The VTR Standard (VTR-1 (published on SSRN)) · Verifiable Strategy Validation

Prove the edge.
Never reveal the strategy.

Production-grade, complete, in open testing — anyone can sign in and test it. Minting is free while the window lasts; the founding 25 seats are the last free ones this company will ever issue. To our knowledge, the first verification standard where every claim is a proof. The forty-six years of literature it answers: mizan.market/evidence. Level I — honestly computed: a secret strategy cleared a pinned institutional gate on Merkle-bound real data, after real costs, in-circuit. Level II — validation-complete: both canonical schools of backtest honesty — the López de Prado/Bailey in-sample program and the Harvey–Liu/Hansen universe program — proven in one zero-knowledge credential; to our knowledge, the first engine to do so. Level III — pre-registered against data that doesn't exist yet: the roadmap, stated as roadmap. Anyone re-verifies in milliseconds, trusting no one.

2
Schools of backtest
honesty · one proof
25
Verified credentials
passes & honest fails
8
Refusals published ·
incl. Apple & the S&P
v11
Current era ·
validation-complete
MIZAN · PROOF SHEET#0847
Point-in-time dataPASS
Look-ahead-freePASS
Gate · Sharpe ≥ 1.20 · MaxDD ≤ 25%PASS
Walk-forward · independencePASS
Strategy in journal— absent —
VERDICT   VERIFIEDSTARK · 220 KB
The Standard

Three levels. Every claim a proof.

The VTR Standard (VTR-1) for Verifiable Strategy Validation. A credential states its level and the engine era that minted it — and every statement below is traceable to a proof artifact on the registry, the published coverage methodology, or the era registry. Where we can't trace, we understate.

Level I · Honest Execution
A committed position stream, compounded on committed real data, net of a committed cost model disclosed on the credential — costs can be raised, never hidden — cleared a pinned gate — inside the proof. No lookahead by construction; a fabricated curve cannot pass. Every gate-cleared credential on the wall holds this level.
Shipped · era v10
Level II · Validation-Complete
Level I plus both canonical schools of backtest honesty in one credential — the López de Prado/Bailey in-sample program (Deflated Sharpe, PBO composed at S=16, purged/embargoed CPCV, PSR, MinBTL, triple-barrier labels, uniqueness, structural breaks, HRP) and the Harvey–Liu/Hansen universe program (Bonferroni/Holm/BHY haircuts, SPA, Romano–Wolf). To our knowledge, the first engine to prove both in zero knowledge. No prover-chosen knobs; the verifier prints every number.
Shipped · era v11
Level III · Pre-Registered
The strategy sealed and timestamp-anchored before the data exists; the forward track proves itself as reality arrives — closing the forward-only-N residual for good. Today's chained anchored tracks (live since 2026-07-16) are the bridge to this level, not the level itself — we name that precisely. Nothing holds Level III yet.
Roadmap
The strongest trust asset we own

Our own flagship: NOT SIGNIFICANT. Published anyway.

The first Level II credential ever minted — the both-schools ValidationExt seal — was run on MIZAN's own flagship strategy. The verdict: PSR 0.7226, below the 0.95 bar → NOT SIGNIFICANT. It is live on the registry wall next to the credentials that passed. A standard that only ever certifies its author is a logo; a standard that fails its author in public is a measurement. That credential is the proof the gate is real.

And the gate kept refusing. Apple buy-and-hold, +272,548% over 28.5 years — refused (Sharpe 0.89, below the bar). The S&P 500 itself — refused, with independence proven in-circuit at 0%: the benchmark is 99% market beta and the proof says so. Our own +895% AI model — refused. All live on the wall, all re-verifiable offline. A gate that would pass everything certifies nothing.

The honest fail is the product. Verify any of them on the wall below.
The Book

The library. Honestly graded.

Most are cryptographically proven in-circuit, as real minted STARKs — each card says which. The rest are research-validated after costs — shown with their true metrics and exactly what each needs to become provable. Nothing here is faked.

Prove & Verify

Run the proof. Then break it.

$select a strategy above…
▸ pick a strategy in the library
▸ press prove — the engine backtests, gates & seals in-circuit
▸ press verify — re-checked with zero trust
$mizan verify credential.bundle — zero trust
the independent verifier re-binds the data root, pins the gate,
and trusts the issuer for nothing.
Coverage

Can MIZAN verify your strategy?

The honest map, before you submit — pinned to a published methodology (docs/COVERAGE_METHODOLOGY.md, v3): the engine rail covers ~80% of systematic strategies today, the published roadmap lifts that to ~90%, and the remaining 10–15% — fill-dependent and unpriced-asset strategies — is a ceiling we state as a feature, because a verifier claiming ~100% would be asserting it can bind data it cannot see. Thirteen strategy classes are provable today; three are in build or on the roadmap; HFT we refuse on principle. The asset universe rolls in deliberately slowly: BTC (4h & daily), SPY and the US single-name/PIT-panel library are canonical today; NIFTY and gold are withdrawn — their source failed our own provenance standard, existing credentials verify forever under era law — and each new market lands only when its dataset is pinned to the canonical allowlist — provenance first, coverage second.

~80%
Of systematic strategies
covered · engine rail · methodology v3
~90%
The published path —
dynamic allocation · options · PIT equities
10–15%
Never covered, by design —
the ceiling is the credibility
Provable today
Trend & momentum
Breakout, moving-average and regime-gated ensembles (≤8 rules, weighted vote). The flagship credential is this class — on the wall now: Sharpe 1.63, net +301.6% after costs, and its Level II Deflated Sharpe reads 0.6779, not significant, published as-is. The class is proven; the honesty is the proof.
Proven path
Mean reversion & range
Band and reversion rules on bars — same ensemble DSL, same gate. The gate doesn't care which direction your edge leans; it cares whether it survives.
Proven path
Long-short directional
Signed positions with a direction-aware regime gate. Shorts are first-class, not a sign flip.
Proven path
Leveraged strategies
Constant leverage to 10×. Returns AND costs scale; equity floors at wipeout — over-leverage is caught by the worst-bar and drawdown checks, not hidden by them.
Proven path
Vol-targeted sizing
Inverse-volatility dynamic leverage from a trailing window — no-lookahead tested by perturbation.
Proven path
Multi-asset books · equal weight
One Merkle root binds every asset's history; the verifier recomputes it over all files.
Proven path
Multi-asset books · weighted sleeves
A different sub-strategy per asset with fixed weights, validated in-circuit and sealed inside the pre-registration commitment — re-weighting after the fact breaks the credential.
Proven path
Delta-neutral carry
Funding-collection strategies with their own audit path and regime treatment.
Proven path
Any market · any bar size · own data
Bring your own series; the proof binds to its Merkle root, with the bar interval and annualization basis sealed in-circuit. Proven in practice down to hourly bars. Public mints pin to the canonical-data allowlist.
Proven path
Volatility risk premium · v1
Short-variance against a committed implied-vol index (two series, role-bound in one root), with an explicit spread haircut the prover cannot claim below a floor — because our own research showed real spreads kill naive VRP.
Proven path
Live forward tracks · chained
The same sealed spec re-proven over a strictly extended window as data accrues — a backtest that becomes a growing live track, and created-in-hindsight fails mechanically: every extension must strictly extend a parent whose Bitcoin anchor predates the new bars; to fabricate January in June you would need a January timestamp you do not have. Run for real 2026-07-16: parent 800 bars → chained 1,096, all 20 verifier checks green zero-trust (17 single-credential checks + chain-continuity checks), artifacts public. Every credential minted in the app is chain-ready — one click re-proves it (⟳ Extend). Single-asset chains today.
Chain-extended
ML / black-box models
Proven for real 2026-07-17, two ways. Black-box FULL: an opaque model commits positions forward into an append-only track and the gate is computed in-circuit over that committed stream. zkML proven inference: a committed compact model runs its own decisions inside the circuit, every position provably from that one hidden model. Tampering, curation and re-tuning are refused by construction; forward-commitment timing rests on anchoring the track head ahead of time (OpenTimestamps / RFC-3161), not the circuit alone. Both minted as real STARKs, verified zero-trust, artifacts public. The model is never revealed. Large-net zkML remains a research frontier industry-wide; we don't relabel it.
Proven forward
Sealed models · dynamic sizing
Since era v10 (current era: v11) the bring-your-own (opaque / ML) rail commits fractional signed positions — a leverage per bar in ×0.01 steps under a cap enforced in-circuit — so an opaque model's sizing edge is provable, not just its direction. Parity ({-1,0,+1}) and fractional commitments live in separate hash domains; neither can replay as the other. Sample — a sealed-model mint under superseded era guest v10 (real STARK, 2026-07-22), distinct from the v11 flagship (Sharpe 1.63 · CAGR 26.6% · net +301.6%, whose Level II Deflated Sharpe reads 0.6779 — not significant; published as-is) — clears the full gate: Sharpe 1.50 · CAGR 28.8% · MaxDD 20.8% · net +345%, on /verify.
Proven forward
In build · roadmap
US equities on point-in-time data
Single-name equity credentials are live today — Apple, the S&P 500 itself and seven more, minted on a licensed survivorship-complete US feed and stamped into the canonical allowlist; the Apple and SPY verdicts on the wall are both refusals. The substrate underneath is bought and in hand: 46.2M price rows, 21,945 tickers back to 1997, 38,598 delisted names carried alongside 27,148 active ones, and dated index-membership snapshots. What remains is narrower than it used to be: wiring point-in-time universes into the allowlist so cross-sectional equity strategies — pick-the-top-N from an index — can be stamped without a current-members universe flattering them by design. That last mile is in build; single-name equity is not waiting for it.
Live · universes in build
Option chains · per-strike
Full surface P&L, spreads and strike selection. VRP v1 covers index-level variance; per-strike is the next honest step, not a relabel.
In build
Dynamic cross-asset allocation
Multi-asset books are proven today at fixed weights (equal-weight and weighted sleeves). Time-varying allocation — rotating weights across assets as signals change — is the next step: the same portfolio backtest, a richer per-asset position stream. Not a new engine.
Roadmap
The refusal

No HFT credentials. Not now — and honestly, maybe never.

Below the bar, the fill is the strategy. A high-frequency or market-making edge lives in queue position, fill probability and adverse selection — none of which exist in bar data, which is what this circuit proves over. We could run your tick backtest through the gate and stamp it. The stamp would be mathematically valid and economically meaningless.

What bars can't seeWhether your limit order actually fills, where you sat in the queue, and who picked you off. A backtest that assumes the fill assumes the profit.
We paid to learn thisWe live-tested a "winning" fast strategy with our own capital: 8 trades, 7 instant stop-outs. Real fills erased in hours what the backtest had blessed for years. It's in our public retraction ledger.
What it would takeTick-level order-book and trade-print data with provable provenance, plus a fill-simulation circuit an adversary can't game. If that day comes, we'll ship it loudly. Until then: refused.
A verifier that stamps what it cannot check is just a logo. The refusal is the product.
Submit Your Strategy

Mint a real credential. Yours.

▸ Launch window — minting is free · paid tiers switch on next

Paste the committed spec of a strategy you've already built, choose a canonical dataset, and this box mints a genuine 220KB STARK credential. The instant dev dry-run also MEASURES your proof's exact size, so the ETA you're quoted (typically ~20–60 min) is a measurement, not a guess. It also previews the gate verdict — a failing strategy is refused on the spot, and hours-class proofs are honestly declined by the public queue rather than silently killed.

▸ DSL reference — every field, valid values, human units
Indicators — a rule is one indicator + a signed vote weight
indicatorsignal (votes long when…)short_windowlong_windowthreshold_bps
Smafast SMA > slow SMA (crossover)fast SMA · barsslow SMA · bars
Emafast EMA > slow EMA (crossover)fast EMA · barsslow EMA · bars
Momentumtrailing return > thresholdlookback · barsentry return · bps
Donchianclose > highest close of prior N barschannel · bars
Bollingerclose > SMA + k·σ (breakout)window · barsk ×100 (200 = 2σ)
RsiRSI < level (mean-reversion)RSI period · barslevel ×100 (3000 = RSI 30)
Ensemble fields
rules — 1 to 8 weighted rules. Weight is a signed integer vote (negative = contrarian), clamped ±1000.
vote_threshold — weighted votes needed to enter long. With shorts on, vote ≤ −threshold enters short.
regime_window — 0 = off. Else longs require close > SMA(N); shorts require close < SMA(N).
allow_short — false = long/flat only. true = signed positions; shorts are first-class.
leverage_x100 — 100 = 1.0×, 250 = 2.5×, max 1000 = 10×. Scales returns AND costs; equity floors at wipeout, so over-leverage fails the drawdown/worst-bar checks honestly.
vol_target_bps — 0 = constant leverage. Else per-bar inverse-vol sizing toward this trailing vol (bps), capped at leverage_x100. Uses only data ≤ t−1.
crash_floor_x100 · vol_cap_bps · crash_lookback · crash_drop_bps — optional crash brake: de-lever to the floor when trailing annualized vol exceeds the cap (9000 = 90%) or the trailing N-bar return drops below −drop. No lookahead, no phantom stops.

All values are integers — the circuit is integer-deterministic. Windows are in bars of your chosen dataset (60 bars = 60 days on a daily set, 10 days on a 4h set). Full SDK docs ship with the local kit: [email protected].

Costs are committed inside the proof and printed on the credential. The public tier is up-only — proving at harsher costs strengthens the credential; understating them is the forgery we refuse. Institutional fee schedule below 7 bps? Attested tier — documented fees only, and the slippage floor stands regardless.

Read before submitting: hosted minting means your spec is processed on MIZAN's server — it is kept only until the mint finishes, then deleted, and it is never committed to the proof. If your strategy must never leave your machine, switch to mint on your machine above — same engine, same credential, and only the finished proof is ever uploaded. Queue: one real mint at a time, 3 pending max, 2 per email per day.

▸ your dry-run verdict appears here in seconds
▸ a PASS queues the real STARK mint
▸ this panel tracks it live — the bundle downloads when verified
Credential Registry

Issued credentials. Verify any of them.

Every entry is a real STARK, independently re-verified and timestamp-anchored into Bitcoin + an RFC-3161 authority — it cannot be backdated. Every card names the engine era that minted it (v6 → v11, current era v11 · validation-complete); the era registry is append-only, so a v10 credential verifies against its own era forever — superseded is not revoked. Honest fails stay on the wall next to the passes: the wall is a record, not a brochure. Listing is opt-in; strategies are never revealed; metrics appear only where the quant chose disclosure.

loading registry…
Disclosure

What this proves — and what it doesn’t.

Guaranteed by the cryptography

  • Level I: a hidden strategy cleared the MIZAN gate (Sharpe · CAGR · drawdown · worst-bar · walk-forward) on tamper-bound data, after floored costs — in-circuit, no lookahead.
  • Level II: both canonical schools of backtest honesty — the López de Prado/Bailey in-sample program and the Harvey–Liu/Hansen universe program — proven in one credential, no prover-chosen knobs. To our knowledge, the first.
  • The strategy logic was provably absent from the credential.
  • A forged, weakened, cost-understated or cherry-picked credential is rejected — including our own (the flagship's Level II verdict is a published NOT SIGNIFICANT).
  • Pre-registered (U10): the strategy's commitment predates the out-of-sample window → its OOS performance is provably not hindsight-fit.
  • The boundaries — named by us before anyone else can find them

  • A verifier that hides its limits is a logo. These are ours, each one a dated promise: entries leave this list only by shipping. One already has — it's at the bottom.
  • We audited ourselves first, in public. The full adversarial review is published — findings, fixes, and what's still open. Most vendors publish a badge; we published the wounds. The paid external ZK audit is budgeted and next; we don't borrow its verdict early.
  • A credential is a seal on history, not a promise about the future. It proves the record was computed honestly on this data — nothing on earth can promise live fills, and anyone who sells you a backtest as one is lying. We won't. That refusal is printed on every credential.
  • The ledger counts every committed trial exactly. What no mathematics can count is the search a researcher ran before committing — so we say so, on the credential itself, instead of letting you assume otherwise. Level III pre-registration closes it, and it ships as shipped, not as a promise dressed as a feature.
  • Data roots are pinned and fail-closed — the verifier rejects anything off the canonical allowlist. The deepest remaining boundary is that we curate that list; independent data-authority signing is the named next step, not a buried asterisk.
  • The live demo runs on a fast dev seal so you can feel the mechanics in seconds; every real credential is the full cryptographic STARK. The flagship is one — verify it yourself and don't take this sentence's word for it.
  • CLOSED — and that's the point of this list. "Anchoring pending" used to sit here. Now every registration and mint is dual-witnessed — Bitcoin (OpenTimestamps) + RFC-3161 — so times are provable, not asserted. (The library demo's preset date stays illustrative; every self-serve credential anchors for real at mint.) This list only shrinks, and every deletion is a receipt.