority-none report binds exact corpus, policy, evaluator bytes, engine version, rule digest, confusion counts, and precision/recall/specificity. PR #178 merged as exact main 396d347; CI, Security Audit, and Pages pass on that SHA. No real sample, file/process scan, governed wiring, actionable authority, or production-quality claim is added.
  • GH-180 merged and exact-main verified, not production-deployed: eight deterministic POSIX integration cases compose canonical synthetic transport through real ingress, governed promotion, schema-v5 atomic outbox, bounded worker, and durable non-actionable semantic-draft completion. Exact bindings, malformed/oversized rejection, replay/restart, duplicate concurrency, lease recovery, redacted failure, and rollback pass with 171 adjacent tests; 1303 Guardian tests passed and 4 intentional live-model tests skipped. PR #181 merged as exact main a28ad00; CI 31662874366, Security Audit 31662874399, and Pages 31662873670 pass. No product runtime or authority path is added.
  • Merged and exact-main-verified PR #227 published exact main 6c39af5; Prometheus CI 32675287618, Security Audit 32675287530, and Pages 32675287300 pass. GH-226 implements one Development-only Light Client v1 ThreatHint sender over the existing Guardian P2P stack. Strict owner-local files, offline preflight, one static literal-loopback QUIC peer, exact canonical bytes, bounded redacted accepted/duplicate/rejected/busy/transport-failure outcomes, and real same-host binary evidence are covered. This adds no proof or membership authority, public multi-host operation, wallet, chain, reward, deployment, or production readiness.
  • Merged GH-229/PR #230 at exact main fba8bb4 provides the tested capability for one explicit Development/Testnet-10 direct literal-IP/UDP/QUIC-v1 route with strict unsafe-route rejection and a non-authorizing evidence boundary. At 2026-08-26T23:36:04Z (2026-08-27 operator-local), one operator-attested run from source commit 27e8b02 delivered one canonical hint between two distinct controlled hosts with rejected/rejected, zero retries, no persistence and acknowledgement authority none. The temporary sender-restricted UDP rule was removed immediately. The redacted evidence does not independently prove host separation and is not public-network, relay/v2, deployment or production evidence.
  • Merged and exact-main-verified GH-234/PR #235, code commit b450740, exact main f146fb2, adds one Development/Testnet-10-only Light Client ThreatHint-v2 sender for an owner-prepared canonical shared payload. Strict owner-only files, separately trusted network parsing before identity/network, offline preflight, one-shot Guardian v2 delivery, redacted outcomes, Beta/Mainnet gates and unchanged v1 behavior are locally tested, including the real binary over same-host QUIC. Exact-main CI 33272578070, Security Audit 33272577951, and Pages 33272577407 pass. It adds no proof generation or approval authority, public/multi-host v2 evidence, deployment, Mainnet or production operation.
  • Merged and exact-main-verified GH-238/PR #239, exact main 912d96d, implements and locally tests repository-only preparation for one later controlled distinct-host Development/Testnet-10 ThreatHint-v2 attempt: challenge-bound role-specific operator attestations over the source commit, actual executable digest, exact canonical payload digest, exact v2 protocol, shared observed UTC time, actual rejected status, one attempt, zero retries and no persistence, with strict owner-only/no-symlink files, the exact 9,265-byte Rust wire bound, atomic no-clobber record output, a closed redacted verifier and CI test wiring. Exact-main CI 33279351831, Security Audit 33279351822, and Pages 33279351387 pass. No real GH-238 remote run has occurred and no GH-238 evidence record exists; host separation is not independently proven. This repository preparation is not a deployment or remote demonstration and adds no port, firewall, host, IAM, wallet, chain, deployment, Mainnet or production action or authority; a later real run requires separate explicit authorization.
  • Approve production authority/key/recipient attestation and the v2 production relation/artifacts, then add real privacy-reviewed semantic/actionable analysis and operated multi-host v2 transport evidence
  • Guardian ↔ Validator proposal submission
Sprint 10B
Guardian Decentralization
  • Fail-closed 8B-first routing with 70B escalation below confidence 0.70
  • Threat-hash, confidence, and submission-decision safety envelope
  • Closed-schema model-provided YARA confidence in exact integer basis points; malformed output fails closed and the former indicator-count/text-shape heuristic is removed
  • Merged and exact-main-verified GH-138 deterministic, internally SHA-256-consistent 24-case synthetic confidence evaluation with the unchanged 8500-bps threshold, confusion matrix, exact-ratio precision/recall, Brier score, and ten-bin calibration error; offline-only and non-authorizing, with no external tamper anchor
  • Merged and exact-main-verified GH-141: literal-loopback, proxy-independent model scoring; canonical corpus, public served-model ID, caller-supplied artifact digest, and pinned prompt binding; atomic owner-only predictions and offline-only non-authorizing evaluation
  • Merged/exact-main verified GH-161: canonical exact-byte manifests for bounded trusted-owner local model directories, plus capture-time re-verification before model adapter construction; caller-supplied digests remain legacy-only, with no upstream-authenticity or live-served-model claim. PR #162 merged as d468426; CI 31340112225, Security 31340112204, and Pages 31340111625 pass
  • Merged/exact-main verified GH-144: version-and-digest-pinned vLLM, loopback-only host publication, local read-only offline weights, non-root execution, internal networking, bounded resources, 8B default and opt-in 70B profile, plus structured CI validation; PR #145 merged as 95d05cc, with CI, Security, and Pages green; no pull, live inference, provenance, calibration, or authority
  • Local 5+ Guardian complete-ballot validation with canonical commitments and strict majority
  • Merged/exact-main verified GH-147: an exact schema-v1 source loaded through an owner-only, no-symlink, bounded, descriptor-verified file boundary binds 5–1024 sorted unique Guardian IDs one-to-one to public BIP340 keys, fixed 8B tier, and model-artifact digests. Its exact-byte digest pins the membership snapshot, while validated member fields derive signer mappings. PR #148 merged as aeecffb; CI 30863940497, Security 30863940502, and Pages 30863940053 pass. This proves structural assignment consistency only, not source authority, key ownership/rotation, Sybil resistance, chain attestation, or production readiness
  • Merged and exact-main-verified GH-242/PR #243 at 5cb132c670d1e7771ccaf6dab2ddf5b1a6fd905a: local ballot-session establishment owner-loads one GH-147 source exactly once, checks a separately trusted network and expected epoch, derives the snapshot and public BIP340 signer map internally, and removes the public caller-built context registration path without changing ballot bytes, session digests, replay behavior, or ensemble math. Exact-main CI 33433012614, Security Audit 33433012605, and Pages 33433011653 pass. Epoch is an identity pin only; external membership authority, key ownership/rotation, Sybil resistance, multi-host operation, L1 attestation, and production trust remain open.
  • Merged and exact-main-verified GH-246/PR #247 at f12e821bb492caae3b94e5b3c882488eb7f2982d: canonical BIP340-signed transitions bind exact previous/next source digests, advancing epoch, bounded validity and nonce into an owner-only durable ledger. New ballot sessions use only the stored current source under the same lock. Rollback, same-epoch equivocation, replay, clock rollback, source substitution, restart and concurrent duplicates fail closed. CI 33452085421, Security Audit 33452085419, and Pages 33452084065 pass. This is owner-pinned public verification only, not external authority, key ownership/rotation, Sybil resistance, L1, multi-host or production trust.
  • Merged and exact-main-verified GH-253/PR #254 at 5920cb4bb737376977f762beb0d5e3108519c7a0: the durable current key authorizes one gapless successor and the proposed key independently proves possession under a separate BIP340 digest domain. Current membership, validity and nonce bind the atomic rotation; exact schema-v1 ledgers migrate transactionally to v2 and later membership transitions use only the durable current key. Prometheus CI 34031999904, Security Audit 34031999907, and Pages 34031999575 pass. This owner-local mechanism has no signer/private-key path and does not prove real-world key ownership, external/decentralized membership authority, Sybil resistance, L1, public multi-host operation, deployment or production trust.
  • Transport-neutral BIP340 ballot intake with persistent replay and equivocation protection
  • Real Guardian ballot carrier with exact bounded frames and end-to-end QUIC-to-collector ACK tests
  • Independently reproducible real 8B/70B candidate evidence, upstream-authenticated and live-served-model provenance, real adversarial semantic-quality evaluation, production calibration evidence, and authorization
  • Public/multi-host discovery/NAT/relay evidence, externally trusted decentralized membership authority, real-world key ownership, Sybil resistance, and on-chain ensemble attestation; GH-253 covers only owner-local transition-key succession mechanics
  • Guardian pooling and final Sybil-resistance design
B
Phase B · AI Production
Real Phi-3. Fine-tuned LLaMA 3. Fed-DART live. After core-network gates Planned
Sprint 11
Phi-3-mini Production Integration
  • Download Phi-3-mini 3.8B from Microsoft HuggingFace
  • 4-bit quantization via ONNX Runtime
  • Implement real reviewed inference in the fail-closed Phi-3 stub
  • Model update: IPFS distribution + on-chain hash verification
  • Test: Phi-3 detects known malware samples
Sprint 12
LLaMA 3 Fine-Tuning
  • VirusShare + MalwareBazaar + Exploit-DB + CuckooSandbox datasets
  • LoRA fine-tuning on LLaMA 3 8B (single A100)
  • Validation: detects Pegasus and APT indicators
  • LLaMA 3 70B fine-tuning
  • Models published to IPFS, hashes stored on-chain
Sprint 13
Fed-DART + fp_rate Oracle
  • Real Fed-DART gradient aggregation client
  • Coordinator rotation via reputation system
  • fp_rate oracle: Light Client reporting → on-chain
  • Replace GovernanceAutoTuning stub with real oracle
  • E2E test: FP rate rises → Auto-Tuning responds
GH-258 / GH-261 / GH-264 · Cross-cutting
Endpoint Detection & Safe Response
  • Includes unauthorized compute conscription of endpoints, accelerators, servers or data-center capacity into a distributed mesh
  • Planned signals: process/resource ownership, unexpected CPU/GPU workload, scheduler/orchestrator drift, workload identity, persistence, credentials, outbound fan-out, model/runtime integrity and agent tool-policy violations
  • Behavior-based detection cannot reliably attribute activity to AI, AGI, a specific actor or intent
  • Stages: observe-only → warn-only → operator-confirmed reversible containment → separately approved limited automation
  • Requires privacy review, real-sample/adversarial evaluation, measured false positives, multi-host evidence and rollback drills
  • No real-time endpoint sensor or response engine exists; automatic quarantine, process termination, firewall changes, credential rotation, remote commands, deletion and host isolation are disabled and unauthorized
  • GH-264 candidate: canonical 512-byte observe-only Rust/Python statement parser; closed categories and no endpoint collection, correlation, attribution, warning, transport, response or production authority
Key milestone
Network is learning
  • All AI stubs replaced with production implementations
  • Network learns from real threats without sharing raw data
  • Target model tamper evidence from an on-chain hash; availability, provenance, quality and authorization remain separate
  • Auto-tuning responds to real network conditions
C
Phase C · Desktop Release
Full desktop client. Public beta. After production AI/P2P Planned
Sprint 14
Tauri Desktop Application
  • Tauri v2 (Rust + React/TypeScript)
  • System tray with live scan status
  • Real-time threat feed + rule history
  • PROM balance + reputation display
  • Settings: model path, node URL, privacy controls
Sprint 15
Installers + Public Beta
  • Windows MSI installer + code signing
  • macOS DMG + Gatekeeper signing
  • Linux: .deb, .rpm, .AppImage, Flatpak
  • GitHub Releases CI/CD + SHA-256 checksums + GPG
  • First public beta release
Sprint 16
One-Click Guardian Installer
  • Auto-detects GPU (NVIDIA / AMD / Apple Silicon)
  • Downloads LLaMA 3 8B from IPFS (on-chain hash verified)
  • Configures Docker + vLLM automatically
  • Systemd service for auto-start
  • Ubuntu 22.04+, Debian, Rocky Linux, Windows Server (WSL2)
Sprint 17
Validator Web Dashboard
  • Full web UI for validator operators
  • KAS staking interface
  • Voting queue with proposal details
  • Slashing risk display + bond status
  • Rewards history and analytics
D
Phase D · Mobile
iOS + Android. Full public release. After desktop beta + security review Planned
Sprint 18
iOS Client (Flutter)
  • Flutter foundation (shared codebase iOS + Android)
  • Phi-3-mini via Core ML (ONNX → Core ML conversion)
  • iOS Background App Refresh for continuous scanning
  • Keychain for ZK-proof key storage
  • TestFlight beta → App Store submission
Sprint 19
Android Client (Flutter)
  • Phi-3-mini via ONNX Runtime Mobile
  • WorkManager for background scanning
  • Android Keystore for ZK-proof keys
  • Google Play Store submission
  • F-Droid release (open source community)
E
Phase E · vProgs
Complete architectural vision. After upstream capability is stable Planned
Sprint 20
vProgs Integration
  • vProgs ships only after upstream DAGKnight/vProgs readiness is independently verified
  • AI analysis results anchored to L1 via ZK-proofs
  • Federated learning auditable on-chain via CDAG
  • Guardian compute resource tracking transparent
  • No possibility to manipulate AI outputs retroactively
Final state
Full vision realized
  • Every AI decision verifiable on-chain
  • Every model update tamper-proof and auditable
  • Target: federated learning with decentralized operation after privacy, membership, Sybil and multi-host gates
  • Target: progressively decentralized governance and bounded improvement after authority, Sybil-resistance, recovery, availability and public multi-host gates
By device

Every device. Every platform.

01 · Desktop
Windows
After desktop beta gates
MSI installer. Download, run, done.
02 · Desktop
macOS
After desktop beta gates
DMG with Gatekeeper signing. Intel + Apple Silicon.
03 · Desktop
Linux
After desktop beta gates
.deb, .AppImage, Flatpak. x86_64 + ARM.
04 · Server
Ubuntu Server
After Guardian operations proof
One-click guardian installer script.
05 · Mobile
iPhone / iPad
After mobile security review
Target: App Store, Phi-3 via Core ML, and reviewed background scanning.
06 · Mobile
Android
After mobile security review
Target: Google Play + F-Droid with ONNX Runtime Mobile and reviewed background scanning.
07 · Cloud
Any VPS
After core-network evidence
Docker Compose. Guardian or Validator node.
08 · Edge
Raspberry Pi
After resource validation
ARM Linux client. Light Client or Honeypot.
Target hardware profiles

Planning values, not certified production requirements.

Role Target hardware Evidence boundary Status
Light Client Any device, 4 GB RAM Production ONNX and platform validation open. Development stub
Honeypot Any internet-exposed server Requires isolated implementation and threat-model review. Planned
Validator 2 vCPU · 4 GB RAM + 10,000 KAS KAS-only state machines tested; no operated network. Target
Guardian (8B) NVIDIA GPU · 24 GB VRAM 8B-first runtime scaffold; no independently evaluated run. Target
Guardian (70B) 4× A100/H100 80 GB · 256 GB RAM Optional escalation tier; no independently evaluated run or reputation authority. Target