From specification to production, one gate at a time.

The roadmap moves from specification to implementation, real operation, independent review, and conservative activation. Timing follows completed dependencies and review findings.

Architecture complete · Implementation next

The architecture and security specification are prepared. Contract implementation and signer operations are the next release phase.

Specify

Define the market-observation policy, independent validation model, signed payload, contract invariants, destination domains, consumer protections, operating model, and acceptance tests.

  • Architecture and trust boundaries
  • Security and acceptance specification
  • Tezos X Layer 1 and Layer 2 publication model
  • Public communication baseline

Implement

Build the oracle contract, canonical payload, independent validator paths, signer tooling, permissionless relay, manifests, monitoring, and adversarial test suite.

  • Threshold authorization contract
  • Independent validation-path software
  • Destination-bound update format
  • Local and integration testing

Exercise

Deploy to test environments, integrate a reference consumer, and exercise source outages, signer loss, stale observations, replay attempts, malformed payloads, and anomalous prices.

  • Verified testnet contracts
  • End-to-end signer operation
  • Failure-injection campaigns
  • Tezos X cross-interface prototype

Shadow

Publish under production-like market conditions without authorizing meaningful financial exposure. Compare every price update with independent references and exercise monitoring and incident procedures.

  • Continuous market comparison
  • Availability and latency evidence
  • Alerting and incident drills
  • Operator runbooks

Review

Freeze the candidate, complete independent human security review, remediate accepted findings, re-run regression tests, and re-review material changes.

  • Independent audit
  • Finding disposition and remediation
  • Frozen source and deployment manifest
  • Operational ownership sign-off

Activate

Launch with conservative assets and exposure limits, publish live status and policy history, and expand only as production evidence supports broader use.

  • Verified mainnet deployment
  • Conservative launch parameters
  • Public status and policy history
  • Post-launch review cadence

Production begins when the whole system is ready.

Engineering, validation diversity, operations, security review, consumer safeguards, and public disclosure all contribute to production readiness. The release candidate advances only when the complete system satisfies its gate.

EngineeringVerified implementation

Contract invariants, canonical serialization, signer tooling, relayer behavior, and acceptance tests pass against the frozen candidate.

ValidationIndependent paths

Required attestations span separately operated validation paths and preserve the required implementation and administrative independence.

OperationsOwned and monitored

Keys, funding, source health, alerts, incident roles, rotation, and recovery procedures have been exercised.

SecurityAudit remediated

Accepted findings are resolved and the actual release candidate is re-reviewed after material changes.

ConsumerContainment enabled

Freshness, activation, bounds, caps, conservative valuation, targeted pauses, and safe degraded behavior are live in the reference consumer.

DisclosureEvidence published

Addresses, source commit, signer configuration, policy, known limitations, review status, and release manifests are publicly verifiable.

Follow the build in public.