Almanak
Operated by Almanak. Evidence mode: fork-onchain-open-position-executed.
Why DN assigned this class
DN has verified bounded authorization, revocation, permission-drift resistance, provider-fault recovery, open-position containment, signer recovery, explicit financial-envelope controls, agent-policy chokepoints, aggregate cross-protocol exposure controls, and authenticated lower-level gateway execution in secure/hosted mode. This is sufficient for provisional E3 classification. E3 is not equivalent to production certification and remains subject to configuration, adapter completeness and credential-management limitations.
Classification conditions
- secure or hosted mode with gateway authentication enabled
- PolicyEngine active on agent-facing execution paths
- risk limits configured for intended financial scope
- no reliance on explicit local insecure mode
- aggregate exposure inputs materially complete for active adapters
Recurring E3 controls active
DN retains historical observations instead of overwriting old results. A failed core surveillance control places the E3 classification under review until the failure is diagnosed.
Control-by-control evidence
Agent Policy Chokepoint Safety
96- oversized direct agent action blocked before compilation
- oversized direct agent action blocked before execution
- cached bundle revalidated against current policy
Cross Protocol Exposure Safety
96- total exposure ceiling enforced
- per-chain exposure ceiling enforced
- position concentration ceiling enforced
Gateway Authorization Safety
96- ExecutionService.Execute authenticated in secure mode
- missing and invalid tokens rejected
- secure startup fails closed without auth
Financial Envelope Safety
95- single-trade cap enforced
- daily spend cap enforced
- position-size cap enforced
Signer Recovery Safety
94- compromised signer proven functional before revocation
- same signer denied after revocation
- revoked signer could not retain bounded authority
Recovery Safety
93- six reconciliation classifier cases passed
- provider fault injection passed at initial receipt observation
- provider fault injection passed at block membership check
Authorization Control
92- authorized call succeeded before revocation
- state change verified
- revocation succeeded
Containment Safety
92- real leveraged position opened and settled on managed Arbitrum fork
- live position measured before containment
- full close compiled from measured position size
Permission Safety
91- teardown permission expansion passed
- unknown-symbol fail-closed behavior passed
- address-form permission preservation passed
Emergency Control
90- 250/250 emergency-control iterations passed
- median in-process latency 2.91 ms
- p95 4.98 ms
Executed observations
DN Almanak Gateway Authorization Boundary
code-executed-gateway-auth-boundary
code-executed authentication and startup tests rather than a live production gateway penetration testDN Almanak Cross-Protocol Aggregate Exposure
code-executed-aggregate-exposure-enforcement
code-executed risk-guard and adapter tests rather than funded production executionDN Almanak Agent Policy Chokepoint
code-executed-agent-gateway-dispatch-instrumented
instrumented mock gateway rather than funded production executionDN Almanak Allocation Limit Enforcement
code-executed-policy-enforcement
code-executed policy tests rather than funded production executionDN Almanak Signer Compromise & Recovery Boundary
fork-onchain-signer-revocation-recovery
local managed Anvil fork rather than production mainnetDN Almanak Open Position Containment
fork-onchain-open-position-executed
managed Anvil fork rather than production mainnetDN Almanak RPC Receipt Observation Fault Injection
code-executed-fault-injected
DN Almanak Permission Drift & Recovery Safety Benchmark
code-executed
DN Almanak Zodiac Fork Authorization Benchmark
fork-onchain-executed
Local Anvil fork only, not mainnetDN Almanak Emergency Control Latency
code-executed
Measures in-process emergency-control latency in CI, not blockchain settlement latencyDN Almanak Isolated Safety Benchmark
code-executed
No funded mainnet or fork-execution testLive DN Agent Trust badge
Current state: PROVISIONAL. The badge derives from the same Risk Graph and surveillance state as this profile. If a core control moves under review, the badge changes with it.