Evidence register
Every gate below is reproduced from the project's own documents: the live fabric-to-cache release gate, the distributed key-generation gate, and the production register that governs any anonymity claim.
Live testnet gate — 19 of 19 met
A gate is met only when it exists in the live data path, has a negative test, and the same commit passes race tests, vet and multi-process deployment evidence.
- LIVE-01One pinned authority signature and every operator attestation bind the same complete topology draft.MET
- LIVE-02Each node holds only its own identity and epoch key; hop keys are derived locally and fail closed on loose file permissions.MET
- LIVE-03Every emitted packet is exactly 1200 bytes at the signed interval, including idle periods.MET
- LIVE-04The 1152-byte mix ciphertext is unchanged; the padding region authenticates stream, batch, sender and sequence.MET
- LIVE-05Unknown sources, wrong sizes, invalid tags, wrong receivers and duplicates are rejected before cache or relay.MET
- LIVE-06Queues and stream counts are publicly bounded; cover cells are not cached; cache pressure cannot change the schedule.MET
- LIVE-07Raw cache coordinates are immutable, atomically written and committed by a digest over the whole ordered batch.MET
- LIVE-08The sending node imports no selection or reconstruction code; the materialiser imports no network code.MET
- LIVE-09Three or more operators run with distinct identities, endpoints, caches, sequence state and threshold shares.MET
- LIVE-10Partial proofs arrive through a separate fixed-cadence fetcher; the offline materialiser never contacts an operator.MET
- LIVE-11A 2-of-3 threshold decrypt requires unique, proof-valid shares; no aggregate secret is reconstructed.MET
- LIVE-12The descriptor carries one signed Neff shuffle per operator, and the materialiser verifies the full chained transcript.MET
- LIVE-13Acceptance requires exact coding dimensions, SHA-256 commitment and Ed25519 signature over the object header.MET
- LIVE-14Output is an immutable .nomadobject already trusted by the current browser trust anchor.MET
- LIVE-15Race tests, vet, module tidiness, snapshot checks, container isolation and capture verification pass on one commit.MET
- LIVE-16Operators generate credentials independently, exchange only public enrolments and attest one common draft offline.MET
- LIVE-17Every operator runs the official Pedersen DKG state machine over signed, bounded messages on a public schedule.MET
- LIVE-18Epoch activation requires one attestation from every operator over one identical public committee and transcript.MET
- LIVE-19The descriptor embeds the distributed certificate, and live services use those exact per-operator shares.MET
Distributed key generation gate — 12 of 12 met
This gate closes the software gap between independently held operator identities and threshold decryption. Passing it does not establish independent administration.
- DKG-01The signed topology binds membership, threshold, session, start time, phase duration and a dedicated key per operator.MET
- DKG-02Ceremony keys are distinct from node identity and hop keys, stored 0600 and verified against the signed topology.MET
- DKG-03The process uses an established Pedersen DKG state machine; Nomad implements no replacement primitive.MET
- DKG-04Every message has a bounded canonical encoding and an outer signature over network, topology, epoch, session and sender.MET
- DKG-05The transport broadcasts to every signed member, disables proxies and redirects and requires TLS 1.3.MET
- DKG-06No message is accepted before the signed start or after its deadline; missing delivery aborts the ceremony.MET
- DKG-07The append-only journal makes retries idempotent, treats a second value as fatal and refuses to resume a broken session.MET
- DKG-08Activation requires the exact ordered membership; threshold-only or partial success is rejected.MET
- DKG-09Every operator independently derives the same public committee and signs the same manifest.MET
- DKG-10Each operator writes only its own private share, proved against the certified public share; no aggregate secret exists.MET
- DKG-11The descriptor embeds the exact certificate; share service and materialiser reject anything not bound to it.MET
- DKG-12The isolated deployment runs three ceremony processes over TLS and records one certificate and three distinct shares.MET
Production register — 0 of 30 met
The authoritative production register lives in nomad-protocol. No production gate is met; several are partial, and each names its own blocker.
- PROD-01Protocol freeze and a conformance suite.REMAINS
- PROD-02Full traceability from every production claim to a test.REMAINS
- PROD-03An independent second implementation.REMAINS
- PROD-04Independent cryptographic review of the mix.REMAINS
- PROD-05At least five independently administered operators with real endpoints, witnessed key custody and drills.REMAINS
- PROD-06+The remaining production criteria, each with its own recorded blocker in the project's register.REMAINS
Wire measurement
Recorded by a dedicated bridge during the live deployment run. Every payload was exactly 1200 bytes.
| Sender | Cells | Mean | Median | Min | Max |
|---|---|---|---|---|---|
| operator a | 102 | 49.993 ms | 49.976 ms | 46.516 ms | 53.398 ms |
| operator b | 102 | 49.994 ms | 49.979 ms | 42.292 ms | 56.923 ms |
| operator c | 102 | 49.993 ms | 49.965 ms | 48.883 ms | 51.748 ms |
capture sha-256 630286a8740c6c39df7e9c580f5d4721901b47b0636d9b2c5cc96baaa80bb9e6