System

What this surface is, and what it deliberately cannot do.

This deployment
Deployment0xdcb9db121ca873817fca7ee6a8e2cd8ef0249b7c83f4e656553338da00eccaa6
Buildgeneration-3
Surfaceread-only
Trust boundary

This console holds no settlement key. Signatures come from your own wallet, and its database is a projection: convenient, and never evidence. A reader who wants proof runs the verifier against the chains.

Application database state never authorizes value movement.

One key, and what it cannot do

Every value-moving call demands a quorum of compliance attestations signed by an address the contract’s registered signer set contains. A browser cannot produce one, so this deployment’s Worker holds that signer. It signs eligibility answers Cleanverse gave and nothing else: it cannot move a token, sign a settlement intent, create a settlement, decide one without both parties’ signatures and a canonical READY state, or release a leg without a COMMIT already on chain.

The contract proves an authorised signer asserted eligibility. It cannot prove the signer asked Cleanverse. At this deployment’s quorum of one, that is a trust assumption in the signer’s operator — threat register T-08 and T-09, accepted with a written waiver, and not described anywhere as trustless.