TWIX Lock protection overview.
The dashboard is intentionally operational: source state, model coverage, simulations, private findings, authorization and continuous watch are visible without exposing vulnerability payloads.
Executable twin lifecycle
Current target state flows through the same protected pipeline on every approved update.
Latest protected activity
Operational metadata only. Vulnerability evidence remains sealed.
Authorization commitment
The target, source state and security authority are cryptographically bound.
—————What the software actually is.
Lock reconstructs the implementation into an executable system map: components, authorities, asset flows, dependencies and invariants that can be tested independently of prose documentation.
Behavior graph
Demo topology reconstructed from an example Cosmos/EVM financial protocol.
Modeled invariants
Examples are deliberately abstract in the public demo and contain no actionable vulnerability detail.
| ID | Invariant | Domain | Coverage | State |
|---|---|---|---|---|
INV-041 | Asset accounting remains conserved across authorized transitions. | assets | 97% | MONITORED |
INV-047 | Privileged execution requires an authority present in the current model. | authority | 94% | DEGRADED |
INV-052 | External price state satisfies configured freshness assumptions. | dependency | 88% | WATCH |
INV-063 | Failure ordering does not create a second authoritative state. | state | 91% | VERIFIED |
Challenge the model in isolation.
Simulations run only against the authorized sandbox twin. This demo shows safe scenario categories and state-search telemetry without disclosing exploit steps.
Verified problems. Zero public disclosure.
Finding metadata is visible to authorized project users; reproduction evidence and technical payloads remain encrypted and access-controlled.
Finding register
Open a row to view the safe private-report summary and cryptographic commitment.
| Finding | Severity | Component | Status | Commit | Action |
|---|
Monitor behavior, not just commits.
When source, dependencies, deployments or governance change, Lock asks what changed in the executable model and which prior assumptions need to be re-tested.
Live protected event stream
Demo feed cycles through repository, model and monitoring events.
Pre-authorized defensive policy.
Lock never lets an LLM arbitrarily pause a financial system. A defensive action requires a deterministic verified condition and a project-authored policy that already permits the response.
Normal operation
Continuous model and runtime observation. No intervention. Collect evidence and establish expected behavior.
Verified degradation
Alert authorized maintainers, increase simulation depth and optionally reduce configured exposure limits if the project has pre-authorized that action.
Reproducible critical violation
Only a deterministic condition plus explicit project policy can invoke an emergency adapter such as pausing a risky route while preserving repayment/recovery operations.
Policy boundary
The sequence is intentionally separated.
Encrypted custody for security intelligence.
Finding packages remain private while cryptographic commitments prove integrity, chronology and remediation linkage. Access can be granted or re-keyed without public disclosure.
R-000184 · Access-controlled
The underlying evidence includes the model failure, repeatable sandbox evidence, state delta, affected target state and remediation guidance. This public demo intentionally never renders the actionable payload.
7e84a2929c7c2e0b8e67b0c4e92f…reverse://private/7f8419bd…12pendingAuthorized recipients
Demo re-keying model inspired by Securail's recipient-bound custody philosophy.
Private research, independently verified.
Researchers submit sealed evidence against authorized targets. Lock reproduces the claim in the project's sandbox before any project payout or severity decision proceeds.
Private submission queue
No report body or proof-of-concept is exposed in this register.
| Submission | Claim | Researcher | Stage | TWIX stake |
|---|---|---|---|---|
RB-2081 | authority invariant | researcher_0x91… | REPRODUCING | 2,500 |
RB-2079 | dependency assumption | researcher_twix1… | TRIAGE | 0 |
RB-2064 | state ordering | researcher_0x34… | PAID | 1,000 |
Meter the work that creates security value.
Rather than inventing artificial token utility, Lock consumes TWIX for real platform resources: compute, simulation, monitoring, report custody, bounty settlement and verification.
Usage ledger
Illustrative demo units only; final economics can be configured at launch.
| Workload | Meter | Quantity | TWIX | Status |
|---|---|---|---|---|
| Lock Inspect | analysis worker-minutes | 428 | 2,140 | SETTLED |
| Lock Sim | sandbox state executions | 84,219 | 7,950 | SETTLED |
| Lock Watch | continuous coverage | 30 days | 2,250 | SETTLED |
| Lock Rail | encrypted report custody | 3 active | 500 | SETTLED |