Home Protocol Architecture Tokens Roadmap FAQ Whitepaper Economics GitHub ↗
Readiness overview · engineering estimates, not release guarantees
Mar 2026
Foundation complete
✓ done
Jul 2026
Toccata runtime + exact signing handoff
✓ verified
Current
Exact-main 205e1ca handoff verified · H-001 external signature · broadcast · evidence
→ next gate
After canary
Six state deployments · oracle · release evidence
gated
After core
Real ZK · P2P · Phi-3 · LLaMA · Fed-DART
planned
After AI/P2P
Desktop beta · signed installers · operations
planned
After desktop
iOS + Android · mobile security review
planned
0
Phase 0 · Foundation
All sprints accepted. March 2026 Complete
Sprint 0–1
Setup, Testnet & Contracts
  • Kaspa Testnet-10 node running
  • Repository structure + CI/CD
  • 6 Silverscript contracts, 54 tests
  • ValidatorStaking, GuardianReputation, RuleStorage
  • GovernanceAutoTuning, DevPool, Donations
Sprint 2–5
Client, AI & Voting
  • Rust client: Kaspa RPC, YARA scanner, ZK stub
  • Phi-3 ONNX wrapper + anomaly detector
  • Fed-DART gradient client (stub)
  • Docker vLLM + YARA generator + analyzer
  • Commit-Reveal voting + bond + slashing engine
Sprint 6–7
E2E + Documentation
  • Development-stub lifecycle fixture <60s; accepted as test foundation, not production evidence
  • Mathematical Sybil resistance proof
  • FP-flood attack resistance verified
  • Audit dashboard, README, whitepaper.html
  • Landing page live on GitHub Pages
Sprint 8
Documentation & Wiki
  • CONTRIBUTING.md
  • 5 wiki guides (user, validator, guardian, dev, faq)
  • Full deployment roadmap
  • AI architecture documentation
  • Session checkpoint — crash recovery
A
Phase A · Post-Toccata Verification
Runtime gates pass; funded H-001 execution and evidence are next. Current · readiness-gated Active
Sprint 9
Canary, State Contracts + Real ZK-Proof
  • Current-Silverscript runtime transitions and H-001 LE encoding verified
  • Externally sign, verify, broadcast, confirm, and independently observe the H-001 testnet-10 canary
  • Deploy all 6 state contracts only after canary evidence passes
  • Implement manifest-pinned active-KIP-16 BN254/Arkworks Groth16 verification engine and owner-only bounded service adapter
  • PROM emission contract: minting logic
  • First KAS/PROM liquidity pool on Kasplex DEX
  • 10 team-operated Guardian + Validator nodes
Sprint 10
Real KRC-20 Reader + P2P Network
  • Merged GH-42 Guardian ballot core: exact-main-verified direct QUIC/libp2p request/response, static peers, bounded resources, cancellation-safe swarm progress, and owner-only collector bridge
  • Merged/exact-main-verified GH-44: atomic owner-only persistent transport identity, strict bounded routes, data-minimal health events, and a bounded relay service
  • Isolated three-node evidence: relay reservation/delivery, AutoNAT state, DCUtR relay fallback, and disconnect handling
  • Merged and exact-main-verified GH-48: strict Guardian/relay process roles, owner-only local submission, bounded JSON health, graceful drain, and separate-process same-host relay evidence
  • Merged and exact-main-verified GH-52: explicit canonical relay bootstrap advertisements with bind/advertise separation
  • Merged/exact-main-verified GH-55 ThreatHint core: shared canonical schema, development-only Light Client builder, and an independent bounded request/ACK protocol
  • Merged/exact-main-verified GH-58 ThreatHint verifier ingress: separate owner-only IPC, trusted network/domain binding, persistent freshness/replay admission, and atomic durable analyzer outbox; production Groth16 remains fail-closed unavailable
  • Merged and exact-main-verified GH-63 real Groth16 engine: canonical manifest/VK trust anchors, exact proof parsing, complete ThreatHint statement binding, bounded owner-aware adapter/service, and fail-closed operation without approved production artifacts
  • Merged and exact-main-verified GH-74 bounded analyzer adapter: canonical outbox digest/network/time revalidation and exact non-submittable handling of hash-only v1 without fabricated IOC, LLM, or YARA output
  • Merged and exact-main-verified GH-77 bounded drain isolation: failed jobs stay pending, later safe jobs progress, and reports expose only fixed category/index plus a validated digest or none
  • Merged and exact-main-verified GH-82 Threat Observable v2 draft: separate artifact hash and observable commitment, strict canonical bounds, deny-by-default disclosure classes, and exact non-claims
  • Public or multi-host relay/NAT operation and broad discovery; mDNS is held while its compatible dependency path has unresolved RustSec advisories
  • KRC-20 UTXO queries for "PROM-RULES" tick
  • Rule content download from IPFS via CIDv1
  • Merged and exact-main-verified GH-86 provides isolated Rust/Python canonical bundle validators with one shared byte-exact valid/invalid corpus; no v1, P2P, proof, analyzer, committee, IPFS, chain, or public-rule wiring
  • Merged and exact-main-verified GH-90: local Rust file_sha256 production from exact caller-supplied bytes plus typed scope, with Python validation of shared vectors; no path API, transport authorization, external provenance, privacy approval, or proof binding
  • Merged and exact-main-verified GH-94: local Rust byte_pattern production from exact caller-supplied bytes, checked offset, boolean wildcard mask, and typed scope, with mandatory local-only review_required_v1 and Python validation of shared vectors; no pattern/path API, transport authorization, external provenance, privacy approval, or proof binding
  • Merged and exact-main-verified GH-103: bounded local Rust Linux ELF api_import production from exact bytes plus a checked sorted/deduplicated import index; 16 MiB and 4096-dynamic-symbol parser limits, internally derived scope, mandatory review_required_v1, and independent Python parsing of shared exact-byte vectors; no path/string/generic builder, transport authorization, external provenance, privacy approval, or proof binding
  • Merged and exact-main-verified GH-121: the same isolated api_import boundary for exact PE32/PE32+ bytes, with 16 MiB, 4096-import-descriptor, and 4096-thunk-entry limits, fail-closed ordinal/grammar checks, fixed windows/pe scope, architecture-specific Rust coverage, and independent Python parsing of a synthetic shared PE32+ vector. Library names never become observables; no path/string/generic, transport, proof, analyzer, wallet, chain, or promotion behavior.
  • Merged and exact-main-verified GH-107: matching local Rust/Python verification of one canonical, maximum-one-hour BIP340 approval statement bound to the exact review-required bundle, separately trusted approver key, recipient-scope digest, network, report nonce, and separately trusted current time that must never be attacker-controlled; no signer, replay ledger, transport, promotion, disclosure, analyzer, proof, wallet, or chain action
  • Merged and exact-main-verified GH-111 local durable consumption: owner-only fixed authority/scope/network policy, same-call verification, atomic approval-ID and authority-nonce consumption, persistent clock high-water, and restart/concurrency/lock/path hardening; no pairing, promotion, analyzer, outbox, wallet, or chain action
  • Merged and exact-main-verified GH-114 isolated local Rust/Python canonical ThreatHint v2 statement parsers and one shared exact-byte corpus: separate artifact hash and observable commitment plus confidence, disclosure class, nonce, time, and separately trusted network under a new length-prefixed, domain-separated digest; no relation, proof acceptance, pairing, transport, analyzer, wallet, or chain action
  • Merged and exact-main-verified GH-117, not production-deployed: strict Rust/Python ThreatHint-v2 proof-envelope and RelationManifest-v2 parsers plus an atomic raw-manifest-anchor/network/domain/public-input compatibility binding; Groth16 verification, approved artifacts, transport, analysis, promotion, and rollout remain separate gates
  • Merged and exact-main-verified GH-117, not production-deployed: silent Rust verify-v2 binds owner-only manifest/relation-source/verifying-key bytes and performs real canonical BN254 verification over binding-derived inputs; runtime loads no proving key, all generated artifacts are test-only, and production relation/key/ceremony approval plus atomic acceptance remain open
  • Merged and exact-main-verified GH-117, not production-deployed: an owner-only read-only v2 preflight pins network, approver, recipient-scope, and manifest anchors and verifies statement/bundle/approval compatibility without proof verification, approval consumption, SQLite mutation, disclosure authority, or operational side effects
  • Merged and exact-main-verified GH-117, not production-deployed: a POSIX-only Guardian verified-preflight service owner-pins the absolute Rust verifier by exact SHA-256, reuses the preflight policy network and manifest anchor, runs approval/privacy checks first, and sends the same envelope bytes to verify-v2 under bounded, scrubbed, shell-free, fail-closed process control; its receipt is data only and no SQLite access or approval consumption occurs
  • Merged and exact-main-verified GH-117, not production-deployed: a raw-input-only Guardian acceptance service proves exact policy identity before ledger creation, runs verified proof/privacy preflight first, and binds the approval ID plus observable commitment before final durable consumption; failed verification never consumes or advances ledger time
  • Merged and exact-main-verified GH-117, not production-deployed: an owner-only exact-schema promotion boundary requires review-required disclosure, exact platform/format, allowed observable kinds, and a count cap before forwarding the same raw wires into atomic acceptance; rejection never reaches proof verification or the ledger, while success remains restricted local data
  • Merged and exact-main-verified GH-117, not production-deployed: an owner-only retention policy declares recoverable local bundle form, durable kinds, pending cap, and retention cap without creating a queue or effect
  • Merged and exact-main-verified GH-117, not production-deployed: enforceable authority/privacy governance binds network, key, scope, epoch/window, same-Guardian recipient semantics, denied external disclosure, and explicit per-kind risk decisions; all three policy digests and authority state pin or advance atomically with valid consumption
  • Merged and exact-main-verified GH-117, not production-deployed: governed schema v4 binds canonical statement/digest, trusted nonce, bundle, approval, lease and retention; atomic completion stores one canonical non-actionable result before deleting work. The bounded worker uses only a deterministic test analyzer and has no LLM/YARA, actionable rule, transport, publication, chain, reward, deployment, or external effect
  • Approve production authority/key/recipient attestation and the v2 production relation/artifacts, then add real privacy-reviewed semantic/actionable analysis and v2 transport
  • Guardian ↔ Validator proposal submission
Sprint 10B
Guardian Decentralization
  • Fail-closed 8B-first routing with 70B escalation below confidence 0.70
  • Threat-hash, confidence, and submission-decision safety envelope
  • Local 5+ Guardian complete-ballot validation with canonical commitments and strict majority
  • Transport-neutral BIP340 ballot intake with persistent replay and equivocation protection
  • Real Guardian ballot carrier with exact bounded frames and end-to-end QUIC-to-collector ACK tests
  • Live 8B/70B service wiring and calibrated confidence evidence
  • Public/multi-host discovery/NAT/relay evidence, trusted membership and key assignment, Sybil resistance, and on-chain ensemble attestation
  • Guardian pooling and final Sybil-resistance design
B
Phase B · AI Production
Real Phi-3. Fine-tuned LLaMA 3. Fed-DART live. After core-network gates Planned
Sprint 11
Phi-3-mini Production Integration
  • Download Phi-3-mini 3.8B from Microsoft HuggingFace
  • 4-bit quantization via ONNX Runtime
  • Replace entropy heuristic with real inference
  • Model update: IPFS distribution + on-chain hash verification
  • Test: Phi-3 detects known malware samples
Sprint 12
LLaMA 3 Fine-Tuning
  • VirusShare + MalwareBazaar + Exploit-DB + CuckooSandbox datasets
  • LoRA fine-tuning on LLaMA 3 8B (single A100)
  • Validation: detects Pegasus and APT indicators
  • LLaMA 3 70B fine-tuning
  • Models published to IPFS, hashes stored on-chain
Sprint 13
Fed-DART + fp_rate Oracle
  • Real Fed-DART gradient aggregation client
  • Coordinator rotation via reputation system
  • fp_rate oracle: Light Client reporting → on-chain
  • Replace GovernanceAutoTuning stub with real oracle
  • E2E test: FP rate rises → Auto-Tuning responds
Key milestone
Network is learning
  • All AI stubs replaced with production implementations
  • Network learns from real threats without sharing raw data
  • Model integrity guaranteed by on-chain hashes
  • Auto-tuning responds to real network conditions
C
Phase C · Desktop Release
Full desktop client. Public beta. After production AI/P2P Planned
Sprint 14
Tauri Desktop Application
  • Tauri v2 (Rust + React/TypeScript)
  • System tray with live scan status
  • Real-time threat feed + rule history
  • PROM balance + reputation display
  • Settings: model path, node URL, privacy controls
Sprint 15
Installers + Public Beta
  • Windows MSI installer + code signing
  • macOS DMG + Gatekeeper signing
  • Linux: .deb, .rpm, .AppImage, Flatpak
  • GitHub Releases CI/CD + SHA-256 checksums + GPG
  • First public beta release
Sprint 16
One-Click Guardian Installer
  • Auto-detects GPU (NVIDIA / AMD / Apple Silicon)
  • Downloads LLaMA 3 8B from IPFS (on-chain hash verified)
  • Configures Docker + vLLM automatically
  • Systemd service for auto-start
  • Ubuntu 22.04+, Debian, Rocky Linux, Windows Server (WSL2)
Sprint 17
Validator Web Dashboard
  • Full web UI for validator operators
  • KAS staking interface
  • Voting queue with proposal details
  • Slashing risk display + bond status
  • Rewards history and analytics
D
Phase D · Mobile
iOS + Android. Full public release. After desktop beta + security review Planned
Sprint 18
iOS Client (Flutter)
  • Flutter foundation (shared codebase iOS + Android)
  • Phi-3-mini via Core ML (ONNX → Core ML conversion)
  • iOS Background App Refresh for continuous scanning
  • Keychain for ZK-proof key storage
  • TestFlight beta → App Store submission
Sprint 19
Android Client (Flutter)
  • Phi-3-mini via ONNX Runtime Mobile
  • WorkManager for background scanning
  • Android Keystore for ZK-proof keys
  • Google Play Store submission
  • F-Droid release (open source community)
E
Phase E · vProgs
Complete architectural vision. After upstream capability is stable Planned
Sprint 20
vProgs Integration
  • vProgs ships only after upstream DAGKnight/vProgs readiness is independently verified
  • AI analysis results anchored to L1 via ZK-proofs
  • Federated learning auditable on-chain via CDAG
  • Guardian compute resource tracking transparent
  • No possibility to manipulate AI outputs retroactively
Final state
Full vision realized
  • Every AI decision verifiable on-chain
  • Every model update tamper-proof and auditable
  • Federated learning fully decentralized
  • Protocol self-governing, self-improving, unstoppable
By device

Every device. Every platform.

01 · Desktop
Windows
After desktop beta gates
MSI installer. Download, run, done.
02 · Desktop
macOS
After desktop beta gates
DMG with Gatekeeper signing. Intel + Apple Silicon.
03 · Desktop
Linux
After desktop beta gates
.deb, .AppImage, Flatpak. x86_64 + ARM.
04 · Server
Ubuntu Server
After Guardian operations proof
One-click guardian installer script.
05 · Mobile
iPhone / iPad
After mobile security review
App Store. Phi-3 via Core ML. Background scanning.
06 · Mobile
Android
After mobile security review
Google Play + F-Droid. ONNX Runtime Mobile.
07 · Cloud
Any VPS
After core-network evidence
Docker Compose. Guardian or Validator node.
08 · Edge
Raspberry Pi
After resource validation
ARM Linux client. Light Client or Honeypot.
Hardware requirements

From any laptop to a server rack.

Role Minimum hardware Details Est. monthly cost
Light Client Any device, 4 GB RAM No GPU required. Windows, macOS, Linux, iOS, Android. $0 (existing device)
Honeypot Any internet-exposed server Emulates vulnerable services. Higher reward per zero-day. ~$5–20 / mo VPS
Validator 2 vCPU · 4 GB RAM + 10,000 KAS No GPU needed. Standard VPS. 7-day exit cooldown. ~$20 / mo VPS
Guardian (8B) RTX 4070 Ti+ · 16 GB VRAM LLaMA 3 8B. Consumer GPU viable. 500+ GFLOPS. Own hardware
Guardian (70B) 4× A100/H100 · 128 GB RAM LLaMA 3 70B. Primary model. Highest reputation potential. $500–2,000 / mo cloud