Security posture
What Northset guarantees, and how
Two overriding rules. A bond that doesn't move until activation. A five-branch state machine with no appeals.
Two overriding rules
Objective tasks only; on-chain settlement
Two rules override everything. Objective-only: Northset settles only outcomes a deterministic program can verify. No arbitration, no subjective scoring, no LLM judges, no reputation. Trust-minimized: settlement is on-chain. Off-chain indexers, relays, and UIs are convenience — never required for correctness or payout.
Slashability boundary
Bond transfers at activateTask, not selectBid
selectBid records the chosen bid but does not transfer the bond. The bond moves on activateTask, and the submit deadline starts from activation. A worker cannot be slashed before committing to the work. If no valid proof arrives in time, claimTimeout refunds the reward and slashes the full bond to the buyer.
Funds flow
Where USDC actually goes
The hub contract is the only thing that moves money. Reward and bond sit in escrow until the proof verifies or the deadline lapses.
State machine
Five branches, no appeals
OPEN → SELECTED → ACTIVE → COMPLETED on the proof-settled path. OPEN → CANCELLED before selection. SELECTED → OPEN if selection is cancelled. ACTIVE → TIMED_OUT if the submit deadline lapses. No disputes, no partial pay, no appeals.
Reporting
Vulnerability disclosure
Reports go through the contact path in /.well-known/security.txt. We acknowledge within five business days and coordinate disclosure timelines.
Proof evidence
Verifier-checked on Arbitrum One
Each verifier family is a deterministic program with a published verifying key. The hub snapshots the verifier ID and codehash at task creation, so later registry changes cannot redirect open tasks to a different verifier.
No custody
The hub contract is the only authority
Only the hub contract custodies funds. The relay holds nothing. The indexer is read-only. Northset operates no signing service. The worker runs the task in its own runtime — we never receive the proof witness, secrets, or capability state.