Development phase
Cryptographic review authentication
Zero-knowledge infrastructure that lets platforms distinguish reviews carrying cryptographic evidence of configured eligibility from unverified feedback — without suppressing the latter. In active development, with working prototypes and five hash-locked Phase 1 evidence bundles.
REF establishes cryptographic provenance between a review and an eligible customer event.
It does not determine whether the review is true.
Development status
Four subsystems, each with an implemented state and the evidence that establishes it.
Cryptography
Consensus
Testing
Verification
- 1,155
- Circuit constraints
- 8/8
- Negative vectors rejected
- 4
- Test-network nodes
- 4
- EV-008 safety invariants checked
Verification evidence
Every claim on this page traces to a locked, hashed artifact in the REF verification repository. Internal verification follows Rigorous Digital Engineering methodology.
Consensus TLA+
Token lifecycle TLA+
Mechanism validation
Threat model
Internal ZK circuit audit
- 5/5
- Evidence bundles hash-locked
- 1,155
- R1CS constraints
- 0
- EV-008 invariant violations
- 500/500
- Archived rows satisfy guard
- 8/8
- Vectors rejected
Technical foundation
Zero-knowledge proofs
- Circom token circuit implemented; internal EV-011 constraint audit recorded
- Groth16 on BN254 with trusted setup
- Python SDK operational
- FastAPI REST endpoints
Consensus protocol
- PBFT with Ed25519 signatures
- Rotating committee design
- BFT fault model: f < n/3
- Bounded TLA+ safety model checking
Security model
- Dolev-Yao network adversary
- Minority validator compromise
- Constraint-level circuit evidence and negative-vector testing
- Phase 1 evidence bundle hash-locked; independent external audit not yet completed
- Not yet production-audited — independent review planned
Development roadmap
Cryptographic foundation
Zero-knowledge proof system implemented and tested.
Consensus protocol
PBFT consensus with Byzantine fault tolerance.
Evidence bundle lock
Five Phase 1 evidence bundles are hash-locked: consensus and token-lifecycle model checking, threat-model analysis, circuit-audit evidence, and MC-500 mechanism analysis. Assurance scope differs by artifact.
Planned external review and network expansion
Target independent protocol review. Scale the validator network and optimise performance.
Production deployment
Enterprise pilots and compliance certification.
Technical collaboration
Five Phase 1 evidence bundles are hash-locked. Independent external audit remains a planned next-stage activity; we welcome academic collaboration on advanced formal properties.