TRUST / METHODOLOGY
How the evidence works
Source binding, deterministic transitions, explicit unknowns, and reproducible records.
EVIDENCE MODEL
Reproducible, source-bound, fail closed.
Canonical identity begins with Robinhood's asset registry API. Every active API UID must independently resolve through the verified Chain 4663 StockFactory at the same address. Factory reads are pinned to the lower common block and must agree across two independent RPC provider origins before a registry snapshot can be accepted.
The official contracts page is hashed and monitored, but its stock-token table currently fetches that same API client-side, so it remains an indirect public surface rather than a second authority. Any API-to-factory address divergence is persisted, quarantines the candidate snapshot, and fails the registry job. Names and tickers never substitute for UID and exact-address agreement.
Critical token-state and venue reads use the same fixed-block provider quorum; missing or conflicting evidence is never persisted. Venue candidates must resolve from Uniswap's official V3 factory, match the canonical token and USDG orientation, return a 30-minute TWAP, and retain at least USD 1,000 of attributable quote depth after USDG/USD conversion. The separately timestamped Robinhood quote remains an underlying reference, never a token execution or redemption price.
Blockscout holder and transfer counters retain token address, source URL, coverage, and observation time. Events retain source mode, block or observation time, and deterministic identity.