Do not trust us.
Check.
LAYA makes eight promises. Next to each one is live evidence and a button that checks it right here in your browser, so you never have to take our word for it.
Eight promises, each with a live proof read from the public endpoints and a check you run yourself: Ed25519 verification in WebCrypto, SHA-256 over canonical JSON, the pinned manifest, raw feeds and a zero tolerance replay comparison.
The service, read live.
These numbers come straight from the running service every 30 seconds. If the scanner stops, this panel turns amber and says so.
Polled from /api/status every 30 seconds while this tab is visible, plus the signed feed head. Block rate is measured from two signed results, not quoted. A missing heartbeat reads as unavailable.
Raw sources: /api/status, /api/health, /api/feed. Open them and compare with this panel.
Eight promises. Each one checkable.
Read the promise, look at the live evidence, then press the button to check it yourself.
Each row states the claim, shows the live evidence it rests on, and gives a check you run here plus the command line equivalent.
Two runs. Every number side by side.
Paste or load two replay outputs, or two results. The page lines them up number by number and tells you if anything differs.
Accepts replay results (answers), job results (result.answers) or result payloads (inference.result.answers). Every numeric leaf is compared with tolerance 0. Nothing leaves this browser.
The exact model, the exact questions.
Which AI answers, which version, the fingerprint of every file, and the four questions it is asked, word for word. Known contradictions are listed too.
From /api/manifest and the newest full result. The question text is inference.request.questions exactly as signed. Contradictions are counted over the complete archive with the published risk threshold.
- Loading
- the pinned manifest
The four typed questions, word for word
Loading the newest full result.
What is protected, and what is not.
The honest list: what the signatures and rules protect you from, and what they cannot.
Trust anchor, transport, browser policy and the limits of each guarantee, stated next to each other.
Protected
- Tampering with a verdict. Change one character and the seal breaks.Any byte change breaks SHA-256(payload) = id and the Ed25519 signature under key_id
dde4b6d3…. - A swapped model. The model files are fingerprinted in every result.model_manifest_sha256 binds revision, per-file hashes and runtime; replays refuse a mismatch.
- A silently trimmed archive. The browser refuses a list with pages missing.Signed record_page cursors share one generation; a gap, repeat or mixed generation throws before rendering.
- Your keys. LAYA never asks for a private key and never trades on its own.No key material is requested. The wallet module needs an explicit confirm callback per transaction, with spend and gas caps rechecked before sending.
- Third party scripts. The site only loads code from itself.Content-Security-Policy:
script-src 'self'; connect-src 'self'; frame-ancestors 'none'. GSAP is vendored, not hotlinked. - Your privacy in the queue. Rate limits never store your address or wallet.Rate limiting stores a salted hash only. Job IDs are bearer capabilities kept in localStorage and never sent to analytics.
Not protected
- Being right. A valid signature proves who published the bytes, not that the AI was correct. No accuracy is claimed.
- Publication time. The signed time is the publisher's clock, not an independent timestamp.
- Truthful inputs. The input is what the scanner read from its RPC. Check blocks on the explorer yourself.
- Token safety. A GUARD pass means these checks did not fail at that block. Unknown is a limitation, never an accusation.
- Your money. Memecoins can go to zero. Only use what you can afford to lose entirely.