Confidence you can check for yourself.
A stated confidence of 0.7 carries an empirical coverage guarantee, not a model probability. It holds whether or not the underlying survival model is correctly specified.
Why not the model's own number.
A survival model emits a probability, and it is tempting to publish that as confidence. For a bonded claim it is the wrong number.
A model probability inherits every misspecification in the model.
If the feature distribution shifts, a stated 0.9 can be an empirical 0.6.
Publishing that as confidence is a promise the system cannot keep.
How this works
Split conformal prediction gives distribution-free, finite-sample coverage under exchangeability. Market regimes are not exchangeable, so the mitigations matter as much as the method.
01
Scores nonconformity
Signed, so over-prediction of the horizon is the error that counts. That is the error that gets a user liquidated.
02
Stratifies by regime
Separate calibration sets per market regime, matched on supply direction, cross-chain flow, and realised volatility.
03
Degrades explicitly
Outside the support of every calibration stratum the system does not extrapolate. It flags OUT_OF_SUPPORT and lowers confidence. Refusing to make a confident claim is a supported output.
What it reads, derives,
and does with it.
What it reads
Resolved attestations, held back from training.
What it derives
What calibration produces.
What it does with it
What ends up in the payload.
“The scoring model is publishable and copyable, but the accuracy record is not. A competitor who reimplements the ensemble from this paper starts with an identical model and a calibration history of zero.”
Thirty-six surfaces across contract, API, agent, and automation
Durability attestation for autonomous capital. Read the horizon before the capital moves, not after.