secp256k1 research state

One operator view for the current decision, formal substrate, evidence, active work, and generated trust checks.

Canonical snapshot snapshot 307 ledger rows / ~268 distinct
Scope boundary. The environment maps and verifies the research boundary. It does not solve the plain secp256k1 discrete logarithm problem. Monitoring means new evidence can reopen a route; it does not mean impossibility was proved.
307
ledger rows
~268
distinct results
179
proved modules
486
corpus claims
17
routes evaluated
8
typed cells
2
generated seeds
1
completed exact toy run

Current operating state

The decision layer controls what work is justified; proof volume does not select an attack route.

Reference deployment
AUTH-HYP-M16-FIXED-TARGET-YIELD-001-20260730-01Consumed toy run

One hash-bound synthetic-toy diagnostic completed.

HYP-M16-FIXED-TARGET-YIELD-001 / TASK-026 only: 3000000 primary trials across 3 frozen E_7 toy subgroups. Terminal: CLASSIFY_AS_KNOWN_LOCAL_SIMPLIFICATION; rerun authorized: false. Native Engine selection, direct secp256k1 work, solvers, and promotion remain closed. Structural selection RS-2026-07-24-001 remains unchanged.

Research Engine v0 queue

0 selected; 0 ready. Positive toy evidence is supported, never proved; threat-model scope, route decision, and evidence remain separate.

Native queue closed
No native Engine candidate clears every scientific gate.

The native queue remains empty; the exact external TASK-026 singleton is governed by the decision substrate. A future native candidate still requires both an exact mechanism and an independent raw-artifact validator.

Typed research questions

8 mechanism/property cells; 4 decided at desk; 2 seed-eligible questions; 2 submitted; 0 quality-cleared. Typed screens, seeds, and drafts authorize nothing.

Open evidence

Can this target-property cell be decided without an ECDLP run: Construct or rule out a fully priced auxiliary-curve instance over the secp256k1 base field under the exact PKC 2016 conditions. The answer must instantiate or refute the typed construction and price every named precomputation term.

HGS-5CC94AD51AE6 · CELL-M-PKC-AUXILIARY-CURVE · R-PETIT-COMPOSED-MAPS

The first output is a bounded arithmetic construction or no-instance record plus a complete precomputation estimate, not an ECDLP experiment.

Property resolution

Can an exact desk derivation price Total construction, representation, solving, and recovery cost of the corresponding S17 system. against the declared baseline before any solver run?

HGS-3266E42A729C · CELL-M-PKC-SMOOTH-M16 · R-PETIT-COMPOSED-MAPS

This open desk-cost cell has exact input presentations, an exact set-theoretic projective-tree bridge on the stated nonsingular characteristic domain, a complete named exceptional-fiber classification, deterministic control and secp256k1 GLV recovery checks, a frozen recursive projective S17 contract, kernel-checked fixed-degree projective resultant plus literal Sylvester unit-one and end-to-end common-root theorems, the actual frozenC specialization, the exact all-stage frozen projective witness chain, an exact literal finite MvPolynomial family in guarded form, an exact affine/infinity chart-polynomial cover for the frozen stage-14 predicate after injective base change, exact necessary infinity-stratum pruning, and exact conditional infinity propagation. Each fixed InfinityMask I uses 14 - I.card affine variables, no guard equations, and fifteen H equations with degree ceilings 2/4/2; the existential cover is exact and retains [1:0]. Affine external inputs reduce the exact logical cover from 16384 masks to 987 separated masks, and nonzero endpoint determinants conditionally reduce it to 377 interior masks. TASK-025 gives the nested local reductions 377 to 129 to 69 to 36 and the independent boundary-only branch 129 to 60. Under endpoint and BalancedPropagatedRegular assumptions it proves an exact single empty-mask affine chart, not a unique witness. The direct propagation applies over any field, but the source-stage bridge still requires injective base change into an algebraically closed target and separately assumed mapped-target regularity. Symbolic nonzeroness, nonemptiness, density, probability, and genericity are not proved, and source-field computation does not automatically establish mapped regularity. The 2^14 logical masks are not enumerated or materialized, and neither are the pruned families. It is not an expanded direct S17 polynomial, an unconditional base-field descent theorem, a solver run, or evidence of independent dimensions or relations. The complete cost bridge remains open. CQ-SEMAEV-S17-SYSTEM-COST remains partial; solving cost, rank, and yield remain unpriced. The scoped result has zero_retention_success and does not justify a production mask sweep, solver run, target computation, hypothesis retention, experiment authorization, cost inference, route rejection, or route promotion.

Desk cost

Why this decision

Canonical rationale, not a claim of impossibility

  • RS-2026-07-22-001 is historical after supersession; this current decision explicitly carries forward its zero-promotion assessment.
  • The owner selected the exact S3/S4 coordinatewise C3 polynomial classification and the S4 fixed-target consequence as the sole current structural uncertainty because they can resolve the premise of the naive GLV-Semaev quotient without an attack run.
  • Exact symbolic certificates and narrowly scoped Lean covariance theorems can reduce this uncertainty while preserving the parked experiment status and every P0-P4 result.
  • A diagonal-only result is a bounded no-go for independent u_i=x_i^3 quotienting, not a lower bound for Groebner/F4, faithful Petit, or the whole R-GLV-SEMAEV route.
  • A larger stabilizer would still require an exact quotient, recovery map, orbit tags, excluded components, cost prediction, and a later decision before any externally validated solver experiment.

Route portfolio

All routes are bound to an exact threat model, evidence gate, stop condition, and next action.

Open detailed route map

Disposition distribution

17 canonical routes

Guardrail 1Baseline 1Constant factor 1Ruled out for target 4Open, parked 4Monitor 1Conditional inputs 2Separate threat model 3
ECDLP route portfolio
RouteDispositionThreat modelPriorityNext action
Generic-group lower boundR-GENERIC-LOWER-BOUND Guardrail classical-generic P0 Retain as a mandatory comparison and scope guard; no new experiment.
Baby-step giant-step and Pollard rhoR-GENERIC-BASELINE Baseline classical-single-target-plain, classical-generic P0 Use as the benchmark comparator in the evaluation harness.
GLV endomorphism accelerationR-GLV Constant factor classical-single-target-plain P0 Keep as target structure available to a selected route; do not treat it as a standalone attack.
Pohlig-Hellman subgroup reductionR-POHLIG-HELLMAN Ruled out for target classical-single-target-plain P0 Retain as a machine-checked elimination certificate.
MOV, Frey-Ruck, and Tate/Weil pairing transferR-PAIRING-TRANSFER Ruled out for target classical-single-target-plain P0 Keep the target-specific exclusion; defer a full pairing library unless a new route needs it.
Smart, Satoh-Araki, and Semaev anomalous-curve liftingR-ANOMALOUS-PADIC Ruled out for target classical-single-target-plain P0 Retain the formal exclusion; do not build an elliptic formal-group stack for this target now.
Weil descent and GHS-style transferR-WEIL-DESCENT Ruled out for target classical-single-target-plain P1 Document as a target-applicability exclusion; no formal stack now.
Prime-field index calculusR-PRIME-FIELD-INDEX-CALCULUS Open, parked classical-single-target-plain P1 Preserve evidence and prerequisites; wait for explicit route selection before any new experiment.
GLV-symmetrized Semaev systemsR-GLV-SEMAEV Open, parked classical-single-target-plain P1 Keep GLV-SEMAEV-ITER-001 closed without a solver run. Accept only a materially different phase-preserving mechanism with an exact recovery map, orbit tags, excluded components, a falsifiable full-cost prediction, and an independent validator through TASK-008 before any new decision.
Petit-style composed rational mapsR-PETIT-COMPOSED-MAPS Open, parked classical-single-target-plain P2 Keep the route parked. TASK-023 through TASK-025 completed the exact chart cover, necessary infinity-stratum filters, and conditional single-affine-chart propagation. TASK-026 then consumed its one external synthetic-toy authorization: all 3000000 trials completed, 911 exact relations were accepted, 907 were affine regular, and all six curve-arm regularity gates passed. REO-2026-07-31-001 records the result. This supports the bounded enabling claim that the named regular locus is usable in the frozen toy construction. Matched orbit/plain controls retained no H_NEW qualifying size, so the GLV-specific explanation is bounded negative and the terminal is CLASSIFY_AS_KNOWN_LOCAL_SIMPLIFICATION. The result is not source-faithful PKC relation generation, rank, solver scaling, recovery, total cost, 256-bit persistence, or an ECDLP improvement. Only formulate and review a source-faithful, non-executable HYP-M16-SOLVER-SLOPE-001 proposal with end-to-end metrics and scaling death criteria. Keep every TASK-026 rerun, production mask sweep, solver, experiment, route rejection, route promotion, cost claim, and exact-target inference closed until a separate dated authorization. Keep the auxiliary-curve cell parked until a primary source supplies a finite family or search domain with a completeness criterion.
Elliptic divisibility sequences and division-polynomial re-encodingsR-EDS-DIVISION-POLYNOMIAL Open, parked classical-single-target-plain P2 Keep HYP_WARD_EDS_001 parked; finish no additional point-division bridge unless a selected route needs it.
Isogeny, endomorphism-ring, and Frobenius transferR-ISOGENY-ENDOMORPHISM-TRANSFER Monitor classical-single-target-plain P3 Monitor literature and reuse GLV facts; no build now.
Multi-target and reusable-precomputation tradeoffsR-MULTI-TARGET-PRECOMPUTATION Conditional inputs classical-conditioned P1 Represent in the evaluation contract; no experiment in this phase.
Interval DLP, partial-key knowledge, and auxiliary-power algorithmsR-INTERVAL-AUXILIARY-INPUT Conditional inputs classical-conditioned P2 Keep as a scope category for future protocol or leakage analyses.
Hidden-number and lattice attacks on biased or reused ECDSA noncesR-HNP-NONCE-LEAKAGE Separate threat model implementation-leakage P1 Preserve as a separate security track; no lattice foundation build for the primary objective now.
Invalid-curve, twist, fault, and side-channel routesR-PROTOCOL-FAULT-SIDECHANNEL Separate threat model implementation-leakage P1 Record scope; do not expand the Lean substrate until a concrete implementation-verification goal exists.
Fault-tolerant quantum ECDLPR-QUANTUM-SHOR Separate threat model fault-tolerant-quantum P1 Update the registry estimate and monitor primary literature; do not build a quantum Lean stack now.

Formal substrate

11 of 17 critical nodes are closed. Blocked nodes retain exact resume conditions.

Open canonical map
Formal substrate critical nodes
Critical nodeStatusDepends onBlockerEvidence
Canonical counts, registries, generated views, and active queuetruth-layer Closed none none STATUS.mdtasks/NEXT.md
secp256k1 field and subgroup parameterssecp-parameters Closed none none Ecdlp/Proved/Secp256k1PrimeP.leanEcdlp/Proved/Secp256k1PrimeN.lean
Exact rational-point cardinality and full cyclic groupsecp-rational-group Closed secp-parameters none Ecdlp/Proved/CurveCardinalityExact.leanEcdlp/Proved/CurveFullGroup.lean
Fixed-transcript generic-group collision coregeneric-security-core Closed secp-rational-group none Ecdlp/Proved/GenericGroupBound.leannotes/SECURITY_SCOPE.md
Abstract protocol algebra and concrete curve instantiationprotocol-soundness Closed secp-rational-group none Ecdlp/Proved/ProtocolInstantiation.lean
GLV automorphism on the full rational point groupglv-rational-scope Closed secp-rational-group none Ecdlp/Proved/GlvSubgroupEigenvalue.leannotes/SECURITY_SCOPE.md
Semaev S3/S4 formal foundationssemaev-foundations Closed secp-rational-group none Ecdlp/Proved/SemaevThree.leanEcdlp/Proved/SemaevFour.lean
Division-polynomial, EDS, degree, and coprimality substratedivision-polynomial-foundations Closed secp-parameters none Ecdlp/Proved/DivisionPolynomialCoprime.leanEcdlp/Proved/NormEDSConsecutiveZeros.lean
Exact closure E[n] structure for n in {2,3,4,5,7}, including the first composite case n=4small-torsion-family Closed division-polynomial-foundations none Ecdlp/Proved/TwoTorsionStructure.leanEcdlp/Proved/DoublingPointFormulaBar.lean
Coprime and distinct torsion locitorsion-loci Closed division-polynomial-foundations none Ecdlp/Proved/TwoTorsionCount.lean
Weil divisor, Miller function, and reachable evaluation layerweil-w1-w3 Closed small-torsion-family none Ecdlp/Proved/WeilMillerEval.leannotes/WEIL_LADDER.md
Uniform point-level multiplication coordinate formulan7-uniform Blocked division-polynomial-foundations, small-torsion-family blocker-point-division-map, blocker-n7-certificates Ecdlp/Targets/n7_uniform_carrier_induction.leantargets/n7_uniform_secp256k1_x.json
Uniform separability and geometric n-torsion countn10-uniform-separability Blocked division-polynomial-foundations blocker-uniform-separability notes/SEPARABILITY_ROUTES.md
General E[n] structure over the algebraic closuregeneral-n-torsion Blocked n7-uniform, n10-uniform-separability blocker-point-division-map, blocker-uniform-separability notes/DIVISION_POLY_TORSION_MAP.md
Weil reciprocity and the bilinear non-degenerate pairingweil-w4-w5 Blocked weil-w1-w3, general-n-torsion blocker-weil-reciprocity notes/WEIL_LADDER.mdBARRIERS.md
P-256 exact rational-point cardinalityp256-exact-cardinality Outside release secp-parameters blocker-p256-cardinality Ecdlp/Proved/P256Cardinality.lean
New cryptanalytic hypothesis testingexperimental-hypotheses Parked truth-layer none experiments/HYPOTHESES.yaml

Accepted blockers

Missing foundations are recorded, but do not authorize work without a selected route.

Accepted formal blockers and resume conditions
BlockerWhat is missingResume condition
No uniform Point-to-division-polynomial multiplication mapupstream-foundation Mathlib exposes the polynomial identities but not the theorem connecting [n]P to the phi/psi coordinate formulas for all n. An upstream multiplication-coordinate theorem lands, or a reviewed in-repo induction closes the torsion bridge.
Four N7 algebra walls need large checked elimination certificatesproof-engineering The statements are machine-elaborated and numerically/symbolically validated, but checked cofactors for the degree-heavy identities are not yet authored. A reproducible certificate generator emits Lean-checkable cofactors for all four algebra walls.
Uniform separability of multiplication-by-n is not availablemissing-theory Small n is closed, while the general prime-to-characteristic counting and differential argument remains absent. A checked [n]*omega=n omega or equivalent general separability theorem is available.
Weil reciprocity and divisor-degree machinery are missingupstream-foundation The reachable W1-W3 evaluation substrate is closed; W4 reciprocity is required before the pairing can be assembled. Mathlib or this repository gains the needed divisor/tame-symbol reciprocity layer.
P-256 exact cardinality needs a general point-counting/Hasse routeout-of-scope-foundation Only n divides the P-256 group cardinality is proved; the secp256k1 j=0 certificate does not transfer. A reviewed Hasse/Schoof or curve-specific exact-cardinality proof becomes available.

Sync Health

The public and agent-facing views resolve back to canonical machine sources and their gates.

Reconsideration triggers

What can legitimately reopen route selection

  • A materially different phase-preserving quotient, birational construction, or relation mechanism supplies exact fixed-target semantics, recovery, orbit tags, excluded components, and a falsifiable full-cost prediction.
  • An independently replayable counter-certificate or proof identifies an error in the frozen S3/S4 polynomial formulas or coordinatewise classification, the S4 resultant/fixed-target construction, or their assumptions.
  • A formal cost theorem combines the finite target orbit with a new mechanism and proves a nonconstant full-pipeline gain rather than attributing asymptotic value to orbit size alone.

Operating policy

post-task026-decision-review

  • Engine exploration capabilitytrue
  • Exact decision experimentfalse · consumed AUTH-HYP-M16-FIXED-TARGET-YIELD-001-20260730-01
  • Native decision explorationfalse
  • Structural routesR-GLV-SEMAEV
  • Promotion experimentsfalse
  • Promoted routenone
  • Merge ruleThe owner delegated merge authority on 2026-07-22. Merge only from a clean branch after required CI is green, the diff has a documented scope and rollback path, and no unresolved blocking finding is known.
  • Product claim policyrepo/PRODUCT_MODEL.jsonscripts/check_product_model.py

Work queues

Research and product contracts have separate owners and KPIs; neither can count as progress in the other.

Open queue router

TASK-013 · Build and calibrate Research Engine v0

ECDLP research

The repository needs a closed evidence -> generation -> adversarial proposal review -> selection -> bounded exploration -> validation -> retention loop without weakening the independent promotion gate. Creative model output remains untrusted; deterministic gates compile it into a candidate or retain its exact blockers.

Maintenance Non Executable During Task026

TASK-008 · Maintain evidence-gated candidate intake

ECDLP research

New progress must enter through source-pinned mathematical evidence or a concrete mechanism, not by silently reviving a parked route. Generated research seeds reduce dependence on one agent noticing an intersection, while adversarial compilation prevents fluent text from becoming authorization.

Active

TASK-009 · Resolve the bounded GLV-Semaev structural uncertainty

ECDLP research

The exact coordinatewise C3 action on S3 and S4 decides whether the naive invariant quotient has the symmetry it claims. This bounded structural uncertainty is now resolved; it was not route promotion or an experiment hypothesis run.

Completed Bounded Structural

TASK-010 · Independent adversarial audit at a stable checkpoint

ECDLP research

The independent audit found reproducibility, lifecycle, calibration, semantic-drift, and authorization defects. This task repairs those findings before Research Engine v0.2 is treated as stable.

Completed Accepted

TASK-014 · Run the first post-v0.2 scientific activation cycle

ECDLP research

A new prime-field Semaev/Petit proposal cannot be assessed honestly without claim-level source boundaries and a full-cost bridge. Yokoyama and Amadori are now bound to inspected primary artifacts and exact extracts; Kudo CANS 2018 remains full-text unread. The deterministic smooth-subgroup desk screen resolves the two arithmetic predicates but leaves solving degree, recovery, relation independence, and total work unknown, so it does not justify a solver or native experiment.

Evidence Closed Phase D Blocked

TASK-015 · Map the bounded hypothesis frontier and select one desk question

ECDLP research

The mathematical idea space is open-ended, but the actionable frontier can be made finite relative to a versioned evidence snapshot, mechanism grammar, route model, target properties, recovery contract, and cost quantities. The existing knowledge graph already supplies that projection. Choosing the exact M16 desk-cost cell avoids both a free-form idea search and an unbounded auxiliary-curve search.

Completed Non Executable Scoped Blocker

TASK-016 · Fix the source-faithful M16 ideal and recovery semantics

ECDLP research

TASK-015 showed that low input degree can be obtained only by adding variables, while solving degree, fill-in, recovery, and rank remain unknown. Those quantities are not meaningful until direct S17, the recursive S3 tree, and the source-factor membership circuit are related by an exact base-field semantics with every exceptional fiber accounted for.

Completed Non Executable Scoped Blocker

TASK-017 · Classify M16 exceptional fibers, liftability, and recovery domain

ECDLP research

TASK-016 disproved the naive global affine substitution and isolated two independent exceptional mechanisms: identity prefixes and extension-only or non-liftable fibers. The next useful result is a complete set-theoretic classification of those fibers and a recovery domain, not a choice from an unbounded hypothesis space and not a solving-degree estimate.

Completed Non Executable Scoped Blocker

TASK-018 · Freeze recursive projective S17 and prove the reverse projection

ECDLP research

TASK-017 proves the complete set-theoretic projective S3-tree semantics and recovery domain. TASK-018 was required to freeze the exact recursive projective S17 object before any attempt to certify its universal reverse projection or price a solver.

Completed Non Executable Scoped Blocker

TASK-019 · Kernelize fixed-degree projective resultants and reverse projection

ECDLP research

TASK-018 freezes the recursive projective S17 contract, records its forward algebraic argument, and replays bounded S4/S5 forward/reverse fixtures, but finite fixtures cannot replace a universal proof. TASK-019 isolates which part of that gap is generic resultant algebra and which part still depends on the actual frozen recursion.

Completed Non Executable Scoped Blocker

TASK-020 · Kernelize frozen recursive C_r specialization

ECDLP research

TASK-019 proved the generic fixed-degree resultant theorem, but that theorem did not name or constrain the actual frozen recursive symbolic family. TASK-020 binds the real recursion before any universal projective witness extraction is attempted.

Completed Non Executable Scoped Blocker

TASK-021 · Kernelize universal frozen C16-to-C2 projective witness extraction

ECDLP research

TASK-020 returns a non-irrelevant common projective root of the fixed homogenized predecessor and local slices at every vanishing successor. To recurse, those homogenized evaluations must be identified with the actual projective frozen-family specialization, including `[1:0]`, and the witnesses must be assembled into one exact chain.

Completed Non Executable Kernel Result

TASK-022 · Materialize the frozen stage-14 guarded projective system

ECDLP research

TASK-021 proves an exact recursive chain of fourteen valid projective witnesses, but the existential `ProjectivePair` representation is not yet a finite scalar polynomial inventory. A guard `A*U + B*V - 1 = 0` expresses exactly that `(U,V)` is not `[0:0]` over a field while retaining `[1:0]`. The target representation is one literal finite `MvPolynomial` family: `∃ assignment : GuardVar → K, ∀ e : GuardedEquation, MvPolynomial.eval assignment (guardedEquation q y e) = 0`.

Completed Non Executable Kernel Result

TASK-023 · Replace guarded projective redundancy by an exact chart cover

ECDLP research

TASK-022 gives an exact finite polynomial system, but its four `(U,V,A,B)` scalars and one guard per projective slot retain both projective-scale and guard-witness redundancy. Every valid projective pair over a field lies in exactly the needed two-chart cover: the infinity branch uses `[1:0]`, while the affine branch uses `[X:1]`. Selecting one branch for each of fourteen intermediate slots leaves, for a fixed mask `I`, exactly `14 - |I|` scalar variables and fifteen literal `H` equations.

Completed Non Executable Kernel Result

TASK-024 · Prove necessary infinity-stratum pruning

ECDLP research

TASK-023 proves an exact cover over all `2^14 = 16384` affine/infinity masks but does not distinguish masks that cannot occur. The local triquadratic `H` identities at `[1:0]` expose exact necessary conditions. With affine external inputs, adjacent infinity slots would force an external projective `v` coordinate to vanish, so every solution mask is a separated subset of the fourteen-slot path. This reduces the exact logical cover to 987 masks without a solver or production enumeration.

Completed Non Executable Kernel Result

TASK-025 · Propagate infinity constraints to a conditional affine chart

ECDLP research

TASK-024 conditionally leaves 377 interior separated masks and proves that every isolated infinity fixes its adjacent affine coordinates. TASK-025 substitutes those forced coordinates into the neighboring literal `H` equations, extracts explicit exceptional polynomial conditions, and proves that a precisely stated balanced nonvanishing condition makes the empty infinity mask complete. A one-chart conclusion means only one affine representation branch on that conditional locus, not one solution or an ECDLP shortcut.

Completed Non Executable Kernel Result

TASK-026 · Measure fixed-target balanced-regular yield on frozen toy E7 subgroups

ECDLP research

TASK-025 proves that explicit endpoint and balanced nonvanishing assumptions reduce the exact projective cover to one affine chart, but it does not show that fixed-before-sampling targets admit enough such relations to make that chart usable. This task performs the cheapest precommitted test that can kill that continuation before any solver work. It does not test a secp256k1 key, a faithful PKC factor base, solver scaling, rank, recovery, or total ECDLP cost.

Completed Independently Validated Terminal

TASK-027 · Recompute the exact M16 factor-base census and current proposal regime

ECDLP research

the source heuristic used all `D=564522` subgroup coordinates, while the exact curve factor base depends on whether `x^3+7` is a square. This task resolves that target property and records separate exact conditioned null comparators before any solver proposal can interpret a toy slope. These comparators do not establish the actual group-sum distribution and may leave additional zero-sum configurations uncounted. The task also binds the immutable proposal's own statement that its current at-most-24-bit ladder is calibration-only.

Completed Non Experimental Certificate

TASK-028 · Close the source-faithful M16 mechanism and sound acceptance contract

ECDLP research

the typed cell previously cited a coarse source summary while the exact map chain, System (4), recovery boundary, and partial cost formula were distributed across prose and older certificates. This task binds those facts to exact primary-source locators and separates source statements from repository-derived completion semantics.

Completed Nonexperimental Certificate

TASK-029 · Formulate and review the current-seed M16 solver-slope proposal

ECDLP research

TASK-028 produced the current typed seed and exact source input, but it did not supply a generalized-root algorithm or complete cost bridge. TASK-029 tests whether the same scientific mechanism can now clear proposal intake without renaming an old premise or converting a design specification into evidence.

Completed Reviewed Hard Rejected Zero Retention

TASK-011 · Validate the external product pilot

KeyAI product

The secp256k1 repository demonstrates an owner-operated research-state loop. It does not establish that another team has the same pain, can use the contracts, or will return.

Active

TASK-012 · Build configurable intake after a pilot contract

KeyAI product

A hosted or multi-project platform is justified only after a real team exposes the minimum adapter boundary.

Blocked