The Standard · v1.1 · Issued successor
The complete issued successor.
This is the full v1.1 Standard: every lane, claim, evidence rule, exclusion, no-go trigger, review control and correction procedure. It becomes governing on 11 September 2026.
The Mjolnir Standard
Version 1.1 · Issued 12 August 2026 · Effective 11 September 2026
Informational only. This document defines an assessment methodology. It is not investment advice, an offer, a solicitation, a credit rating, a statutory audit, or legal advice.
0 / Status of this document
This document defines Standard v1.1. It governs only a registry record that expressly identifies MJ-STD-v1.1 as its governing methodology. A draft, summary, readiness review, or private memo confers no registry status and no right to use a Mjolnir verdict or mark.
Every assessment issued under MJ-STD-v1.1 is bound by this document. An analyst may not apply criteria that are not written here, and may not decline to apply criteria that are. Where this document is silent, the answer is Declined to Assess — not analyst discretion.
The conditions precedent to issuance are stated in §16 as controls, not as a public progress report. Internal readiness, staffing, incorporation, vendor selection, and implementation status are not part of the methodology and are not published here.
Document owner: Mjolnir Capital. Change control: §15. Changelog: Appendix D.
1 / Purpose
The Standard exists to answer one question, repeatably and on the record:
Were these specified claims, about this specified subject, supported by this specified evidence, on this specified date?
It does not answer whether a project is good, safe, honest, undervalued, or worth buying. It cannot answer those questions, and any wording that implies it can is a defect under Appendix B.
The output of an assessment is a public registry record. The record is the product. A visual mark, if one is ever issued, is a pointer to the record and has no meaning independent of it.
2 / Constitutional principles
These six are not preferences. A change to any of them is a new major version, not a revision.
2.1 Standard before symbol. The full rubric, evidence thresholds, no-go rules, and change policy are published before any assessment is issued. A criterion that is not published when the work is done cannot be applied to that work.
2.2 Registry before marketing. Every serial resolves to a permanent record carrying scope, status, expiry, people, and revision history. A record that cannot be found is not an assessment.
2.3 Buy-side commission only. Investors, allocators, and comparable independent users commission registry assessments. A subject cannot commission, purchase, accelerate, soften, suppress, or delete its own registry record.
2.4 Evidence before assertion. No claim passes without an archived source artifact. Absence of evidence is never treated as evidence of the affirmative. The unevidenced claim does not become true because it is plausible or because the subject is likeable.
2.5 Time-bounded, monitored, permanently corrected. Every record expires. Every material change triggers review. Every revocation and correction stays visible forever.
2.6 No price calls, no recommendations. The Standard assesses defined facts and controls. It does not assess merit. The words in Appendix B never appear in a Mjolnir record.
3 / What Mjolnir is not
Stated positively so it can be quoted against us:
| Mjolnir is not | Because |
|---|---|
| A statutory auditor | No audit is performed and no audit opinion is given. The word “audit” does not describe any Mjolnir work product. |
| A credit rating agency | No creditworthiness assessment, no rating scale, no aggregate score, no default probability. |
| An investment adviser or research house | No recommendation, no valuation, no price view, no suitability opinion, personal or general. |
| A security auditor | Code is not audited. The technical domain assesses review provenance and on-chain control configuration — see §8.2. |
| A legal adviser | No opinion is given on token classification or any other legal question. The legal domain documents disclosure — see §8.5. |
| A fraud detector | A disciplined evidence process does not detect a competent liar. See §12.6. |
| A guarantor | Nothing here promises that a subject will not fail, be exploited, or change after the evidence cutoff. |
4 / Definitions
Subject — the project, protocol, entity, or product being assessed. Commissioning party — the buy-side party that commissions and pays for a Lane A assessment (§5.1). Claim — one atomic, binary, observable proposition (§7.2). Artifact — an archived source object supporting a claim, with capture metadata. Evidence cutoff — the date after which no new evidence entered the assessment. As-of date — the date the record speaks to. Identical to the evidence cutoff. Block height — the specific block at which on-chain measurements were taken. Every on-chain figure carries one. Analyst of record — the named individual who performed the analysis and signs the record. Reviewer of record — the named independent individual who re-performed the review and countersigns (§12.3). Material — a claim, gap, or change that a reasonable allocator would consider capable of altering a domain verdict. Claims designated material carry (M) in §8.
5 / The three lanes
The lane determines who commissions, what is produced, and what becomes public. Lane is fixed at intake and cannot change mid-engagement.
5.1 Lane A — Buy-side commissioned
| Who commissions | Fund, family office, allocator, lender, co-investor, or comparable independent party with a real decision to make |
| Who chooses the subject | The commissioning party. Mjolnir does not select subjects in this lane. |
| Public output | Registry record with serial. Non-negotiable and disclosed before any data room opens. |
| Private output | Full evidence memo to the commissioning party under contract, with defined reliance rights |
| Subject’s rights | May decline to provide a data room (assessment proceeds on public evidence, with scope stated). May not prevent, delay, or edit the record. May link to it. |
Lane A is the only lane that creates a registry object.
5.2 Lane B — Readiness Review (private)
| Who commissions | The subject |
| Public output | None. Ever. No serial, no record, no mark, no right to state that Mjolnir has assessed them. |
| Private output | Gap analysis against this Standard: which domains would not clear, which claims lack artifacts, which no-go triggers apply, and what evidence would close each gap |
| Verdict language | Gap list only. A Readiness Review does not produce verdicts and must never be described as one. |
A Readiness Review is a map, not a grade. It exists so that a subject can find out what will fail an institutional diligence process before it fails one in public. It confers nothing.
A Readiness Review does not entitle the subject to a registry record and does not shorten the path to one. It changes nothing except what the subject knows. The cooling-off consequences are at §14.3.
5.3 Lane C — Thematic research
| Who commissions | Mjolnir, or a buy-side consortium with no interest in any named subject |
| Public output | Aggregate and anonymised only in v1.1. Patterns, evidence-gap frequencies, cohort statistics. |
| Named subjects | Prohibited in v1.1. |
Lane C exists to publish what the desk learns across assessments without publishing a named negative finding on a party that never commissioned the work, never contracted with the desk, never warranted its information, and never had a right of reply. Named public assessment without a commissioning party carries unbounded reliance, no information warranty, and defamation exposure. v1.1 does not accept that trade. Revisit only with counsel and a later version.
5.4 Prohibited structures
The following are refused regardless of fee:
- Any fee for a Lane A registry assessment that is contingent on a verdict, listing, financing, token price, or subject outcome.
- Any arrangement where a subject funds a Lane A assessment of itself, directly or through an intermediary.
- Any offer to suppress, delay, soften, or delete a record for payment.
- Unsolicited public negative findings on a named subject followed by a paid remediation offer. This is extortion in structure regardless of intent, and it is permanently disqualifying.
- Assessment of a competitor commissioned as a commercial weapon with no genuine allocation decision behind it.
6 / Verdicts and statuses
Verdicts describe evidence. Statuses describe the record. They are different objects and are never merged.
6.1 Verdicts (per domain, three only)
| Verdict | Means | Condition |
|---|---|---|
| Verified | Every mandatory claim in the domain is supported by sufficient, current evidence, and no automatic no-go applies. | All claims Pass. All artifacts archived. Analyst sign-off complete; independent re-performance complete where §12.3 requires it. |
| Conditional | The domain was assessable, and a specific gap, breached threshold, remediation item, or no-go trigger exists. | The record names the exact claim, the gap, the evidence that would close it, and the review date. |
| Declined to Assess | The domain could not be substantiated. | Not a finding of misconduct. A documented inability. |
6.2 There is no failure verdict, and this is deliberate
A subject that is tested and found wanting receives Conditional with a precise gap statement, not a scarlet letter. “Conditional — CUS-04: treasury of US$14M is controlled by a single key; remedy: migration to multisig with threshold not less than 3-of-5; review on evidence of remediation” is more useful to an allocator, more defensible in a dispute, and more damaging to a subject that deserves it than any adjective would be. Precision does the work that judgment would otherwise do badly.
6.3 There is no aggregate verdict, score, or count
The registry publishes six domain verdicts and nothing above them. No roll-up, no aggregate, no numeric score, no “N of 6 cleared,” no letter grade, no tier.
The reasons are structural, not stylistic:
- An aggregate requires a weighting function across six non-commensurable domains. That function cannot be evidenced, only asserted — which violates §2.4 at the top of our own output.
- Any single object Mjolnir prints becomes the thing the market trades on. The moment that object exists, Mjolnir is operating a rating scale without the regulatory apparatus of a rating agency, and the careful scoping in §3 is decoration.
- An aggregate is what becomes “Mjolnir Verified” in market shorthand — a project-level property, which is precisely the claim the Standard is built never to make. A count is worse than a word: numbers travel further and lose their caveats faster.
A reader who wants to count the verdicts may count them. Mjolnir does not count them for the reader.
6.4 Statuses (per record, five)
| Status | Means |
|---|---|
| Active | Issued, unexpired, no trigger fired. |
| Under Review | A §11 trigger has fired. Set publicly and immediately, before any conclusion is reached. |
| Expired | Past valid-until date. No reassessment commissioned. |
| Revoked | A material error, undisclosed fact, or later event invalidates the record. Permanent. |
| Superseded | A later assessment of the same subject exists. The old record remains, linked forward. |
Records are append-only. A status changes; a record is never edited, replaced, or removed. Revocation and correction history is permanent (§13).
6.5 The published statistic
Aggregate statistics across all assessments are published quarterly (§14.5): the share of assessments in which every domain reached Verified, the distribution of verdicts by domain, the most frequent evidence gaps, correction counts, review-participation rates, and reviewer disagreement rates where independent review applied.
This is not the same object as §6.3. A statistic about the desk’s own record is not a rating of any subject. The distinction is that the statistic is not attached to a name.
7 / Evidence
7.1 Hierarchy
| Tier | Description | Sufficient for Verified? |
|---|---|---|
| Tier 1 | Independently verifiable primary evidence: on-chain state and transactions; government company registers; regulator notices and enforcement databases; court records; cryptographically signed statements. | Yes |
| Tier 2 | Reliable third-party evidence: security review reports from identified firms; licensed custodian confirmations; recognised data-provider outputs; independently reported media. | Yes, with source named |
| Tier 3 | Subject-provided: data-room documents, management representations, policy documents, decks. | No — corroborating only. Never sole support for a claim where an independent source exists. |
| Tier 4 | Unverified assertions, social posts, screenshots without provenance, undated documents. | Never. |
A Tier 3 artifact may support a Verified finding only where no independent source can exist for that claim — for example, the existence of an internal key-management policy. Where that happens, the record says so.
7.2 Claim construction
Every claim is binary and observable. “Treasury requires a 3-of-5 multisig” is a claim. “Treasury governance is sound” is an opinion and is not permitted in a checklist.
Each claim carries: claim ID; the binary question; the accepted artifact types and maximum evidence age; the source record (URL, transaction hash, register extract, document hash, source date, access date); the archive ID; the result; analyst sign-off; and reviewer sign-off where §12.3 requires independent review.
For any issued record, the normative checklist must exist in a machine-readable, versioned form. Human-readable tables, engine validation, and record rendering are generated from that same source. If a rendered document and the checklist source diverge, issuance blocks; an analyst may not resolve the conflict by discretion.
7.3 Results
Pass · Fail · Insufficient Evidence · Not Applicable
Fail means tested and the condition is not met. Insufficient Evidence means not testable on available artifacts. These are never conflated: one is a finding about the subject, the other is a finding about the evidence.
7.4 Evidence rules
- Two-source rule. Material non-chain claims require two independent artifacts where practicable. Where not practicable, the record says so.
- Age limit. Evidence older than 21 days at issuance requires refresh or a stated explanation.
- Block height. Every on-chain measurement carries the block height at which it was taken.
- Denominator discipline. Every percentage names its denominator. Supply figures are quoted against total supply, circulating float, and 30-day average volume — never one alone. Whoever picks the denominator picks the conclusion; the Standard picks all three.
- Capture on contact. Artifacts are archived as the analysis occurs, not reconstructed afterwards.
- Exceptions register. Every uncertainty, contradiction, and management representation is logged.
7.5 Claim classes and epistemic register
Claim class determines what the evidence can establish and how the result is written. It is not a confidence scale.
| Class | Object | Permitted register |
|---|---|---|
| C1 | On-chain state | Verified fact at a stated block height |
| C2 | Registry and legal-record fact | Verified fact from a named register as of a stated retrieval date |
| C3 | Market observation | Verified observation from named venues and timestamps; venue honesty remains a limitation |
| C4 | Code structure and review provenance | Verified structural fact; never a claim that code is secure |
| C5 | Documentary content | Verified statement that a document says X; never proof that X is true |
| C6 | Subject or counterparty representation | Attributed representation with corroboration status |
| C7 | Analysis, inference, or opinion | Named desk judgment, never rendered as fact |
A C6 or C7 statement rendered in the factual register is an issuance-blocking defect. Automated analysis, static analysis, decompilation, wallet clustering, or model output may create evidence or a review signal; none creates a verdict by itself.
8 / The six domains
Each domain states what it covers, the mandatory claims, the automatic no-go triggers, and — bindingly — what it does not cover. The exclusions are load-bearing. They are what makes a Verified verdict defensible, and they appear on every record.
Each exclusion is a versioned checklist field, not analyst-written boilerplate. The record renderer must reproduce the exclusions applicable to its checklist and jurisdiction-profile versions without paraphrase.
Claims marked (M) are material: an Insufficient Evidence result on any material claim sends the domain to Declined to Assess (§9).
8.1 Domain 1 — Team & Governance Integrity GOV
Who controls this, are they identifiable, and can any one of them act unilaterally?
| ID | Claim |
|---|---|
| GOV-01 (M) | Each named founder and key person’s legal identity is corroborated by at least one Tier 1 or Tier 2 artifact. |
| GOV-02 (M) | The controlling legal entity is identified in a government company register, with jurisdiction and registration number. |
| GOV-03 (M) | No named principal appears on the OFAC SDN, EU consolidated, or UK OFSI sanctions lists as of the evidence cutoff. |
| GOV-04 | No named principal is subject to a current material enforcement action recorded in a public register. |
| GOV-05 | Prior project history of each named principal is documented, including abandoned or failed protocols. |
| GOV-06 (M) | Treasury-controlling addresses are published, and signer threshold is read on-chain. |
| GOV-07 (M) | Upgrade and admin authority holders are published, and read on-chain. |
| GOV-08 | A dated written governance instrument exists (bylaws, multisig policy, or equivalent). |
| GOV-09 | Key-person dependency is documented: the set of individuals who could unilaterally move treasury or upgrade code. |
Automatic no-go: anonymous or unverifiable controlling team; any sanctions hit; single-key control of material treasury or upgrade authority; documented prior rug pull with no published post-mortem.
Excluded: Mjolnir does not assess competence, character, intent, or the likelihood of future honesty. Identity corroboration is not a background investigation, does not detect an undisclosed alias, and does not establish that a verified identity is the true controller.
8.2 Domain 2 — Technical Control Environment & Review Provenance TEC
Has competent third-party review happened, and does the on-chain control configuration match what is claimed?
This domain is not a security audit and its name says so. The rename from “Technical Security” is deliberate: a solo desk cannot audit code, and a domain that implies it can is a liability, not an asset.
| ID | Claim |
|---|---|
| TEC-01 (M) | Contracts in scope are enumerated by address, with verified source published on a block explorer. |
| TEC-02 (M) | At least one third-party security review covering the material contracts exists and is published. |
| TEC-03 (M) | The reviewing firm is identified, and its independence from the subject is documented. |
| TEC-04 (M) | The review’s stated scope names the contracts or commits reviewed. |
| TEC-05 (M) | The review’s reported critical and high findings are enumerated with current remediation status. |
| TEC-06 (M) | The upgrade mechanism is identified from on-chain state (immutable / proxy / other). |
| TEC-07 (M) | Where upgradeable, admin authority and any timelock delay are read from on-chain state. |
| TEC-08 | Oracle dependencies are enumerated where the protocol reads external price data. |
| TEC-09 | A bug bounty program, where claimed, is corroborated by a live program page stating scope and maximum payout. |
| TEC-10 | Exploit and incident history is documented, with any published post-mortem. |
Automatic no-go: no third-party review of material contracts; unresolved critical finding at evidence cutoff; upgrade authority held by a single externally-owned account with no timelock.
Excluded — read this before relying on a Verified verdict here: Mjolnir does not audit code, does not re-derive the severity of any finding, does not verify that deployed bytecode corresponds to reviewed source beyond the block explorer’s own verification, and does not detect vulnerabilities that the reviewing firm missed. A Verified verdict in this domain states that a review exists, its provenance is documented, and the on-chain control configuration is as claimed. It states nothing about whether the code is secure.
8.3 Domain 3 — Supply, Distribution & Unlock Verification SUP
Does the chain agree with the documents, and who can sell what, when, into what?
| ID | Claim |
|---|---|
| SUP-01 (M) | Total supply is read from the token contract at a stated block height. |
| SUP-02 (M) | Claimed circulating supply is reconciled against on-chain balances at the same block height; any variance is quantified. |
| SUP-03 (M) | Published allocation categories sum to total supply; any gap is quantified. |
| SUP-04 (M) | Vesting and lock contracts, where claimed, are identified on-chain and their release schedule read from contract state. |
| SUP-05 (M) | Where a lock is claimed but not enforced on-chain, its discretionary nature is recorded. |
| SUP-06 (M) | Top-10 holder concentration as a share of circulating supply is measured at a stated block height, with exchange and contract addresses labelled where identifiable. |
| SUP-07 | Addresses disclosed by the subject as team, insider, or treasury are enumerated and balances read. |
| SUP-08 (M) | Unlock events scheduled within the validity window are enumerated with date and size. |
| SUP-09 (M) | Each unlock is quoted against total supply, circulating float, and 30-day average volume on venues meeting VLS-06. |
| SUP-10 | Emission schedule, where any, is read from contract state or documented as off-chain discretionary. |
Automatic no-go: material contradiction between published supply figures and on-chain state; vesting represented as enforced but not on-chain; disclosed insider allocation with no lock, above the concentration threshold in §9.4.
Excluded: concentration is measured across disclosed and labelled addresses only. v1.1 does not perform heuristic wallet clustering. Undisclosed insider wallets that are not labelled will not be detected, and a Verified verdict here does not imply their absence. This limitation appears on every record. (Clustering remains a future-version candidate — Appendix C.)
8.4 Domain 4 — Venue & Liquidity Structure VLS
Where does this trade, how fragile is that, and does reported volume match observable activity?
| ID | Claim |
|---|---|
| VLS-01 (M) | Trading venues are enumerated with each venue’s share of reported 30-day volume. |
| VLS-02 (M) | Decentralised exchange (DEX) pool addresses are identified, and pool depth read on-chain. |
| VLS-03 (M) | The largest single liquidity provider’s share of each material DEX pool is measured on-chain. |
| VLS-04 | The centralised exchange (CEX) versus DEX split of reported volume is quantified. |
| VLS-05 (M) | Reported volume is compared against observable on-chain transfer activity; unexplained divergence is flagged. |
| VLS-06 (M) | Each material venue is classified by whether it publishes proof of reserves and holds any regulatory authorisation. |
| VLS-07 | Market-maker (MM) arrangements, where disclosed, are recorded with counterparty and stated terms. |
| VLS-08 (M) | Bridge dependencies are enumerated where the token exists on more than one chain, with bridge value locked and review status. |
| VLS-09 | 30-day and 90-day trend in DEX pool depth is recorded. |
Automatic no-go: a majority of reported volume on venues with neither proof of reserves nor authorisation; a single liquidity provider supports a majority of material DEX liquidity; material bridge exposure with no third-party review.
Excluded: v1.1 measures observable on-chain liquidity and reported volume. It does not measure centralised order-book depth, does not execute test trades, and does not determine that wash trading has occurred. VLS-05 flags divergence between reported volume and observable activity as an indicator. It is not an accusation, and the record does not phrase it as one. (Order-book depth remains a future-version candidate — Appendix C.)
8.5 Domain 5 — Legal & Regulatory Disclosure LEG
What has the subject disclosed about its legal position, and what do public registers show?
| ID | Claim |
|---|---|
| LEG-01 (M) | The issuing or operating legal entity is identified, with jurisdiction and register extract. |
| LEG-02 | Published terms of service and privacy notice exist, with a readable version or effective date. |
| LEG-03 | Jurisdictional restrictions stated in the terms are recorded. |
| LEG-04 (M) | Whether the subject has obtained external legal analysis of token classification is recorded. Where provided, its existence, author, date, and stated scope are documented. |
| LEG-05 (M) | Markets in Crypto-Assets Regulation (MiCA) relevance is recorded: whether a white paper has been published, authorisation sought, or a basis stated for non-application. |
| LEG-06 (M) | Public regulatory registers and enforcement databases in the subject’s stated jurisdictions are searched; results recorded. |
| LEG-07 | Material adverse legal proceedings disclosed publicly are recorded. |
| LEG-08 | Where the model handles fiat on- or off-ramps, the anti-money laundering / know your customer (AML/KYC) provider or licence is recorded. |
Automatic no-go: active material enforcement action; an applicable, dated, counsel-reviewed jurisdiction profile identifies a registration, authorisation, or disclosure requirement and the evidence file contains neither the evidence required by that profile nor documented external legal analysis supporting non-application; no external legal analysis exists where classification is materially ambiguous and the token has been publicly distributed.
Excluded — critical: Mjolnir does not provide legal advice and does not opine on whether any token is a security in any jurisdiction. This domain documents what the subject has disclosed and what public registers show. A Verified verdict means the disclosure exists, is dated, and is internally consistent. It does not mean the subject’s legal position is correct, and it is not a defence to anything.
8.6 Domain 6 — Custody & Operational Continuity CUS
Can the treasury be moved by one person, and does this survive contact with stress?
| ID | Claim |
|---|---|
| CUS-01 (M) | Treasury addresses are published, and balances read on-chain at a stated block height. |
| CUS-02 (M) | The custody model is identified (self-custody multisig / qualified custodian / hybrid) and corroborated. |
| CUS-03 (M) | Where a qualified custodian is claimed, the custodian is named and the claim corroborated by a Tier 1 or Tier 2 artifact. |
| CUS-04 (M) | Multisig threshold and signer count are read on-chain for each material treasury address. |
| CUS-05 | Signer diversity is recorded: whether signers are documented as distinct individuals or entities. |
| CUS-06 | A dated written key-management or disaster-recovery policy exists. |
| CUS-07 | Operational continuity dependencies are enumerated (hosting, validators, relayers, key vendors). |
| CUS-08 | Insurance, where claimed, is corroborated by certificate or broker confirmation; scope and limits recorded exactly as documented. |
| CUS-09 | Incident history is documented, with disclosure quality and remediation evidence. |
Automatic no-go: single-key custody of material treasury; claimed custodian relationship that cannot be corroborated; claimed insurance that cannot be corroborated; material incident with no disclosure.
Excluded: Mjolnir does not verify that a custodian’s internal controls are effective, does not test disaster recovery, and does not confirm that any insurance policy would pay any given claim. Where insurance is recorded, the record states the documented limits and nothing beyond them.
9 / Verdict mapping
Mapping is mechanical. The analyst does not choose the verdict; the claim results determine it.
9.1 Verified — every mandatory claim returns Pass, every non-mandatory claim returns Pass or Not Applicable, and no automatic no-go is triggered.
9.2 Conditional — no material claim returns Insufficient Evidence, and at least one of:
- any claim returns
Fail; - an automatic no-go is triggered;
- any non-material claim returns
Insufficient Evidence; - a §9.4 threshold is breached.
The record states the claim ID, the gap, the evidence that would close it, and the review date. One Conditional line per triggering claim. No summarising.
9.3 Declined to Assess — any of:
- any material (M) claim returns
Insufficient Evidence; - a majority of the domain’s claims return
Insufficient Evidence; - the subject withheld access necessary to test material claims (recorded as such, neutrally).
9.4 Named thresholds (breach → Conditional, not automatic no-go):
| Threshold | Value |
|---|---|
| Top-10 concentration of circulating supply | > 50% |
| Single unlock as share of 30-day average volume | > 100% |
| Single unlock as share of circulating float | > 10% |
| Single DEX liquidity provider share of a material pool | > 40% |
| Reported volume divergence from observable activity | > 3× |
Thresholds are published so a subject can know where the line is and an allocator can disagree with where we drew it. Both are features.
10 / The registry record
Stable identifier: /standard/MJ-STD-2026-0001. Serials are sequential, permanent, never reissued.
Required fields — a record missing any of these is not issued:
| Field | Content |
|---|---|
| Subject | Name; legal entity where identified; contract addresses in scope; network(s) |
| Commissioning party | Named where contractually permitted; otherwise category and the reason for anonymity |
| Lane | A (registry assessments only) |
| Standard | Exact version, publication date, changelog link |
| Verdicts | Six domain verdicts with the rationale line for each. No aggregate (§6.3). |
| Scope | Claims examined, assessment period, evidence cutoff, block height, exclusions, material limitations |
| Dates | Issued, valid-until, next scheduled review |
| People and review status | Analyst of record; whether independent review occurred; reviewer of record where §12.3 required one |
| Status | Active / Under Review / Expired / Revoked / Superseded, with full history |
| Reliance notice | Appendix A wording, verbatim |
The record carries the §8 exclusions for every domain assessed. They are not a footnote and are not collapsed behind a link.
11 / Expiry and monitoring
11.1 Default validity: 180 days. Shorter where a material unlock, attestation cadence, or known event falls inside the window. An assessment is a photograph. A record with no expiry is a claim about the present tense that nobody checked.
11.2 Triggers. On-chain and market alerts are configured for every assessed address at issuance. An alert never changes a verdict; it opens a documented review.
| Trigger | Action | Target |
|---|---|---|
| Material exploit or hack | Status → Under Review; open incident assessment | 24 hours |
| Regulatory action | Reassess LEG; record status change | 72 hours |
| Material treasury movement (> 20%) | Reassess CUS; investigate explanation | 48 hours |
| Contract upgrade or admin change | Reassess TEC | 7 days |
| Founder or CTO departure | Reassess GOV | 7 days |
| Major unlock or concentration shift | Refresh SUP and VLS | Before event |
| Scheduled expiry | Reassessment, or automatic Expired | No exceptions |
11.3 Under Review is set publicly and immediately — before any conclusion is reached, not after. A desk that waits until it knows the answer before telling the market it is looking has already chosen the subject over the reader.
12 / Quality control
12.1 Intake and independence gate
- Conflict check. No assessment where Mjolnir, its staff, or any reviewer holds an undisclosed financial, advisory, token, or family interest in the subject or commissioning party. A reviewer does not cure a prohibited conflict.
- Screening. Sanctions, adverse media, engagement legitimacy, lawful basis to receive information.
- Buyer legitimacy. A Lane A commission must trace to a real allocation decision. A subject routing payment through a friendly fund is a Lane B engagement misrepresented, and is refused.
- Scope letter. Subject, chains, contracts, evidence cutoff, domains, exclusions, deliverables, expiry — fixed in writing before work starts.
- Assessment fee firewall. Fees for a Lane A registry assessment are fixed or staged and may not depend on any verdict, price, listing, financing, or subject outcome (§5.4).
- Capacity. No engagement is accepted unless the analyst can complete it inside the scope letter’s dates and, where §12.3 requires independent review, a conflict-cleared reviewer can do the same.
12.2 Lead analysis
Locked Standard and checklist version. No undocumented criteria. Artifacts captured on contact. Two-source rule on material non-chain claims. Time-sensitive evidence refreshed within 21 days of issuance. Every uncertainty and management representation logged to the exceptions register.
12.3 Conflict-gated independent review
Every assessment is signed by the analyst of record. Independent review is mandatory where the subject has previously received issuer-side advisory or Capital Solutions work from Mjolnir, or where another disclosed relationship creates a reviewable material conflict under the engagement terms. A prohibited conflict is refused; it is not cured by adding a reviewer.
Where independent review is required, no assessment is issued until a conflict-cleared reviewer has completed the following procedure and signed the record. There is no staffing exception in a conflict case.
- The reviewer has no sales ownership, no outcome-linked compensation, and no access to the analyst’s verdicts until forming an independent view from the evidence pack.
- The reviewer receives the completed checklist with artifacts and the scope letter — not the analyst’s conclusions.
- The reviewer re-performs a risk-based sample plus every material and every borderline claim.
- The reviewer tests the chain: artifact → claim result → domain verdict → public wording.
- Disagreement is recorded, escalated, and resolved on the record. It is never silently overwritten. Unresolved material disagreement produces Conditional or Declined — not forced consensus.
- The analyst and reviewer sign the issuance certificate. Both names appear on the record.
Where independent review is not required, the analyst of record is solely accountable for the assessment. The registry record states that no independent reviewer participated, and neither the record nor any related communication may describe the assessment as independently reviewed.
12.3.1 Why review cannot be deferred in a conflict case. §14.3 sets the advisory cooling-off at 6 months rather than 18. That decision is defensible only because a conflict-cleared reviewer remains between prior project-side work and the later assessment. A party the desk advised in March can be assessed in September, but the September record cannot issue unless a second person who never saw the March work and whose pay does not depend on the answer has completed the review.
A single analyst cannot both advise and later issue the assessment without that control. The six-month interval and solo issuance on a previously advised subject are jointly indefensible. This Standard permits analyst-only issuance only where the conflict gate does not require independent review, and it makes that review status public.
12.4 Pre-issuance challenge session
Documented in working papers.
- Each Verified domain: what evidence or scenario would move this to Conditional?
- Each Conditional domain: what precise remediation, by when, verified how?
- Each Declined domain: which sources were searched, and why is the missing evidence not obtainable?
- Whole record: prohibited language (Appendix B), scope creep, stale data, unsupported certainty, contradictions between domains.
12.5 Named error modes and their controls
| Error mode | Control |
|---|---|
| Recency bias | Minimum 12-month on-chain history before Verified in SUP |
| Presentation bias — polished decks create false confidence | Tier 3 is never sole support where an independent source exists (§7.1) |
| Commission pressure drift | Named analyst accountability; conflict-gated independent review; fee firewall |
| Scope creep | The checklist is fixed. Anything outside it is out of scope, stated as such. |
| Stale evidence | 21-day rule (§7.4) |
| The “good enough” trap | Verified requires all claims Pass. One unevidenced claim is Conditional at best. |
| Capability laundering | A gap in the desk’s tooling is never recorded as a gap in the subject’s evidence (§12.6) |
12.6 Two honesties this document commits to
Accuracy is not a guarantee. No process detects a competent liar or predicts a future decision. The defensible promise is narrower and it is the only one made here: a disciplined, repeatable, reviewable process — independently reviewed where §12.3 requires it — that identifies, documents, escalates, and corrects uncertainty. Mjolnir will be wrong. The Standard is designed to make being wrong survivable and visible, not impossible.
Capability is not the subject’s fault. Where the desk lacks the tooling to test something, that is a scope exclusion under §8 — published, and identical on every record. It is never recorded as Insufficient Evidence against the subject. This matters because the published statistic (§6.5) is the desk’s most valuable asset, and it is only meaningful if a domain that fails to clear reflects the subject’s evidence rather than the desk’s budget. A decline rate that secretly measures our own tooling gap is a lie told with a number.
13 / Error and correction
- On identifying an error, omission, or material contradiction: preserve evidence, open an incident file.
- Within 24 hours: status → Under Review. If the available evidence already establishes that the record is invalid, status may be set directly to Revoked; Superseded is used only where a later assessment exists. History is never quietly edited.
- Publish a permanent correction statement: what changed, why, what was previously stated, what remains unknown.
- Within 30 days: post-mortem — root cause, the control that failed, the Standard or checklist change that addresses it, owner, completion date. Public where material.
- Track the corrective action to closure and test that the new control works.
The error is not the problem. Silence is. A visible correction ledger is the most credible object the desk will ever own, and it costs nothing but ego.
14 / Independence and conflicts
14.1 Assessment fee firewall. Under §12.1, no fee for a Lane A registry assessment depends on any verdict or subject outcome.
14.2 Lane separation. Where the desk has provided issuer-side advisory or Capital Solutions work to a subject, the reviewer of record on any later Lane A assessment of that subject must have had no involvement in that work, no sight of its deliverables, and no compensation linked to it. This is mandatory and admits no staffing exception in a conflict case: the reviewer is the independence mechanism, and a reviewer who already saw the prior work is re-reading the desk’s own homework.
Project-side working papers are quarantined from Lane A. The Lane A analysis starts from evidence and the published checklist, never from the earlier advisory or Capital Solutions deliverable. An assessment that begins by asking “did they fix the things we told them to fix” is a re-run of the desk’s own work, not an independent test of the subject’s claims.
14.3 Cooling-off. A party the desk has advised is ineligible for Lane A assessment for 6 months from the close of the advisory engagement. Published policy, not case-by-case judgment.
Every Lane A record for a previously-advised subject discloses, on the public record:
Mjolnir provided [issuer-side advisory / Capital Solutions work] to this subject, closing [date]. The reviewer of record for this assessment had no involvement in that engagement and no sight of its deliverables. The analyst of record [did / did not] participate in it.
An independence register logs every advisory and material commercial contact. Without the register the wall is unenforceable, and an unenforceable wall is worse than none, because it is a claim we cannot support.
What the softened wall does not touch. §2.3 is unaffected. A subject still cannot commission its own Lane A assessment at any price, through any intermediary, at any remove. Shortening the interval between advisory and assessment changes when a buy-side party may commission work; it does not create a path by which a subject commissions work about itself. That distinction is the load-bearing one, and it does not bend.
14.4 Disclosure. Every record names its commissioning party where contractually permitted; otherwise it states the commissioning category and the reason for anonymity. Where a commercial relationship anywhere in the desk intersects a record, the record says so.
14.5 Transparency. Quarterly: aggregate verdict distribution, clearance rate, evidence-gap frequencies, correction count, review-participation rate, reviewer disagreement rate where review applied, and median completion time. Annually: the same, plus methodology changes and their rationale. Never any confidential client data.
14.6 The Standard is not for sale. No client, at any price, can alter a criterion, a threshold, or a published record.
15 / Change control
- Versioned.
MJ-STD-v{major}.{minor}. - Every record stamps four separate objects: Standard version, checklist version, engine version, and each applicable jurisdiction-profile version.
- The Standard contains the constitutional and methodological rules. The machine-readable checklist contains claim-level questions and evidence requirements. The engine implements them but may not modify them. Jurisdiction profiles contain dated, counsel-reviewed disclosure and register checks activated only by the subject’s operations or market exposure.
- Material changes: 30 days’ public notice before taking effect.
- Old versions stay published, permanently. A record assessed under v1.0 is forever a v1.0 record and is never retroactively re-graded.
- Changes to §2 constitutional principles are a major version.
- Public consultation before any minor version that changes a threshold or a no-go trigger.
- A jurisdiction-profile update does not silently amend the global Standard. It carries its own effective date, authority, applicability rule, and changelog.
- Every change carries its rationale in the changelog. “Improved wording” is not a rationale.
16 / Conditions precedent to issuance
No registry assessment issues unless every applicable condition below is satisfied. These are conjunctive controls. Their inclusion here does not publish Mjolnir’s internal implementation status.
- The governing Standard, machine-readable checklist, change policy, and applicable jurisdiction profiles are versioned and fixed before scope lock.
- The registry can display serial, scope, six domain verdicts, expiry, status history, correction history, and the Appendix A notice.
- Every claim in §8 has an applicability rule, evidence rule, age limit, archive path, materiality designation, result mapping, and published exclusion.
- The evidence archive, exceptions register, and independence register preserve the required provenance and access history.
- Where §12.3 requires independent review, a reviewer is engaged, conflict-cleared, and able to complete it within the scope dates.
- The contracting entity, governing law, engagement terms, reliance limits, information warranty, liability allocation, and no-fiduciary-duty language have been reviewed by counsel qualified for the governing law and the markets in which the service is offered.
- Privacy, data-protection, and retention policies apply. Retention is no shorter than the applicable long-stop limitation period confirmed by counsel.
- Appendix B is enforced across records, memos, site copy, and communications.
- Monitoring, escalation, amendment, revocation, and correction procedures have named owners and tested paths.
- Professional indemnity / errors and omissions treatment is documented in the legal and risk framework.
- An end-to-end dry run has exercised assessment, review, issuance blocking, revocation, and correction without creating a public record.
17 / Decisions of record
Founding choices, recorded with the rationale and the cost. §15 requires that every change carry its reasoning; the same discipline applies to the decisions that shaped v1.0 and v1.1. A later reader is entitled to see what was traded away.
17.1 Legal perimeter — jurisdiction-neutral core, scoped profiles. Resolved 25 July 2026. The Standard does not select, recommend, or publish candidate incorporation jurisdictions. Entity formation, governing law, tax residence, licences, insurance, vendors, and counsel appointments are operational and legal matters, not assessment criteria.
Before issuance, qualified counsel defines the service perimeter under the governing law and in every market where the service is offered. Subject-facing regulatory checks are activated through dated jurisdiction profiles only when the subject’s operations, solicitation, users, or transaction rails make that profile relevant. Mjolnir’s physical location alone does not activate a subject profile.
This separation prevents a local operating decision from becoming a universal assessment rule. It also prevents an automated register or disclosure check from being presented as a legal conclusion.
17.2 Advisory cooling-off — 6 months, conflict-reviewer guarded. Resolved 17 July 2026; amended 12 August 2026. The interval between project-side work and a Lane A assessment of the same subject is 6 months, not 18.
The trade is explicit and is stated here rather than discovered later. A shorter interval preserves a commercial path from project-side work into the market. The cost is that the independence guarantee moves off time and onto two other things in that conflict case: the independent reviewer (§12.3.1) and disclosure on the public record (§14.3). §2.3 is untouched — a subject still cannot commission work about itself, and that is the load-bearing rule.
An eighteen-month wall is a stronger claim than a six-month wall plus a reviewer, and a serious critic will say so. For a previously advised subject, the reviewer must be real, named on the record, unconnected to the project-side work, and paid the same regardless of the verdict. If that ever stops being true, the conflicted record does not issue. Assessments outside the conflict gate may be signed by the analyst alone, but their review status is disclosed and they are never described as independently reviewed.
Appendix A — Core public wording
Verbatim on every registry record. Counsel qualified for the governing law approves this wording as a condition precedent under §16.
This registry record documents a time-bounded assessment of specified factual claims against the Mjolnir Standard [version], based on evidence available as of [date] at block height [height]. It is not an audit, a legal opinion, investment research, an investment recommendation, a credit rating, a guarantee of future conduct, or an assurance that loss, fraud, technical failure, or regulatory action will not occur. It states no view on the merits of any asset. Public users receive no reliance rights. This record must be read together with its scope, exclusions, limitations, evidence cutoff, expiry date, and status.
Appendix B — Prohibited language
These words never describe Mjolnir work, in any record, memo, page, deck, post, or conversation.
Never: audit · certified · certification · approved · endorsed · safe · secure · fraud-free · clean · guaranteed · assured · investment grade · rated · score · grade · tier · buy · sell · hold · undervalued · recommend · due-diligenced · vetted · trusted · trustworthy
Instead: assessment · evidence review · registry record · as-of-date findings · verdict (per domain, of evidence, never of a subject) · assessed against Standard v[x] · claims supported by archived evidence as of [date]
Never construct: “Mjolnir Verified” as a project-level property. The domain verdict is a statement about claims and evidence. It is never a statement about a subject. “GOV: Verified” is correct. “Cairn is Mjolnir Verified” is a defect, and if it appears in the market unchallenged it is the desk’s failure to correct it.
Also prohibited: any statement that Mjolnir holds regulatory approval, institutional endorsement, or insurance backing, unless objectively true and documented.
Appendix C — Capability boundary: future-version candidates
These capabilities may enter a later checklist only after the stated admission requirement is met, tested, and versioned. Until then they remain explicit exclusions. This table describes the methodological threshold for adoption; it does not report internal implementation or procurement status.
| Capability | Domain | Admission requirement |
|---|---|---|
| Heuristic wallet clustering to detect undisclosed insider addresses | SUP | Validated chain-specific methodology, ground-truth calibration, false-attribution controls, and published exclusions |
| Centralised order-book depth and executable-liquidity measurement | VLS | Reproducible market-data access, venue coverage rule, and timestamped execution-cost methodology |
| Bytecode-to-source correspondence beyond explorer verification | TEC | Reproducible exact-match method with known-answer fixtures and explicit treatment of proxies, libraries, and immutables |
| Independent severity re-derivation of audit findings | TEC | Qualified security review, documented threat model, and separation from automated tool output |
| Wash-trading determination (as distinct from divergence flagging) | VLS | Validated attribution methodology, market coverage, and counsel-reviewed publication language |
| RWA addendum: title, custody chain, redemption, bankruptcy remoteness (8 domains) | New | Separate scope, specialist legal review, evidence taxonomy, and versioned domain rules |
Appendix D — Changelog
| Version | Date | Change | Rationale |
|---|---|---|---|
| 1.0-draft | 2026-07-17 | Initial working draft. | — |
| 1.0-draft | 2026-07-17 | Advisory cooling-off reduced 18 → 6 months; reviewer separation and public disclosure made mandatory (§14.2, §14.3, §17.2). | Preserves a commercial path from Lane B Readiness into the market. Independence guarantee moves from time onto the independent reviewer and onto disclosure. §2.3 untouched. |
| 1.0-draft | 2026-07-17 | §12.3.1 added: four-eyes review is non-deferrable. | Consequence of §17.2. Once the interval shortens, the reviewer is the wall. Solo issuance and a 6-month interval are jointly indefensible. |
| 1.0-draft | 2026-07-25 | Claim classes, machine-readable checklist authority, scoped jurisdiction profiles, and conditions precedent added. Internal readiness and candidate-jurisdiction disclosures removed from the public methodology. | The Standard must disclose the rule and its limitations, not narrate incorporation, staffing, or implementation progress. Jurisdiction applies through counsel-reviewed profiles triggered by actual exposure, not by the desk’s location. |
| 1.1 | 2026-08-12 | Universal four-eyes review replaced with conflict-gated independent review; review status made mandatory on every record; reviewer fields and statistics made conditional. Effective 2026-09-11. | Keeps the control executable at principal-led launch and mandatory where prior project-side work creates a conflict. The trade-off is explicit: non-conflict assessments may be issued by the analyst of record alone, and every such record must disclose that no independent reviewer participated. |
Informational only — not investment advice, an offer, or a solicitation. This document defines a methodology and confers no rights. Assessments issued under it grant no reliance to public readers; reliance is defined by contract with the commissioning party.
Standard owner: Mjolnir Capital. Analyst and reviewer identities are stated on each registry record where applicable.
Informational only — not investment advice, an offer, or a solicitation.