Product guard report

Three executable checks from the application source, with the input that passes and the input each check rejects. This report describes source revision e72b0ebc6f42286c0f3461e58434c108f8e951c4, inspected on 5 October 2026. It does not certify a particular installed binary or a market result.

How to read this report

Each row names the exact test and implementation in the source revision. The repository is private, so these paths cannot be linked to public source today. The test commands and observed pass/refusal are stated here so the claim is bounded, but a public reader cannot independently inspect the named source until it is made accessible. No user data or trading strategy is used in these controls.

Run from app/ with the project virtual environment: python -m unittest discover -s tests -p <test-file> -q. The RPC check runs as python tests/rpc_allowlist_smoke.py. A green test records how its constructed inputs behaved. Untested inputs require separate checks.

1. Past output under a future cut

Input. A synthetic hourly series is replayed in full and with its future removed. The guard compares overlapping past output after its declared boundary margin.

Passing control. A backend returning an observed flat series passes, with compared observations recorded. Biting control. A deliberately constructed past trade disappears after the cut; the guard fails and reports the first changed timestamp. A one-sided missing value is also refused. When the margin leaves no overlap, the result is insufficient rather than a pass.

Detects. A backend whose earlier result changes when later bars are removed, within this test's overlap. Limit. This synthetic boundary test leaves real data quality and native kernel coverage unverified.

Private source, available to authorized reviewers at the stated revision: test app/tests/future_poison_boundary_smoke.py; implementation app/stochastly/engine_contract.py (future_poison).

2. Metric threshold direction

Input. Three synthetic return series have expectancy below, equal to and above zero. The test applies the same metric gate through the run specification and the MCP plan adapter.

Passing control. A greater-than-or-equal gate retains the zero and positive cases; a less-than-or-equal gate retains the negative and zero cases. The equality case stays on both boundaries. Biting control. An unknown operator, an unknown observation window and a non-finite threshold are rejected before a run.

Detects. A reversed comparison, lost operator during MCP translation, or an invalid threshold silently accepted. Limit. This checks the gate's filtering behavior on constructed series; it does not validate a trading edge or calibrate the metric itself.

Private source, available to authorized reviewers at the stated revision: test app/tests/gate_controls_smoke.py; implementation app/stochastly/executor.py (_apply_metric_gates).

3. Local RPC surface

Input. The check compares public API methods, literal calls in the React and MCP clients, and the sidecar's explicit RPC allowlist.

Passing control. Core methods used by the app are present in the allowlist and the dispatcher serves declared methods from that list. Biting control. The start_run demonstration remains outside the dispatcher; a fabricated route outside the dispatcher is recognized by the route scanner.

Detects. A called method missing from the declared surface, a stale declared method, or a newly added route outside the dispatcher that was not declared. Limit. The source scan matches literal method names and cannot prove that a dynamically built call name is covered. This is a surface inventory, not proof that a local process cannot obtain the sidecar token.

Private source, available to authorized reviewers at the stated revision: test app/tests/rpc_allowlist_smoke.py; implementation app/stochastly/sidecar.py (RPC_ALLOWLIST).

Limits of these checks

These tests exercise specific mechanisms on constructed inputs. These checks cover the three named paths. Catalogue coverage, installer availability, future returns and independent reproduction require separate evidence while the source repository remains private. The causality method and validity limits give the adjacent protocol and its bounds.