Safety Score V10 is the sole active stablecoin safety model. It publishes evidence-backed grades from A+ through F; NR is a causal withholding outcome, while Pipeline gap has no score or grade.
Agent navigation: Methodology Identity · V10 Model · Dependency Coverage · Exit Route Evidence · Canonical Publication · API · Consumers · History · Frontend.
Methodology Identity
- Active model: <!-- GENERATED-START: report-cards-active-model -->
v10<!-- GENERATED-END: report-cards-active-model --> - Current methodology version: <!-- GENERATED-START: methodology-version-safety-score -->
v10.01<!-- GENERATED-END: methodology-version-safety-score --> - Public response schema: report v7 with score trace v4; retained older publications require explicit historical version dispatch or refusal, never fabricated cause defaults
- Policy:
shared/data/safety-score-v9/methodology-policy-candidate-v1.json, parsed and digested byshared/lib/safety-score-v9/policy.ts - Evaluation build:
6504f67c3c78de3e2b7514ac40b7a069e7cff48c6da317eff7043b0a32448c74(SAFETY_SCORE_V9_EVALUATION_BUILD_DIGEST), generated from the evaluator and fact-producer source manifest. The manifest's evaluator closure includes the policy's reviewed chain-maturity registry, so score-bearing source edits rotate the identity used by replay and publication comparability. - Implementation:
shared/lib/safety-score-v9/ - Structured changelog:
shared/data/methodology-changelogs/safety-score/ - Public methodology:
/methodology/#safety-scores-methodology - Scoring history:
/methodology/scoring-changelog/
Historical V8 methodology is documented in the scoring changelog. It is not a production API, fallback, selector input, or frontend model.
V10.01 introduces cause-aware scoring after the V10 major release. Internal safety-score-v9 implementation names and API route paths remain unchanged; public body schemas distinguish technical availability from NR. Digest snapshots label their grade distribution from the captured methodology major version, preserving V9 editions rather than relabelling history.
V10 Model
V10 evaluates three pillars:
| Pillar | Aggregation weight | Scope |
|---|---|---|
| Backing | <!-- GENERATED-START: report-cards-backing-pillar-weight -->40%<!-- GENERATED-END: report-cards-backing-pillar-weight --> | Reserve quality, mechanism solvency, custody, assurance, and loss-bearing structure |
| Exit | <!-- GENERATED-START: report-cards-exit-pillar-weight -->35%<!-- GENERATED-END: report-cards-exit-pillar-weight --> | Same-notional executable capacity, cost, settlement, confidence, independent backup credit, and stress horizon |
| Economic Control | <!-- GENERATED-START: report-cards-control-pillar-weight -->25%<!-- GENERATED-END: report-cards-control-pillar-weight --> | Mint, upgrade, oracle, bridge, and other binding control paths |
Weights bound headroom, not an unrestricted average. With included pillars S, renormalize their original weights, let m be their minimum and M their weighted mean, then Q = m + 20 × tanh((M − m)/20). Three included pillars keep 40/35/25; exactly one A/B-only pillar permits a two-pillar rating. Q ≤ M ≤ max(S) holds before independently evidenced additions. Peg behavior, positively evidenced structural/method/parent/history limits and wrapper-local risk still apply; missing-data and generic evidence ceilings do not.
Missing evidence is classified by scoped proof: A pipeline unavailable; B current required public data not curated; C researched non-disclosure; U not yet researched; D measured adverse. A/B factors stay visible with null scored values and zero effective weight, never synthetic favorable facts. Mixed components keep known/C/U/D constraints. partialEvidence flags subcomponent exclusions as well as whole pillars. Two or three A/B-only pillars publish ratingStatus: "pipeline-gap", null score/grade and diagnostic breakdowns, not NR or a one-pillar Safety Score. Exactly one excluded pillar publishes a two-pillar partial rating only if the other gates pass.
C/U quality credits use max(the pre-v10.01 value, the comparable ordinary non-adverse family minimum); charge/discount ladders keep their previous values. Disclosure is monotone only for equal-minimum fields with applicability fixed. Retained cost 50, holder .85, topology −6, synthesized route defaults and wrapper 3/5/10 can exceed a weaker disclosed ordinary fact. Unknown quality never supplies measured-adverse attribution. Exclusion never clears applicability, certification, supply/whole-book joins, output valuation or positive-evidence eligibility gates. Partial control scopes retain known economics and adverse reach; only closure-complete proof may narrow (execution scope).
Backing separates reserve quality from liability coverage. A current admitted collateralizationMeasurement <1 multiplies evaluated Backing by that ratio, including complete-live parent inheritance. Covered reserves retain quality; the uncovered share becomes a zero-scored mechanism:uncovered-liability contribution with measured-adverse unsafe-backing, not a second whole-score cap. Admission requires source, evidence references, stable identity and an evidenced pin date within the mechanism-overlay freshness budget. Expired, undated or unevidenced measurements grant no haircut or credit; ratios ≥1 grant nothing. Serial wrappers mark inherited applications to charge each parent measurement once; distinct local shortfalls remain chargeable.
Exact-contract and legal-layer allocation claims use independently dated, per-dimension evidence and the evaluation's registry. Partial claims cannot satisfy whole-allocation/A3 proof or clear scoped C/U uncertainty. Parent legal context is adverse-only; burn/mint idle-token custody grants no holder safeguards, supervision or cap relief. See mixed allocation scope.
Financial reports and independently dated reserve observations use separate admission lanes, owned by Stablecoin Data and Live Reserves. Assurance needs an admitted current partition and book join; verified exclusions alone may remove overbroad credit. Preserve original whole-asset holding weights plus disjoint cause-bearing remainder, with known + remainder = 100% within precision tolerance. C/U tails score 35, D uses measured quality, A/B has zero effective scoring weight. Scoring may renormalize the included subtotal; exposure, materiality and dependencies never do. No whole-book denominator means no invented full composition. Standing identity/header-bound accounting grants no financial assurance or current-holdings credit.
Bounded reserve facts distinguish contractual maxima, observed tenor, exhaustive eligibility, current availability, applicability and stressed realization without inventing composition or Exit capacity. Exact scope/generation/freshness remains required. C/U asset-class and concentration factors stay 35, liquidity unknown/null becomes 55 and maturity unknown becomes 48; known ladders are unchanged. Missing-factor quality cannot by itself emit unsafe-backing: known facts must independently support the adverse threshold.
Inherited parent Backing replaces only unknown local defaults. The asset's own known reserve class, liquidity and source strength still bound it, with missing factors at their best ordinary rungs. An empty issuer/obligor census scores concentration at bounded-unknown 35, not diversified 98; a missing obligor affects only concentration, never the row's class quality.
Reviewed receipt/bridge graphs expose originating reserve-access authorities and explicit unknown remainder through diagnostic-only accessPosture.freezeLookthrough, with no new freeze penalty. Holder-transfer posture is independent; reserve-access look-through owns exact deployment, denominator and evidence admission.
Expired review is a freshness state, not issuer silence. Resolve A/B only from current captured/scoped proof; researched non-disclosure is C, otherwise U (“Not yet researched”). Research classification lasts 365 days, independently of numerical/report freshness. Keep dated history and active adverse facts; do not date-bump reviews or inherit favorable allocation rights without current whole-allocation proof. Proven Safe-module reach survives partial inventories; internal mint-ledger reconciliation clears only the Control process question. A reviewed Centrifuge route with measured zero supply preserves sibling attribution.
Open live-only routes with proven missing producer capacity remain A diagnostics, not measured no-exit facts or charged missing-route floors. A/B-neutral confidence never admits stale capacity or invalid certificates. Separately admitted current bounded models keep their own limits; C/U-only non-exhaustive Exit uncertainty retains 35 when no admitted route survives. Reviewed channel suspension removes only that rail's capacity/credit, never inventing total-exit failure, onset, lifecycle or wind-down.
Live reserve percentages are weights, not identities. Adapter categories and reviewed sidecars may share a namespace-qualified stable sourceKey: keyed rows join one-to-one, rejecting missing/duplicate reviewed keys across label edits and rebalancing. Historical unkeyed captures join unique normalized names. Neither join compares percentages; Backing classification and dependency compilation share the match set.
Branch-balance observations certify census and valuation separately: incomplete or unpriced censuses cannot become known-only 100% mixes, and uncertified configured rosters cannot claim zero unknown exposure. USD0-denominated lending claims remain unclassified/self-referential until reviewed circular-claim netting and a reconciled independent-backing denominator exist.
Classification research is current for 365 days; composition ages separately. Accepted live rows own their weights/timestamp. Classification-only reviews join unique exact source keys for metadata, not whole-book assurance, new percentages, refreshed clocks or changed dependency/non-link weights. Keep identified holdings with explicit disjoint tails instead of the former 0.1% all-or-nothing admission threshold. Exact full-book denominator, chronology, identities, non-link matching, circular-claim netting and physical-resource guards remain. Unnamed generic curated composition retains 31+7 days; independently named-firm reports use the 120-day rule below.
tether-transparency uses the 7-day disclosure source-age tier, not the 3-day dashboard tier: totals and chain details remain admissible for seven days (cadence rationale). Reserve percentages stay curated in liveReservesConfig.params.slices, independent of feed age. Totals are unscored for fiat-cash; the wider window protects live strong backing-evidence admission, not numeric reserve credit. USDT's June 30 report identifies company-owned LBMA physical gold bars, classed other: D2 reserves commodity-allocated for metal-pegged tokens; USDT retains gold-price risk. Only overnight reverse repo discloses a one-day term. Other horizons remain researched unknowns; average maturities are not maxima, and composition remains dated June 30.
Admission and assurance strength are separate. A named attestor requires a reviewed report identifying the firm, nonempty provider and big4/regional/niche tier; self, none and undisclosed do not qualify. Named attestations, audits and examinations admit through 120 days inclusive (10,368,000 seconds) from conservative UTC as-of/periodEnd, expiring at +1 second. Review must not precede as-of; composition and report period match, publication follows period end, and no date is future. Admission and emitted composition evidence use the same window across fallback lanes, without a 365-day loophole. Named does not mean audited: actual issuer-attested/static-validated/independent strength and scope remain; supervision is not reserve assurance. Fingerprint/config rejection remains absolute. Stale-report reasons preserve publisher dates and resolve cause; they carry no adequate/limited whole-score ceiling.
Curated collateral links enter the dependency overlay only with an admissible reserve-envelope composition and no live reserve slices. Expired, incomplete or otherwise inadmissible reviews assert no basket edges; their reserve-envelope gaps retain scoped cause treatment without invented dependency weights.
Since 9.49, structural dependencies are composition-independent: variant parents and explicit wrappers retain unit serial claims; manual non-collateral relationships survive either source. The 9.48 no-revival rule remains: live compositions without mapped tracked slices retain baseSource: live-unmapped, never curated/manual collateral weights. Surviving variants use source: variant; unmapped provenance and zero mapped weight remain visible. rejectionReasons (sliceIndex, reason) distinguish no-match, expired classification and reviewed non-link. Curated fallback requires no live composition; partial live mappings retain live weights.
Mint Authority Scoring owns posture and scoped questions. Known minority adverse controls remain exposure-proportionally charged. Aggregate review expiry never erases individual adverse facts. C/U generic mint uncertainty scores 50; unbounded-family reconciliation uncertainty scores 55, not a missing-data cap or a direct NR trigger. NAV plus AUM is not supply reconciliation. Seasoned and merged mint-credit headroom share a known-only posture/reconciliation/custody ladder; changing uncertainty cannot change its known thresholds.
Reviewed execution scope binds deployment and authority closure, including latent/re-enabled/counterfactual paths; Safe noninterference removes only the extension-presence penalty, not absence credit. Weighted signing counts minimum cryptographic signatures, including XRPL master/RegularKey bypasses, not independent humans. Stale/unreviewed siblings retain uncertainty/adverse treatment; native bridge-mint/burn rails remain controlled. XRPL amounts use exact decimal-string coefficient/exponent semantics; fixed-unit readers reject native XRPL.
Control inventory resolution and knowledge of control semantics are separate. Access-only controls remain resolved without a privileged identity; individually subthreshold deployment-local unresolved controls may leave the inventory resolved while keeping bounded-unknown status and their gaps (see the aggregate gate below). Every other control needs known authority, cap, impairment, loss-scope, and incident semantics.
The policy semantic digest binds all score-bearing reshapes/freshness gates: insufficient-evidence withhold band, danger/F peg predicates, pre-exit danger, material-bridge high-share band, and named research/access/overlay/reserve expiry windows. Any changed gate in a counterfactual policy clone changes its digest. Presentation derives grade thresholds from active policy, not another table.
Oracle applicability remains distinct from quality: reviewed non-price-sensitive paths emit no component; oracleless mechanisms and known neutral empty-control sets retain 95. Privileged internal mint/redemption/NAV pricing scores 45 without duplicate whole-score penalties. C/U opaque/unknown topology stays 45, without oracle-unverified 55 or invented measured adversity; A/B is excluded. Positively evidenced single-source/manual/unsafe topology retains its existing measured treatment. A wholly unknown A/B-only Control pillar is excluded, never a neutral 95 empty set.
Pre-9.17 oracle reviews use this contract, not the former borrower-liquidation-branch question. Reviewed top-level mint/redemption/NAV/exchange-rate authority remains applicable without fabricated branches; non-price-sensitive mechanisms remain not-applicable, unresolved applicability bounded. Verified adverse oracle facts can emit measured-adverse components and structural ceilings.
Responsibility derives from validated cause proof, not processing stage, enum labels or public prose. A names the exact captured asset/scope/generation and reader/producer rejection; B/C use current dated primary-source research of the required datum, with C's searched surfaces/rationale. Otherwise U. Every contribution retains cause, causeGapIds and scoringDisposition; controlling-cause precedence D,C,U,A,B applies only among controlling gaps, not unrelated diagnostics. Inherited gaps keep originating proof identities and causal-root-qualified paths. Unpublished/unresearched metrics cannot become adverse structural signals merely by being unresolved.
Known external Exit output identity without same-notional valuation does not establish a cause by itself: missing valuation needs its own scoped proof and remains non-scoring. Exact DEX observations retain provenance-bound execution-model output references. Captured peg/NAV values take precedence; route-carried values fill only previously unvalued outputs, with expected value independently established by captured peg/NAV. Non-USD outputs lacking authoritative expected references fail closed; unpriced external redemption assets are never inferred at par. Date-only mechanism/output reviews admit only after their reviewed UTC day, preventing replay leakage.
Partial mint reviews retain admitted controls and scoped causes; unresolved deployments never gain invented shares or closure. Local wrapper controls do not establish parent loss absorption. Missing same-notional evidence resolves its actual cause, not a blanket integration/issuer label. published-evidence-expired records dated publisher history separately from present A/B/C/U cause; expiry alone proves neither issuer silence nor current public availability.
Shared-control pricing uses each receiving asset's own member facts. Admitted adverse reach/domain evidence remains charged; unknown member quality alone cannot manufacture D or a shared-failure signal. Missing/stale/unresolved members carry scoped causes, and no gap establishes high confidence or clears a known adverse path. Common-control census and deployment-scope requirements below remain unchanged.
Common-control census counts independent root liabilities: wrappers/derivatives cannot make their parent meet the multi-liability threshold; same-issuer controllers remain diagnostic, not external common mode. Mint/upgrade/bridge/related signals are deployment-scoped only when every member is reviewed non-root, exact deployment is named and liability partition complete/reconciled; otherwise global/fail-closed. Mento's shared Safe follows the same-issuer rule.
Bridge materiality reconciles exact captured chain rows or reviewed V10 attribution (deployment units, XAUT lock/mint groups, independent liabilities). Native single-route attribution assigns only the published aggregate (share 1) with signed dated native-gas review, no equivalent probeable contract, exactly one current reviewed route, no upstream chain partition and finite positive aggregate. Failure keeps aggregate-only null shares; real partitions win. Supply Pipeline owns registry/clocks/gates; aggregate-only intake follows 9.92 below.
An exact canonical single-chain partition establishes native applicability for a current reviewed zero-route single-chain-or-native profile when tracked contracts identify that chain and no bridge control exists. Same-chain share classes qualify only when every candidate is reviewed native issuance without bridge control. Supply stays one <chain>:native-supply:<asset> cohort; contract shares remain unknown. Bridged, controlled, foreign, mixed or unreviewed candidates retain fail-closed attribution; real control materiality still needs admitted deployment attribution.
The reviewed economic-deployment partition preserves circulating aggregate and source/base/registry generations through exhaustive exact holding censuses, independent quantity/reference clocks and primary-proven escrow/receipt/exclusion/in-flight accounting. Complete eligible provider data wins; missing, contradictory, stale or rejected observations cannot become zero, renormalized supply or favorable transfer/control materiality. Native gas and wrappers keep distinct keys; missing facts follow scoped causes. Reviewed provider-row exclusions remove proven distinct liabilities only from unresolved-deployment and unmatched/unreviewed bridge-share numerators, never the aggregate denominator, observations, reconciliation or other materiality facts.
Unresolved deployment-local controls retain the original admitted exposure denominator and cause-bearing diagnostics. A/B uncertainty is excluded; C/U keeps bounded component quality and existing charge polarity without the former 5–15% control-unverified ceiling. Known/D control constraints retain scoped pricing. Missing, aggregate-only, stale, ambiguous or null-share rows never establish deployment shares, native applicability or favorable materiality; Supply Pipeline owns attribution admission.
Reviewed-deployment observations >120 seconds after clock reject before journalling; journal validation failures quarantine only that asset. Packets age independently; shared chain-supply retains the fixed input's timestamp so one stale packet cannot stale peers.
Single-deployment transfer attribution (9.6)
transferScopeAttestation on a reviewed transfer overlay is a strict version-1 single-deployment-attribution: reviewer, reviewed date, explicit expiry, exact deployment key, primary sources, and exhaustiveLiability: true. With positive admitted aggregate circulating from getCirculatingRaw(), one active resolvable contract, and no bridge/wrapper representation routes, it can complete only access:transfer scope. The resulting fact carries attestation evidence and scopeBasis: attributed; it never invents chain amounts or changes freeze, bridge, concentration, or control scope. Observed chain partitions and accepted exact-input materiality packets retain precedence.
Singleton assets and the share-token liabilities of savings-passthrough, risk-absorption, and strategy-vault variants are eligible. pure-wrapper, bond-maturity, and unspecified variant kinds are excluded. Eligibility is structural, not a named asset allowlist. vusd-virtue is excluded because it has two deployments; xdai-gnosis is excluded because WXDAI is a wrapped representation rather than the exhaustive native-gas liability. The existing xDAI bridge attribution does not authorize this transfer lane.
Attestations expire within the existing 365-day reviewed-research window. The registry guards are re-evaluated every capture, so a second deployment or a bridge/wrapper route invalidates an otherwise current attestation immediately. Missing, future, expired, mismatched, or non-exhaustive attestations cannot complete scope.
Bridge completeness still tests unmatched rows at its existing materiality thresholds, with no fabricated within-chain shares. Material missing attribution carries scoped A/B/C/U causes rather than control-unverified 55; nonmaterial unmatched rows remain diagnostics. Physical exposure denominators and independent known bridge/control facts do not change because scoring uncertainty is excluded.
Unsupported adapter coverage needs captured reader-boundary proof for A exclusion, not an enum label. Per-chain deployment census publishes supported scope plus unsupported remainder without claiming unobserved scope safe. Populated p4a.9 DEX gap accounting uses the public selection budget, not the full recognition set: leftover target-unresolved, incomplete exact capture, quote-budget deferral and reviewed model limits no longer keep incomplete-dex-route-coverage open once budgeted score-eligible routes are observed. Exact-route completeness stays strict. Missing current price is cause-bearing; independently admitted adverse peg history retains its own treatment.
Deployment-supply joins age each census row from observed_at via resolveDexDeploymentCensusMaxAgeSec() over active contracts and tradedContracts, matching DEX classification: 48-hour floor for single-window footprints, sweep-aware bound for rotating ones. This does not extend four-hour DEX quote/scoring validity; publication timestamps refresh neither clock.
Exit scores selected-route executable capacity, not exchange volume, DEX TVL or reserves. Below both 1% completion and $100K capacity, route score is zero; ≥$100K with <1% completion caps at 50. Since 9.5, binary materiality uses measured executable notional before output retention; retention still discounts continuous capacity/output quality without duplicating depeg at the threshold. Fully observed zero/immaterial issuer/protocol routes remain included primary evidence with measured capacity, completion, confidence and cap, not unsupported. Zero Exit emits no-viable-exit-path.
Local V10 order-book and off-ramp certificates require exact canonical-supply stress requests, reviewed identity, current source/output/gate clocks, settlement proof and integer-unit execution. Missing proof is unavailable, not zero or legacy fallback. Kraken proves an observed prefix; Securitize needs authorized-holder simulation, gas valuation and complete output identity. Public traces strip private prerequisites/evidence IDs. Reviewed identities remain empty; scored routes, issuer charges, supply and pool census are unchanged. The redemption owner links the all-48 authoring checklist and live diagnostic failures.
A dependent's exposure to an upstream with an open reserve gap counts once per upstream cause. projectResolvedUpstreamReserveExposure folds slice-level reasons into one reason per projected code, source code and owner on each dependent exposure; slice paths survive in the causal key. The live-reserves scoring gate (live-reserves.md) prevents a single failed fetch from demoting a fresh snapshot.
evaluateV9SubthresholdUnresolvedBridgeJoins excludes reviewed-native selected supply rows from bridgeControlsByDeployment: the native-liability boundary in worker/src/lib/safety-score-v9/extension-bridge.ts keeps native controls as umbrella facts, not bridgeClaimControls. This mapping correction does not change floors, completeness or unknownBridgeShare.
worker/src/lib/redemption-exit-route-observations.ts resolves offchain-issuer commodity routes with outputAssetType: bluechip-collateral (physical GOLD/SILVER delivery) as unresolved-asset, not fiat. buildOutputReview cannot imply a synthetic $1 value for a physical bar; physical-to-USD composition requires its separate reviewed valuation path.
External validation quorums (LayerZero DVNs, CCIP DON/RMN, Bantu AMTP or equivalent) are named validator-quorum authorities, not unknown single controllers. Bounded-unknown quality is below concentrated-admin/multisig; weakest-authority merging places them below issuer-backend, above eoa, so unattested single keys still bind. Authored bridge/custodian map to contract/issuer-backend.
Reviewed unavailable mechanism factors expose the checked source/date and precise missing datum. Current researched non-disclosure is C; a not-yet-reviewed question is U (“Not yet researched”), never automatically issuer-undisclosed. Unproven queue settlement is not measured zero: no missing-data Exit ceiling remains, C/U retains the admitted bounded 35 where applicable, and A/B never creates a charged floor. Known queue/offchain/documentary method boundaries stay priced.
Faster settlement credit requires exact delay, review date and source; conservative cost/settlement corrections may lower Exit without asserting a favorable promise. Unestablished same-notional capacity, settlement or cost emits bounded-terms-gap: partial facts stay visible but generated fallbacks earn no primary/diversification credit. Measured-zero DEX cannot turn separate uncertainty into danger; Exit stays bounded where other evidence permits rating.
Tracked outputs use expected USD unit value: reviewed NAV first, 1 for USD pegs, captured reference for others. Without a reference, pinned output is unpriced/non-scoring. DEX/redemption share physical resource identity: each pool/venue/protocol/issuer backs at most one scoring route; reuse is diagnostic. Cost overrides merge with the base model before validating fee ordering and stress-cost monotonicity.
Basket valuation requires complete reviewed outputs, weights summing to one (including zero members), pinned USD and expected peg/NAV values, source identity and time. dEURO's nine verified StablecoinBridge outputs publish same-run EUR/USD as expected value only: absent member prices withhold whole valuation as outputValuationUnavailableReason: "output-tokens-unpriced", never par.
Historical supply refinements retain fail-closed materiality: 9.94 reconciles XAUT circulating totalSupply() - treasury against totalAuthorized - notIssued; 9.93 bounds each candidate by an unsplit ambiguous row only below both materiality thresholds with all candidate routes reviewed. Mismatched, material or partially unreviewed rows remain unresolved.
Under 9.92, supply-review.unpartitioned-aggregate keeps circulating USD known for Exit sizing. Failed chain joins, missing profiles, stale input and missing/rejected attribution still fail closed; Control alone owns runtime-bridge-materiality-unavailable. Method-withheld route ownership follows the causal-gap rule above.
Named-firm composition admission uses the 120-day as-of window above, not the former 38-day fallback cutoff. Stale traces retain dated evidence. Printed signed/as-of date can stand in for absent publication (publishedAtBasis: "signed-date-standin", displayed “signed”), never refreshing period or bypassing chronology/lockstep. Financial assurance keeps its independently scoped age and strength gates; newer unreviewed reports still block independent-assurance discovery (metadata).
Chain-maturity admission resolves at the capture clock with quarterly expiry; replay retains that clock and admitted set. The gates and registry ownership are specified below; rollout history lives in the structured changelog.
Physical physical-commodity-delivery remains diagnostic: captured unscaled USD/troy ounce × deliverable ounces, net of published fees, output tier 65 (55 for unbounded delivery), and sameNotionalEligible: false. Reviewed redemption may compose with a modelled metal sale ending in USD without treating delivery as cash or changing its standalone score. Physical-to-USD retains the 500-bps admission gate but scores cost against the common request denominator, with neutral verified-customer eligibility and explicitly modelled coverage. Capacity is capped by documented throughput over the complete settlement window, otherwise one conservative minimum lot; best-effort cash-outs retain the applicable policy sale spread. See physical-to-USD policy.
Policy sensitivity includes isolated semantic.exit.outputAssetScores.physical-commodity-delivery and semantic.exit.unboundedDeliveryCap parameters with default perturbations of −1 and +1. Policy validation enforces unbounded delivery < bounded physical delivery ≤ stable-single (fiat-par); these tiers do not change coupled weights or reference notionals.
Exit takes the maximum unrounded score over every feasible singleton and independent pair. The higher route is primary; bonus = min(10,100 − primary) × backup/100, with unchanged fee eligibility, same-notional, correlation and physical-resource guards. Ties use combined score, primary, backup, then ascending code-unit route keys; quantize once. Select before applying the admitted bounded-gap floor once: only a strictly binding floor clears selected keys/bonus. Improving a route cannot lose an already feasible better pair. Above 64 eligible candidates, a proved reader-limit A gap replaces silent truncation.
Observation, model and intrinsic capacity-method confidence are separate cause-bearing dimensions; their minimum applicable factor is used. Positive method identity maps to its tier: same-run verified live queue/proxy .75, live-direct 1; documented/heuristic identity alone is not missing measurement. C/U unknown observation uses .6 and unknown method .75; A/B missing dimensions are neutral. Known weaker model/backlog/gate limits still bind. C/U holder uncertainty retains .85 and cost 50, while A/B excludes only the unknown factor; a public formula is not a measured zero fee. Confidence relief never certifies expired/unavailable capacity. Positive admitted lower bounds are usable route evidence, not exhaustive zero; route reasons do not depend on floor activation. A proven-empty, reconciled route surface is native D with Exit 0 and no-viable-exit-path, not a synthetic U gap.
V10 uses JavaScript code-unit order, not locale collation, for route ties, dependency paths/diagnostics, reviewed transfers, supply attribution and bounded publication reasons. Scores/grades are unchanged; route/path identities, trace ordering and digests can rotate for previously locale-collated non-ASCII/case-sensitive keys.
Serial parent claims bind because children cannot diversify them away; baskets use live exposure weights. Wrapper-local risk is separate. Parent-cap form follows relationship, not label: reviewed third-party risk-absorption uses strategy-vault treatment; parent-operated wrappers use native-staked treatment.
Wrapper allocation reviews are fixed-block and expiry-bounded. Current fully on-chain proof resolves U custody/reuse uncertainty; leverage and loss absorption stay separate. Eligible C/U local gaps retain max(known assessment, form fallback 3/5/10), not summed per-risk maxima or newly expanded fallback triggers; eligibility follows cause, not a legacy disposition label. A/B gaps trigger no fallback and no favorable risk-transfer credit. Parent custody relief and favorable inheritance still require current whole-allocation proof; known local private-credit/loss controls stay charged. yBOLD/sBOLD renewals retain liquidation-loss absorption and unknown measured unwind, bound to their actual observation clocks.
Wrapper-local leverage signals shared by distinct reserve slices are emitted once per finding. The closed reserve-risk vocabulary recognizes the leverage keyword and maps it to the existing high assessment; leverage bands from reviewed allocation facts remain unchanged.
documented-risk-transfer/wrapperParentLimit.riskTransfer grant no credit: the production builder emits disposition: "not-applicable", mechanism: "none" and zero parent loss-absorption; extensions admit no first-loss evidence. Activation needs a new evidence lane, intake, review window and methodology bump.
Reviewed control/wrapper/operational/peg incidents enter their owning components, not a generic fourth pillar. Root-claim, deployment, integration-only and holder-exit scopes bound affected liability. Active/mitigated/resolved states require dated remediation evidence; repeated evidence cannot double-charge a domain fact.
Cap limits and scope gates
The signalLimits table is not a set of missing-data ceilings. Only admitted measured-adverse D or positively established method E predicates can activate surviving limits; unknown-driven quality cannot fabricate that support. Scope and pillar pricing select the role:
| Signal context | Role of the limit |
|---|---|
global-claim and legacy-scope signals | Whole-score hard cap only with an admitted surviving D/E predicate; undefined responsibility is not measured-adverse proof |
| Deployment-scoped signals | Proportional exposure floor, published as exposedScore, rather than a whole-score cap; the per-card values are live publication output from GET /api/report-cards/v9 |
| Pillar-priced signals without an asserted residual | Inert as a whole-score cap; a signal already priced inside a pillar cannot impose a second ceiling without an asserted additionalHardCapRisk residual |
Limits are integral in published score space. Scope gating retains proportional deployment adjustment without double-charging pillar facts; pillar-priced hard caps require explicit residual risk.
Equal caps prefer specific observed/withheld facts over generic absence, then source priority and code-unit kind/reason order, keeping selected reason and full trace total/byte-stable.
Evidence-derived NR witnesses are C/U/D only, with U counted as C. A pillar counts only when its pre-v10.01 evidence predicate still limits it after A/B relief and it has a real compiled witness; newly tagged bounded components alone do not make it limited. Lever-1 retains score <55, at least two genuinely limiting pillars including Backing, and its measured-danger exception; A/B and reviewed not-applicable pillars never count. A single C/U gap cannot directly cause NR. Separately, computed F without attributable D is withheld as f-without-measured-adverse: “Score below the F threshold without a measured adverse fact”. No uplift or invented D is allowed. NR and pipeline-gap publish no binding cap or published-cap attribution; genuine pillar-priced signals remain diagnostic.
Known root-reaching adverse controls retain supported global caps; proved deployment-local controls with complete reconciled shares use proportional adjustment. Missing controls retain cause-aware component treatment, never a missing-data global cap. If still binding Economic Control, causal attribution remains even with zero adjustment.
Chain maturity requires five dated gates, not inferred age: 36 months continuous production; 365-day liveness; permissionless participation or ≥21 independent producers/finality members, no unilateral halt/finalization and documented economic security; no unilateral instant change (L2 Stage ≥1 and ≥7-day holder exit); documented bridge/data-availability dependencies with holder exit. Citations record document date, assertion, independent access time, reviewer outcome and reachability. Default access date is VERIFICATION_ACCESSED_AT, also policy default clock; per-URL REVERIFIED_SOURCE_ACCESSED_AT does not move either. Unreachable/non-supporting citations stay pending. Captured clock enforces cadence and numeric nextReviewAt. CHAIN_MATURITY_REVIEWS_V1 in shared/data/safety-score-v9/chain-maturity-reviews-v1.ts owns admitted set/rationales, projected as matureChains; do not duplicate its roster.
Report-v7 distinguishes rated (numeric score/letter grade), not-rated (null score/NR with causal reasons), and pipeline-gap (null score/null grade, diagnostic breakdowns and partial metadata). Partial rated cards may have null excluded pillars. Aggregation includes effective weights and included/excluded sets only with at least two scoreable pillars; pipeline-gap has null aggregation/stages/weakest pillar. Technical gaps never enter ranked/safe cohorts, grade-history rows or downgrade alerts.
Asset premiums and dependency inheritance
The policy-declared market-anchor-longevity premium applies only to usdt-tether when its eligibility gates are met: market rank 1, at least 120 months of history, base score at least 75, exit score at least 70, strong evidence, a clean peg, and the stress-redemption plus reserve-reconciliation operational components. It adds 12 points, raises the signal:centralized-mint:low cap from 83 to 87, and limits the public score to 87, the A+ threshold.
Premium gates re-evaluate each capture; new chain admission can restore eligibility without policy change. Neither 9.9 replay nor 2026-09-23 TRON re-review met every gate. Structured changelog owns capture scores/history; CHAIN_MATURITY_REVIEWS_V1 owns current admission/rationale.
Premiums are not inherited: applyV9AssetPremium leaves inheritableScore unchanged; projectV9DependencyScore returns it. USDT may publicly score 87 while steakusdt-steakhouse/susdt-spark inherit 83. That 83 snapshot is not stale and must not sync to the premium-adjusted parent.
Dependency Coverage
Reviewed catalog wrapperLocalFacts.parentBackingInheritance withholding blocks favorable parent Backing even without a reserve envelope, until a separate review establishes the economic claim. susd1plus-lorenzo uses dated primary-source-backed withholding because its mixed RWA/CeFi/DeFi book does not establish a measured whole-portfolio USD1 claim. Parent cap, price, supply, peg and lifecycle relationships remain; other wrappers retain single-parent evidence gates.
Direct-wrapper onchain custody relief requires a current fully-onchain allocation review or complete custody checks with zero unknown exposure; an authored custodyModel: "onchain" alone is insufficient. Parent custody and reuse remain in the dependency instead of being duplicated locally. Missing or expired proof, omitted models and CEX, institutional, mixed or unknown custody retain conservative local treatment. Relief grants no legal segregation, bankruptcy remoteness or parent Backing inheritance.
ctUSD is a pure fixed-unit M wrapper from independently verified deployed implementation; parent, bridge, permissioned swap-out, intervention and upgrade risks remain. The 2026-10-02 USDK/XO review retains defaults: funded indexed M vaults and NoYield state do not establish exact deployed-source equivalence or pure-wrapper credit. Owner ruling 12 preserves aggregate sdUSD parent treatment and legacy USDv's August scope rather than inferring current closure.
Wrapper-local evidence
Measured unwind requires known, score-eligible, exact-complete, non-documented evidence with bounded fees and settlement. Modelled alternatives retain their scoped evidence treatment; whole-wrapper exhaustion requires a complete comparable route inventory. Emergency-control assessment excludes explicitly inherited parent controls (controllerAssetId or the inherited parent mint-control failure domain), already priced through the parent limit; genuinely local controls stay charged. A/B local gaps never trigger form fallback; eligible C/U gaps retain max(known local assessment, form 3/5/10) and existing exemptions. Missing proof grants no risk-transfer credit.
A current scoped published fee formula not evaluated by Pharos is B only with dated availability proof: exclude its unknown cost factor without assuming zero fee. C/U cost keeps 50, not fee-ceiling 52. Actual cost, access, execution, holder and settlement admission remains strict; a known above-budget fee is measured.
Whole-book custody coverage
Registry editing rules own whole-book custody labels and independently dated adapter composition. Labels grant no numeric V10 credit; Backing uses scoped custody and reserve facts. Security-history authoring owns informational remediated vulnerabilities, separate from scored incidents.
Keyed zero-percent categories retain their captured provenance and consume matching reviewed classifications, but emit neither dependency edges nor positive-weight backing exposure facts. A zero balance cannot quarantine the asset solely by violating the compiled exposure-weight bound.
Reserve-derived basket exposure can coexist with an independently reviewed non-default role to the same upstream. A subset role review must explicitly name a non-default role and match an exact authored identity, type, and weight anchor in the sourced derivation. Reserve weights remain basket exposures; the role uses its own authored anchor. An unanchored subset remains a dependency-review mismatch. Relationships merge by identity, type, and role, so a reviewed default replaces rather than duplicates the same edge.
Authored and runtime reserve schemas deliberately differ. AuthoredReserveSliceSchema and FullAuthoredReserveCompositionSchema require depType whenever a slice carries coinId; registry and reserve-sidecar validation use that strict boundary. ReserveSliceSchema and the runtime composition schema remain permissive so legacy persisted live snapshots remain readable rather than failing the whole response. Derivation never defaults an untyped link to collateral. A legacy live row inherits only one uniquely authored kind for the same coin id from reserve rows or adapter identity declarations; unresolved or conflicting kinds withhold that row's link with coinId-without-depType and increment coinIdWithoutDepTypeCount. The coverage gate treats that counter as zero-tolerance. Other rows and structural relationships survive, and wholly unmapped live reserves do not revive curated collateral weights. Until adapters resync, cached legacy rows without unique reviewed-kind inheritance can transiently lose links.
Methodology 9.98 makes linked reserve kinds explicit without refreshing historical reserve evidence. Mento separates native USDC/EURC/USDT from axlUSDC/axlEUROC/USDT0, aggregates reviewed canonical-parent shares, and retains partial intermediary contributions in slices and producer metadata instead of a false whole-edge tag. USDat retains PYUSD with immediate PYUSDx annotated; Frankencoin retains yBOLD with ysyBOLD annotated. Representation identity verification is not independent bridge solvency assurance. Avant exposes measured gross-positive-long holdings, retains debt and NAV separately, and withholds tracked links pending exact position-to-contract, receipt, or bridge joins. Source-label matching, fabricated netting, and NAV-normalized dependency shares are not permitted. Cached legacy-row withholding can change backing and downstream scores until typed producer rows arrive; the reviewed removal of ReUSD's old pooled USDe link is not a missing-type regression. Fixture replacements are diagnostic inputs, not production freshness evidence or score forecasts.
Methodology 9.97 retains scoring weights, materiality thresholds, and evidence admission rules while correcting reserve attribution and precision. Accountable reconciles reviewed nested leaves; OnRe identifies Solomon's replacement USDv mint; Reservoir identifies the high-risk Sentora PRIME PYUSD claim; Re keeps protocol-pooled holdings unlinked without an attributable off-chain denominator and tranche waterfall. Frax, Nest, and InfiniFi preserve positive measured dust, and ftUSD validates present exact collateral identities without a fixed row count. Producer recovery does not establish scoring admission: weak probes, unverified freshness, and reconciliation failures retain their existing gates. Agora's Fern discovery repair preserves the exact reviewed July report and integrity checks.
Report schema v7
Report v7 is a semantic cutover: cause-bearing exclusions, partial weights and pipeline-gap/null-grade are distinct from NR. ratingStatus, full partialEvidence, separate confidenceDimensions and completeness.pipelineGapCount/pipelineGapIds reconcile to the cards. Existing supply/shared-book fields retain their meanings.
Publications carry card.supply with circulatingUsdAtEvaluation, asOfSec, and generationId. The amount is the evaluated compiled supply fact, not a current market-cap lookup. Unknown supply remains null, including its unavailable clock and identity. Observed zero remains zero. The supply clock is the fingerprint whose generation matches that fact; it is distinct from the publication clock.
Cards carry nullable sharedBookId. The stable scope mapping assigns sky-maker only to captured balanceSheetScope: "shared-sky-maker" members named in sharedBookAssetIds; unknown scopes publish null. The adapter's measured holdings remain in the captured reserve provenance. Consumers must not add shared-book liabilities as independent holdings.
Serial and basket summaries, and their exact graph projection, carry optional dependencyType from the compiled relationship using the existing wrapper, mechanism, and collateral vocabulary. The field is absent in v5; edge identity remains (from, to, kind). Nullable wrapperForm comes from scoreTrace.wrapperParentLimit.form only on wrapper claims. Mechanism and basket claims publish null; a wrapper without a parent-limit form also publishes null, so consumers distinguish claim types with dependencyType, not form presence.
provenance uses the existing dependency-source vocabulary (live-reserve, live-unmapped, curated-reserve, manual, none, variant), the dependency evidence observation date as evidenceAsOf, and a nullable reserve-slice intermediary. An intermediary retains kind, label, optional chain/contract/source URL, and verification status. Structural and manual serial claims also retain matching slice annotations. Identical annotations across all contributing slices publish that annotation. Any unverified annotation takes precedence, using the first unverified slice. Otherwise mixed native/bridged or differing verified routes publish null; Plume's aggregate claim does not inherit its partial USDC.e route annotation.
dependencyCoverage is an optional disclosure list, separate from scoring admission and graph edges. Rows carry upstreamLabel, nullable upstreamAssetId, nullable fractional share, an existing producer rejection or admission reason, nullable sourceAsOf, and identityVerified. Unverified identity never publishes a tracked upstream ID. Reasons retain producer codes such as no-match, expired, non-link, coinId-without-depType, native reviewed identity/type conflicts, manual-collateral-not-in-reserves, outside-active-set:<id>, and compiled reserve-envelope gaps. These relationships never contribute to graph totals. An absent list means this generation did not publish coverage, not that no relationships were withheld.
Coverage deduplication uses source-key identity and reason, or upstream identity, label, and reason for unkeyed rows. Distinct withheld slices or reasons sharing a display label remain visible.
Top-level commonModeGroups optionally projects the evaluated V10 dependency plan as compact { id, kind, key, memberAssetIds, pricedEffects? } rows. The canonical ID is kind:key, using the existing failure-domain vocabulary. Groups and member IDs are unique and sorted. Only groups with at least two distinct assets publish; several paths on one asset do not qualify. All qualifying groups remain visible, even without a referenced priced effect.
Optional pricedEffects contains sorted unique receiving assetId rows with zero-based capIndices into that card's caps and deploymentAdjustmentIndices into scoreTrace.deploymentRisk.adjustments. Each row has at least one nonempty reference list; the field is omitted when none exist. Consumers resolve the existing prices through those references. Membership is not an additive loss estimate, a counterfactual score change, or a new penalty, and an omitted effect list does not prove no risk. Report v5 omits commonModeGroups; absence means not published, while [] means a published census with no qualifying multi-asset groups. The coin-to-coin graph is unchanged.
A group carries pricedEffectsIncomplete: true when a member has an evaluated structural signal for that failure domain that the evaluator prices through a hard cap (structuralSignalNeedsHardCap), but no matching cap or deployment-adjustment reference can be joined. Evaluator cap deduplication keeps one domain's reason when several domains produce the same source, kind and limit, so the other domains cannot be referenced; on the 2026-09-29 capture this affects 6 of 519 groups. The flag is presentation-only: it never withholds the publication or changes a score, and each affected group also emits a safety_score_v9_common_mode_priced_effects_incomplete warning naming the group and member assets.
The standalone Dependency Map and its Shared failure domains board consume GET /api/dependency-graph/v1, not full evaluator internals. Its optional common-mode effects preserve published capIndices and deploymentAdjustmentIndices, adding resolvedCaps (kind, limit, binding) and resolvedAdjustments (scoreBefore, scoreAfter, adjustmentPoints). Missing references omit only unresolved entries and set referencesUnresolved: true; they never invent prices or erase resolved entries. The board ranks known member supply with publication-bound supply preferred and explicitly labelled market-cap fallback, discloses partial subtotals, and keeps unresolved references separate from pricedEffectsIncomplete. Group totals overlap and must not be added.
The separate offline GET /api/dependency-scenarios/v1 artifact is not canonical. It reuses the production evaluator for generation-bound modeled shocks, but never changes canonical cards, journals, publication identity, graph membership, or score policy. Its modeled changes are not forecasts and are displayed only under the scenario freshness contract.
Current producers emit report 7. Retained old schemas use explicit historical dispatch or are refused; no active compatibility alias supplies fake causes. Current dependency graph/scenario body schemas are 2 while their /v1 route paths stay unchanged. Graph validation requires unique edges sorted by (from, to, kind) and exactly the serial/basket card projection; coverage cannot introduce external graph nodes.
Exit Route Evidence
A current established circulating USD amount sizes Exit's same-notional request when supply is bounded-unknown solely under v9.supply.bridge-materiality, including missing bridge profiles, ambiguous joins, and missing or rejected attribution packets. Unknown, stale, unsupported or unavailable amounts cannot size it. Sizing never resolves bridge/control/transfer/distribution evidence; those gaps follow scoped causes. Stress fraction, grid, cost bound and horizon stay unchanged, and sizing grants no route credit or substitute for executable capacity and terms.
Exit exhaustion (no-viable-exit-path, measured-adverse low capacity) requires a known or stale, score-eligible, output-resolved exact-complete measurement. Documented terms, modelled/estimated capacity and exact-lower-bound prefixes cannot prove exhaustion; lower bounds retain positive credit. Without an exhaustion measurement, missing same-notional evidence follows scoped causes: A/B is excluded, C/U retains 35 only where the bounded floor applies. Complete inventory alone proves nothing; an unmeasured alternative blocks whole-token exhaustion attribution. Exact-complete low measurements retain adverse attribution when they establish the aggregate claim, even after aging: staleness is not clearance. Execution-certificate coverage comes from the admitted request point. Only genuinely limiting C/U/D witnesses enter the collective evidence-withhold gate.
A proven-empty route surface stays measured-adverse (no-viable-exit-path, Exit 0) only when captured verified-no-pools coverage reconciles to every supply-bearing chain in the captured distribution. Unknown, unsupported, provider-inaccessible, missing or partial coverage is bounded uncertainty, never global exhaustion.
Reviewed above-budget costs retain their exact public trace but yield zero executable capacity within that budget, not a producer quarantine. NUSD's separate programme pays 0.51 USDC per token (4,900 bps), with wallet acknowledgement, issuer-discretionary eligibility and a raw-capacity bounded-terms gap; its holder-exit incident remains. yUSD's issuer route is unknown from the October 2 frontend pause observation, without an inferred onset, loss or suspension record; vyUSD is untracked.
Owner ruling 12 retains BRLV's reviewed 14-day modelled horizon despite disclosed T+3-business-day terms. Unavailable recovery, CGO's physical-exit reader boundary and other integration gaps need scoped cause proof: A/B is excluded, C/U remains bounded where applicable, never measured holder loss.
Reviewed physicalToUsd routes use the same supply-sized request grid, weights, delay/backlog/minimum multipliers and independent-resource rules. Only these composed physical routes have a 500-bps all-in ceiling; all other routes keep 200 bps. London/Zurich modelled gold sale spreads are 100/200/400 bps for Good Delivery/kilobar/small-bar-or-coin; silver uses 100/300/800 bps. Other vaults add 100 bps. Fees, logistics, tax and spread reduce net USD once through execution cost, while USD output retention stays one and output quality/offchain ceiling stay 65. Variable Good Delivery gold bars conservatively consume a 430-token deposit per lot plus fee and count 350 fine ounces, refunding excess without a loss charge (LBMA specification). Metal-price movement has no separate charge.
Public physical traces name USD endpoint, verified-customer scope, branch, lots, gross/net USD, all-in cost, maximum time, review/reference budgets, assumptions and rejection reason. Terms expire at the earlier explicit review expiry or 90 days; captured metal references retain their 24-hour budget. Explicit fees and issuer settlement maxima win. Unpublished issuer fees use 100 bps plus USD100 fixed, conversion50 bps; in-vault spread covers unpublished delivery/insurance/assay. Same-jurisdiction delivered logistics use conservative class estimates, while unpriced cross-border logistics remain unavailable. In-vault tax is zero for both metals; release/import allowances use the policy jurisdiction table (Hong Kong0, qualified Singapore IPM0, Swiss silver810 bps, UK/EU silver2000 bps, documented investment-gold exemptions). Missing lot quantities or all stated issuer timing remain unavailable; explicit unbounded inputs never receive credit. Stated issuer typical times use clamp(3 × typical, 10, 30) business days per leg (several-business-days maps once to7), and the evaluator automatically appends a modelled dealer-sale maximum10 business days from LBMA spot T+2. Sequential calendar delays include intervening weekends. Fee/issuer-time assumptions are named and lower model confidence; documented best-effort cash-out independently requires its own lots, costs and final-USD timing. Policy tables and cited market rationale live in redemption backstops.
Physical traces publish netUsd only for positive calculated proceeds; non-positive proceeds publish null with physical-net-usd-nonpositive, and below-minimum requests publish null with physical-request-below-minimum. costBps retains the full loss from signed proceeds, never a zero-clamped statistic. Both rejected cases earn no score credit.
Methodology 9.96 makes two score-semantic changes. Issuer routes honor reviewed explicit stablecoin payouts ahead of the legacy fiat projection: pathUSD, USYC Teller, pUSD and USDO pay USDC; thBILL, MXNB's conversion rail and StandX DUSD pay USDC/USDT; HLUSD's existing basket is honored. Unreviewed issuers keep the legacy default without variant-parent inference, and USDN is unchanged because current sources do not confirm USDC. Tracked outputs require captured price evidence: a single payout at par keeps quality 100, while multi-output routes keep conservative stable-basket quality 80 and weakest-priced-component semantics, a 3-point raw route difference at par; missing prices remain unresolved. Uniswap V4 retained exact PoolIds are fetched without the subgraph TVL floor and bypass the indexed-TVL 2% affinity guard, which remains only for token/fee fallback. Positive retained TVL, PoolKey/currency identity, zero hooks, active liquidity and existing quote/capacity gates still apply. Trigger: thUSD/USDC's indexed TVL was -$222,031.94; seven pool assets are affected (thUSD, USDD, USDT, USDS, USP, AUDM and sUSDD). Measured is not deep: at Ethereum block 26088713, a $1,000 thUSD sell returned $966.94. As curation context, not a third semantic change, thUSD moves to an executed stablecoin-redeem rail consistent with USDe, with measured Cash Wallet capacity from theo-thusd-redemption and no fallback. On the frozen replay of generation report-cards:9.94:1790752511 at clock 1790752628, only thusd-theo moves, 38/F to 43/D from its configuration, with no quarantines; the capture still has its old issuer-api observation and lacks its live-reserve fallback observation. Output and V4 effects require the first production redemption and DEX cycles and are not shown by that replay. The reviewed payout assets and seven V4 pool assets are expected movement candidates, not guaranteed score or grade improvements; standalone Liquidity Score arithmetic is unchanged.
Canonical Publication
Bridge-materiality diagnosis requires accepted publication identity and matching retained base/enrichment (replay contract). Prepare-time report-cards:fixed-input:exact omits compute-time attribution/transfer materiality; base-only replay can falsely report unavailable facts. Complete route metadata, a sole representation or parent chain distribution cannot prove liability shares. Same-chain multi-contract rows need admitted deployment attribution except the reviewed native-cohort applicability lane: every candidate must be native issuance without bridge control. That lane preserves one chain aggregate with unknown contract shares; it grants no deployment/control/transfer materiality. Rejected raw-unit observations never become zero supply.
Publication follows rule R8 (ADR-35 in architecture.md): one unusable asset is quarantined by id and field path, not allowed to hold the cohort. compileSafetyScoreV9FactSetWithIsolationFromValidatedExtension is the reference implementation of that rule for the whole repository.
The publication pipeline has two active stages:
prepare-safety-score-v9-inputruns immediately after each successful half-hourly DEX publication. It captures the publication-exact base input and peg-provenance seed and binds them to that exact DEX generation.compute-safety-score-v9runs at minutes 22 and 52. It rejects an input whose DEX dependency no longer matches the latest accepted generation, compiles the V9 fact set, evaluates the policy, and publishes the accepted result.
Runtime-neutral control and settlement schema fragments are owned by shared/types/safety-score-v9-facts.ts and reused by the Worker fact-set extension schema; Worker-specific envelope validation stays local. worker/src/lib/safety-score-v9/supply-attribution.ts owns the exact asset-to-journal-source bindings consumed by both producer descriptors and generation validation.
The approved Workflow pilot does not add a third authoritative stage. With WORKER_V9_WORKFLOW_MODE=off publication behavior is unchanged; shadow is the checked-in value while the pilot runs (worker/wrangler.toml), and off is the kill switch. In shadow, each completed cron publication triggers one deterministic Workflow instance for the same slot. When the compiler returns a terminal result with no publication to shadow — a neutral admission skip, a fail-closed input, or a deferred cadence — the trigger instead records a neutral cron_runs row naming the upstream status, stage, and reason (upstream-compute-publication-absent), so the job's status reports the real cause rather than a bare missing run; a skip whose reason shows another invocation still owns the V9 lane stays silent, because that invocation writes the slot's real terminal row. The Workflow reuses the canonical compiler and gate, suppresses their live-cache writes, and stores the exact captured publication envelope and hold/current sidecars only at safety-score-v9:shadow:<generation>. Its separate terminal cron_runs job is compute-safety-score-v9-workflow. A seven-day byte-parity, replay, resource, observability, and cost review is required before a separate cutover decision; the live keys below remain cron-owned throughout the pilot.
Since methodology 9.07 the private upstream input is a native V9 capture. Schema v4 carries exactly the fields the V9 compiler reads and drops everything the retired V8 report-card projection needed: bluechip ratings, resolved blacklist statuses, collateral-drift diagnostics, the non-current chain-circulating buckets, and every DEX row field outside the exit-route observations. Its capture identity is model: "v9-input", bound to the V9 evaluation build; the retired V8 evaluation-build identity is gone with the engine. Base-input generation ids keep the report-cards-input:v1: prefix, which is a published format namespace pinned by the public fact-set schemas, the OpenAPI spec, the publication codec, and the safety_score_history_v2 CHECK constraint — not a projection version. Which projection minted an id is carried by the input identity.
The prepare cron owns:
report-cards:fixed-input:exact(cache envelope v2, carrying the v4 capture)report-cards:v9-peg-provenance-seed:exact- publishing the peg-analytics aggregate cache, now an explicit producer step rather than a side effect of building V8 cards. Content and cadence are unchanged: one publish per capture, at the half-hourly chart slot.
When replay-delta serialization succeeds, the compute cron atomically retains the accepted publication's private replay base (report-cards:v9:accepted-replay-base:v1, reusing the compressed prepare envelope) and enrichment delta (report-cards:v9:accepted-replay:v1). Only one generation is retained; held attempts leave both rows unchanged. Serialization failures log safety_score_v9_replay_capture_retention_failed and publish canonical cards without advancing either row; capture identity violations remain fatal. The delta contains supply attribution, both bounded journals, peg provenance, and transfer materiality already consumed by compilation. Offline scenario plan must use a matching accepted pair, not the mutable latest prepare cache, and fails closed if retained rows belong to an earlier publication.
V9-only enrichment is loaded directly by the canonical compiler. Supply attribution runs on its dedicated fenced schedule and is admitted only when its identity matches the fixed scoring generation. The producer due interval is shorter than the compiler's freshness window so the existing 15-minute trigger grid lands healthy captures roughly every 30 minutes. Compilation normally follows an ok core slot from the current Worker, but that slot's durable stablecoins publication evidence is sufficient when the parent slot row is degraded, otherwise not terminal, or was finished by a Worker version a deploy has since replaced — the ledger row must still be that slot's sync-stablecoins publication of the live stablecoins cache generation, whichever Worker version wrote it, so a stale or no-write run cannot pass. The compiler still rejects a fixed input whose stablecoin timestamp no longer matches the live cache. Stale, future, registry, and inventory mismatches are reported with clause-specific reason codes…
The activation calibration gate also preserves supply absence: if any unattributed F card lacks observed circulating supply, its supply-weighted D3b share is unavailable and the gate fails closed rather than treating the missing supply as zero. D3b thresholds and weights are unchanged.
A missing input-bound attribution generation is diagnosed separately from an RPC rejection: supply-review.generation-outcome-missing means the scoring input had no compatible outcome, supply-review.attribution-rpc-rejection is reserved for a journaled collector rejection and carries that rejection code in its evidence reason, and supply-review.unpartitioned-aggregate means intake published only an aggregate with no per-chain rows to join, so the circulating quantity is not bounded and bridge materiality stays with the control pillar.
Canonical accepted state is stored in:
report-cards:v9report-cards:v9:score-indexreport-cards:v9:publication-health
The publication envelope and compact score index bind the same publication generation, result digest and full Safety Score identity. Health names the accepted generation and timestamp. The canonical writer commits all three rows in one atomic, newer-publication-fenced batch; held attempts retain both accepted data rows. Index schema 2 includes rated, NR and pipeline-gap status, nullable grade/score, compact partial metadata, evidence/publication clocks and expected card count, so score-only readers need no decompression or dependency graph. See request memory and rollout.
Canonical arrays and digest inputs use the same locale-independent code-unit comparator throughout compilation and publication assessment. Replaying identical facts therefore cannot select a different equal-scoring route, reorder a dependency path, or hash a different reviewed-transfer sequence solely because the runtime locale changed.
Asset-scoped fact-compilation and set-evaluation failures are quarantined with the asset id and failing field path, while unaffected cards continue through publication. Captured quarantine evidence proves an A pipeline cause; an asset with fewer than two supported pillars publishes pipeline-gap with null score and grade, not issuer NR. Dependents preserve the parent's actual availability and causes instead of receiving fabricated zero or perfect support.
The same boundary covers extension admission. Six reviewed registries—access lookthrough, incidents, mechanism, operational resilience, shock coverage and transfer—validate envelopes and asset attribution at module load, retaining duplicate rows. Asset entries validate lazily inside extension-build isolation before chronology/applicability filtering: malformed entries or duplicate keys produce asset-local fact-build-failed quarantines with exact registry paths (for example transferReviews.reviews.0.deployments.0.posture). Conflicting globally unique keys quarantine every attributable owner, not unrelated assets; envelope failures remain global. Full-file provenance retains all entries and canonicalization, preserving valid-file identities. The baseline builder replaces an asset's failed curation, adapter or point-in-time overlay build with a conservative admissionQuarantine stub recording fact-build-failed, field and reason; future-dated review/report/overlay guards remain. materializeSafetyScoreV9FactSetExtension admits assets separately: malformed local fields, research-evidence/operational-resilience overlays outside the extension clock, or replay-pinned shock coverage failing journal provenance produce fact-validation-failed stubs with Zod paths (for example mechanismRiskReview.archetype). Stubs retain only independently valid identity/dependency fields, never score-bearing reviews. Compilation emits the ordinary producer-failed quarantine (safety_score_v9_asset_quarantined, stage extension-admission, message <path>: <reason>), counting toward the unchanged 90% healthy-asset gate. Replaying the admitted stub reproduces quarantine, not a rating. Extension schema, registry fingerprint, source clocks, route freshness, canonical asset ids, duplicate/missing assets and active-set checks remain cohort-global and fail the attempt.
Structural-signal percentages remain schema-bounded to [0, 100]. Producers normalize only binary floating-point tails no more than 0.0001 percentage point above 100 and emit safety_score_v9_structural_signal_percentage_clamped with the asset id, field path, raw value, and multiplication that produced it. A larger overage is not clamped: it remains a producer defect and enters the asset quarantine path.
Publication is fail-closed at the identity and system level. Missing, malformed, stale, or incompatible score-bearing inputs hold the last accepted ratings. Live-reserve input health records live-reserves-coverage-below-floor and holds publication when fewer than 60% of coins configured with independent live-reserve producers have an admitted independent snapshot; the denominator deliberately excludes static-validated and weak-probe adapters that cannot enter the independent map. The raw ratio is retained even if a registry transition temporarily makes admitted rows exceed the current denominator; it is never clamped into a different statistic. The floor was calibrated on 2026-09-17 against the production admission map (173/212 admitted; the rejections are structural: monthly-attestation issuers older than the two-day freshness window, NAV-composition-unverified funds, and undeterminable-freshness vaults), so it catches broad reserve-feed failures without treating non-independent coverage as healthy.
Decision (2026-09-21, rateability floor). The publication floor stays an absolute count — V9_MINIMUM_RATEABLE_ASSETS = 271 rateable assets — rather than becoming a fraction of the active registry. It is a bootstrap guard against a publication that lost most of its cards, not a coverage target, and a ratio would make the gate move every time the catalog grows or shrinks for unrelated reasons. The cost is that the floor weakens in relative terms as the registry grows, so the constant is reviewed on the same cadence as the catalog rather than left to drift; the published floor diagnostic reports the observed rateable count beside the required value so the margin is visible on every publication.
Measured DEX history has an independent three-hour confidence window inside the accepted liquidity generation. Publication checks that embedded clock for the selected primary and positive-credit backup routes. It also checks formerly contributing retained routes when a candidate deteriorates, including route reselection or NR across a liquidity-generation change. Expired, previously mature high-confidence measured history produces a system-level dex-stale hold even below the 10% asset-local allowance and across evaluation-build changes. A new outer snapshot timestamp cannot refresh old embedded quotes. Never-mature measurements, non-measured models, and unused alternatives do not trigger this hold; deterministic quote failures that reset maturity remain ordinary adverse evidence.
This operational gate does not change score arithmetic, grade thresholds, or evidence-age limits. It retains the accepted publication with explicit held health, protecting parent-dependent grades and keeping outage/recovery noise out of canonical history and alert sources. Publication resumes only when the exact input admits refreshed history (or no contributing expired history remains). The existing global hold also pauses unrelated legitimate rating updates and has no automatic age-to-NR transition; per-asset holds or a maximum hold age require a separate product-policy decision. Full liquidity persistence now runs hourly at :16, with :46 reusing that exact accepted generation, so recovered quotes no longer wait for an even-hour publication.
Deleting the superseded D1 cache keys still requires a coordinated cleanup migration, because migrations run before the new Worker is active.
Compile hot path and its memory budget
The :22 / :52 compile runs permanently near both Worker ceilings. On 2026-09-23 the 19:22:06 cron invocation was terminated after 31,327,365 us of CPU — at the platform's 30-second scheduled-handler CPU budget — while its progress row still read fixed-input-prepared; Cloudflare reports that invocation as a clientDisconnected client disconnect, not a memory-limit outcome, with the same value reported for CPU and duration. Its two-invocation status group reports a peak allocation of 195.6 MB against 120.2 MB for the sibling 0.06 s invocation killed in the same minute, so a compile peak in the high 100s of MB remains consistent with that termination. The two Workflow compile invocations the same day (07:52:46 and 11:22:53) were killed as memory-limit outcomes at 217.0 MB and 223.2 MB. Two structural decisions keep the peak down and are pinned by tests:
computeSafetyScoreV9parses the exact capture once and passesfixedInputAlreadyNormalized, so the runner never re-normalizes the base input a second time.prepareFixedInputcomposes its result by spreading that normalized input and layering the two loader-validated journal projections. The runner used to re-run the full native-input normalization over the composed value — three Zod passes over the ~2.4 MB payload plus the DEX and redemption row copies and both payload fingerprints (each a canonical stringify and SHA-256 over the whole map).preparedFixedInputAlreadyNormalizednow routes that result throughwithNormalizedV9JournalProjections, which re-validates only the journals under their own schemas (including their empty-map defaults) and leaves base-field identity to the runner's existingsameBaseInputassertion.- Asset facts admitted behind the quarantine boundary are frozen and marked by weak in-process identity. Cohort compilation reuses those rows rather than Zod-copying the whole graph again, while still validating source identities, the exact active asset set, references and chronology. Cloned or external rows receive full schema admission.
- Research-overlay projection and failure-domain normalization copy only changed branches. Worker reviewed-evidence hashing uses native incremental SHA-256 over the same canonical chunks; shared browser-facing hashing remains runtime-neutral.
- Canonical publication releases the evaluator graph after taking its projection inputs; full replay/verification callers retain their intermediates. Public cards pass full schema admission individually before publication-wide foreign-gap reference remapping. A call-local identity proof avoids cloning the entire card graph again, while response-wide chronology, membership, parent-attribution and causal-authority refinements still run; external publication readers retain full schema parsing.
- Contagion reruns break JSON aliases one asset at a time, including aliases between fields within the same asset. This preserves hypothetical isolation without retaining the full registry's serialized text alongside its decoded clone.
- Publication serialization feeds canonical JSON chunks directly into bounded gzip instead of retaining a full canonical string alongside the publication graph. Chunk boundaries preserve UTF-8 surrogate pairs and do not change stored publication bytes.
- Canonical JSON chunks are flattened with a bounded token join before retention; concatenation ropes otherwise retain per-token nodes across the whole stream. On the 397-active registry extension, paired old/new encoders produced identical 12,262,641-byte strings (SHA-256
bde344bb800c72c12a5548ffe8e9a153a2c908f5de5880be81cf81c39cd05926); sampled serialization heap growth fell from 109.98 to 77.90 MiB (115,325,256 → 81,682,608 B). The unchanged 128 MiB old-space publication guard completes.
Measured on the real 2026-09-23 production capture (2,494,305 B decoded payload: 332 DEX rows, 327 redemption rows, 332 active assets) by running the exact sequence parse, prepare-normalization, compile, serialize under a fixed old-space budget with repeated runs: at 112 MiB the pre-change path never completed (0/10 runs) while the shipped path completed half the time (5/10), and from 116 MiB both are reliable (6/6 each, and 4/4 each at 120 MiB and above). Both paths produce a byte-identical publication (report-cards:v9:v1:c15216e7d4a2bc5842563c3226b89659331c6180b508333e79bf136d8842604e, serialized SHA-256 9cdd8b5d5cae44c489fb0e4ba83187a40d244d2ea77d2b5036880d267391a1e6). worker/src/lib/__tests__/safety-score-v9-prepared-input-normalization.test.ts pins that equivalence on the full-registry fixture, and worker/src/lib/__tests__/safety-score-v9-resource-budget.test.ts keeps the 128 MiB ceiling covered in CI.
The 2026-10-02 real-capture release probe additionally exercises accepted-publication serialization/parsing, warm compilation and replay-capture serialization. Paired frozen V10 source/catalog runs at 128 MiB of Node old-space improved from 2/6 completions to 6/6; archived V9 completed 6/6. At 160 MiB, the three-run median warm CPU fell from 2,878.505 ms to 2,190.763 ms, and the highest process RSS fell from 517.125 MiB to 502.406 MiB. Successful before/after runs retained serialized SHA-256 efdd93cd8083aec325544e38c9daa19a2ace4585dbd32e6e35b9b2613577e221. A separately rebound current-tree capture also completed 6/6 at 128 MiB without quarantines. These are Node regression measurements, not proof of a 128 MB Worker-isolate ceiling: RSS includes native/runtime allocations, and Node GC CPU includes concurrent collector work.
The 2026-10-03 397-active full-registry regression probe exposed duplicate public-card retention during admission. With the probe and its limits unchanged, incremental card admission and early evaluator release changed a paired pre-fix OOM at 128 MiB Node old-space into 6/6 completions; the maximum observed post-GC survivors were 120.6–121.4 MiB, versus 123.5 MiB before termination. Canonical publication JSON and the stored envelope remained byte-identical (SHA-256 a732dac731543b75382f34769ac1c0e5a5fde358f7b2a5e76396b1aff292d718 and d5301eaf66f7530a333ad8076f26ad1181798b09c99ec3881ade5756cc576ad5). Per-asset contagion cloning also completed all nine 397-asset scenarios at the unchanged 256 MiB guard in 14.39 seconds, with identical full scenario outputs. The heap repair does not waive the raw-publication gate: this fixture remains 6,882,271 B against its 6,750,000 B regression ceiling, although 606,409 B compressed and 809,514 B stored are below the production codec ceilings.
Both scheduled events of the :22 minute died together on 2026-09-23: the compile invocation and the fiveMinuteTelegramAlerts invocation at 19:22:06 both report a client disconnect (31.33 s and 0.06 s of CPU), and the Telegram slot's row reads scheduled slot abandoned before child job started while the compile's progress row still read fixed-input-prepared. The :22 / :52 compile minutes are also five-minute Telegram minutes, so whatever the platform co-schedules into that minute shares one isolate's memory limit with the compile; a smaller compile peak bounds that collateral exposure. The 19:52 slot published normally, and a deploy had last activated at roughly 18:43, so the same-minute pair is the whole signal — no deploy coincided with it.
API
GET /api/report-cards/v9 is the full live Safety Score API. GET /api/dependency-graph/v1 exposes a free, no-key graph projection of the same accepted publication, not another scoring authority.
The handler reads the canonical publication and health row, validates the complete current response, and never recomputes or falls back to V8. Missing, malformed, or incomplete accepted state returns 503; an identity mismatch between otherwise valid rows serves the authenticated publication as explicitly held. The retired unversioned /api/report-cards route and preview aliases return 404.
A current response emits X-Safety-Score-Status: current. A held response serves the last accepted ratings, emits X-Safety-Score-Status: held, uses the accepted timestamp for freshness, and forces Cache-Control: no-store.
Endpoint freshness for /api/report-cards/v9 follows the publication cadence: the shared surface descriptor sets the X-Data-Age / Warning budget at 2x compute-safety-score-v9 (3600 s), so the endpoint tolerates exactly one missed 30-minute publication — the same basis as the V9 consumer fail-close — instead of the historical sub-cadence 900 s budget.
The V9 consumer fail-close itself (worker/src/lib/safety-score-v9/consumer-freshness.ts) treats an unusable clock as unavailable, not fresh: a non-finite updatedAt (or now) and any publication time later than now are both rejected on the same path as the age limit. No clock-skew allowance is granted, so the read instant is the newest acceptable publication time. Consumers reading the age constant directly keep their own bounds.
The response includes:
- complete V9 identity and source digests
- methodology and policy identity
- active-set completeness
- current or held publication health
- native three-pillar cards, nullable excluded-pillar diagnostics and status-aware breakdowns
- per-card
backingFromLiveReservesprovenance for score-grade reserve coverage - the canonical serial/basket dependency graph
- accepted
updatedAt
See Report schema v7 for cause-aware fields. Completeness reconciles expectedCount = ratedCount + notRatedCount + pipelineGapCount, with disjoint sorted NR/pipeline IDs. Index 2 and free-grades 1 preserve compact status/partial metadata; graph/scenario schema 2 preserves technical parent/model nulls separately from NR.
Each pillar row on a card carries a freshness value: current, stale, or unknown. The Exit
pillar's value is the age of the DEX liquidity input the exit-route evidence was observed at,
judged against the lane's 4-hour evidence bound (DEX_LIQUIDITY_EVIDENCE_MAX_AGE_SEC, applied by
the compiler as routeFreshness.dexMaxAgeSec): a DEX publication at or under 4 hours reports
current, an older publication reports stale, and an asset with no DEX row reports unknown.
It is presentation metadata projected onto the card — it never feeds a score, a cap, or a
publication identity digest. Backing and Economic Control keep unknown until their own lane
ages are projected (only the Exit lane is wired today). The card-level evidence.freshness
reports stale when any wired pillar is stale and unknown otherwise, so a stale DEX
generation is visible downstream instead of anonymously unassessed.
See API Reference for the wire contract.
Consumers
All active safety consumers resolve the canonical V9 publication:
- Safety Scores, homepage, stablecoin detail, comparison, portfolio, and dependency map
- Yield Intelligence safety hydration
- daily digest and mint/burn flight-to-quality classification
- Telegram grade-change alerts
- OG cards, public datasets, and coverage/status surfaces
- append-only safety-grade history
The stability-index OG consumer renders an explicit unavailable state when no PSI sample exists; absence is never presented as score 0 or the MELTDOWN band.
Consumers that require current ratings reject held publications. Display surfaces may show the held accepted snapshot with an explicit notice, and a producer that stamps the accepted identity on its own payload (yield publication) may consume the held accepted ratings inside the same stale-coherent window the yield read path applies. No active consumer uses the V8 compact score cache or computes V8 cards on request.
Selector creation recomputes against the live V9 publication (functions/lib/selector-canonical-snapshot.ts); a 503 now indicates canonical-source or schema failure, not a policy hold. Existing signed selector snapshots remain readable through their historical contract.
History
The compiler admits each asset's local extension and validates each asset's facts independently. An attributable asset-local build, admission, or schema failure publishes that asset as a producer-failed NR result while unaffected assets continue, provided at least 90% of active assets remain unaffected. Dependency-graph, aggregate, evaluator, identity, and other global failures still hold the whole publication.
Replay captures taken before 9.07 carry the retired v3 exact fixed input in cache envelope v1. npm run safety-score-v9:replay still accepts them, read-only: nothing writes that shape any more, but frozen operator captures must keep replaying byte-for-byte through the same compiler. --input therefore accepts both the native v4 capture and a pre-9.07 v3 capture, in raw or envelope form.
snapshot-safety-grade-history appends identified V9 organic transitions and suppresses writes while publication is held. During a partial publication it also suppresses transitions for quarantined assets and their affected dependents, so operational NR and recovery edges are not recorded as organic rating changes. Each V2 row records model, methodology, policy, evaluation-build, base-input, publication generation, and transition kind.
The writer compares publication identities. The capture's v9-input identity never reaches it, so a capture-producer change cannot manufacture a boundary or an organic transition by itself. The evaluation build is part of publication-identity comparability, so the first publication after an evaluation-build rotation writes one methodology-boundary-baseline per asset rather than organic grade changes.
GET /api/safety-score-history remains the public per-asset timeline. Historical V8 and activation-boundary rows remain readable as archive data; they are never live publication inputs.
The stablecoin detail Grade History module combines that legacy archive with GET /api/safety-score-history-v2. It collapses consecutive same-grade baselines, while retaining a boundary row when the published grade changes and labelling it as a methodology baseline rather than implying an organic upgrade or downgrade. This keeps the current V9 grade and the date it first appeared visible without comparing non-comparable publication identities.
Frontend
- The route FAQ describes the 30-minute evaluation cadence and last-verified publication behavior in reader-facing terms. Its alert CTA links to the existing
/pharoswatchbot/#getting-startedsetup section. src/app/safety-scores/v9-client.tsxowns the active ratings grid, filters, and sorting. Its grade filter composes with an inline peg filter that groups the stablecoin-listpegTypevalues into USD, non-USD fiat, and commodities (gold or silver); selecting the active peg pill again clears that peg constraint.src/app/safety-scores/pillar-explainer.tsxrenders the static three-column primer immediately below the hero. It introduces Backing, Exit, and Control through one plain-language question apiece, shows the current 40% / 35% / 25% weights, and keeps methodology detail out of the ratings grid.src/lib/safety-score-data-coverage.tsanddata-coverage-module.tsxderive and render the score-input coverage module on/coverage/. Collapsed it shows one sentence of headline counts and the open-data-point split by evidence responsibility; expanding it adds the responsibility explanations, the per-count breakdowns, and the most common reason codes by affected assets. A publication hold replaces the headline sentence. The Safety Scores hero no longer embeds this module.src/components/report-card-mini-v9.tsxrenders the V9 card treatment.src/components/stablecoin-detail/stablecoin-safety-score-v9-card.tsxrenders detail-page score, pillars, evidence, and breakdowns.- Pillar breakdowns render as
groups, not a flat row list. Backing nests its components under the Reserves and Mechanism groups the producer already computes — componenteffectiveWeightsums exactly to each group's weight — withmechanism-sourced components under Mechanism and bothreserve-exposureandreserve-concentrationunder Reserves. Rows sort by weight descending, and components under2%of the pillar fold into aSmaller holdings (N) · X% combinedtail once at least three qualify. Exit and Control render a single unlabelled group; Exit keeps producer order because its route components are few and already meaningfully ordered. The Exit summary names the primary route and backup credit, while actual stress-request completion appears separately from the capacity component score. Other eligible routes are labeled as evaluated rather than implying that every route was blended into the pillar. - The Economic Control breakdown leads with its binding components, cheapest first, so the row that sets the pillar score is read first. Its mint component renders as
Mint authority, matching the detail page's Mint Authority section below the card. Non-binding bridges roll into oneBridge deploymentscomposite carrying the cohort's worst score — the pillar rule is a minimum, so an average would flatter it — expandable to the full list. Any binding bridge stays a top-level row and must never be folded away. The composite needs at least two members; otherwise the bridge renders as an ordinary row. This keeps large deployment rosters compact without hiding the score-setting control. - Component bars are tinted only when the input is the problem: neutral below the warn threshold, amber under 65, rose under 40. Those boundaries are the published grade-band floors for B- and D, so a tinted bar always reads as "C+ or worse" and a strong asset's breakdown stays monochrome.
Why not higherrenders the two causal buckets fromscoreTrace:adverseAttribution(measured and adverse) as a flat list, andboundedUncertaintyAttribution(unresolved) grouped byresponsibility. Pharos's own gaps —producer-failed,integration-missing,published-evidence-expired— are named as ours rather than folded into a neutral "not measured".- Attribution
pathvalues are machine keys and are never rendered; producer messages quoting four or more decimal places round to three for display.
- Pillar breakdowns render as
- The detail card renders an evidence summary under the score, pillar rows, score adjustments/caps/construction, an access panel, and
EvidenceFooter, which provides methodology links plus an optional foldedSources (N)list; it has no evidence chip. Dependency context remains withContagionSnapshot("Dependency Context"), which owns the full dependency graph. - Screener and comparison rows expose a compact top-driver chip alongside the V9 profile.
projectTopDriver(card)reads the already-published binding cap first, then the weakest pillar, and preserves the card's evidence freshness without recalculating any score. Withheld cards identify that state explicitly. The chip links to the stablecoin detail#report-cardanchor, where the full waterfall and causal explanation remain available; the screener uses its existing scalar row projection and does not issue another report-card request. AccessPosturePanelrenders the four scored access enums in the summary rail atxl+and inside the card belowxl(xl:hidden), the same split#priceuses.buildSafetyScoreV9AccessRowsexposes the rows without building the whole card presentation.primaryExitdistinguishes three kinds of absence and the panel treats them differently.noneis a reviewed negative — an exit surface observed complete with zero routes — and renders as "None".undisclosedmeans no credited route resolved a posture, or the exit surface was never observed; it renders as an explicit "Incomplete exit surface" row, because the gap does not establish issuer non-disclosure.unknownmeans credited routes exist but their access facts are unresolved; it alone entersunknownFieldsand alone drops out of the panel. The posture is derived from every route the Exit pillar credits — score-eligible routes plus reviewed issuer-, protocol-, and eventual-redemption routes — so the panel cannot contradict a scored exit route.src/lib/safety-score-v9-labels.tsis the single shared machine-key to display-copy map for public V9 surfaces. Cap kinds, failure domains, and attribution paths draw on overlapping producer keys, so new modules extend this map rather than adding their own.src/components/radar-chart-v9.tsxrenders Backing, Exit, and Economic Control comparisons.src/components/safety-score-v9-status-notice.tsxrenders held publication state on every other surface. Reason codes and assessment detail are evaluator identifiers and are never rendered raw; both surfaces route hold reasons throughdescribeDataCoverageHoldCauses.src/hooks/api-hooks.tsexposesuseReportCardsV9anduseSafetyScoreHistory.
The retired V8 report-card components, V8 portfolio synthesis, and contagion stress simulator have been removed. A future stress feature must define native V9 semantics rather than recomputing retired V8 dimensions.
Reviewed native transfer applicability retains unresolved material chain identities from supply and declared deployments. A review of one unsupported chain cannot establish another unsupported chain's transfer posture; each chain and each exact declared token identity must be covered by a non-additional reviewed deployment before the native exemption applies.