Security
System integrity and verification architecture for ACI Risk Indicators
No AI-generated narrative. No black-box computation. Every published ACI Risk Indicator is deterministic, versioned, and reproducible from documented inputs and framework version.
Governance and approval
Methodology governance
- Risk Indicators are written to an append-only record
- Methodology changes require Chief Risk Officer sign-off
- CRO certification of individual indicators is being introduced; none is certified yet
- Rejected outputs are logged with reason and not published
Evidence integrity
Each Risk Indicator decomposes into criterion-level values under ACI Framework v1.0. Each criterion is supported by evidence artifacts — provider, criterion, source reference, observation date, and recorded value. The evidence chain is versioned, exportable, and tied to the active methodology version.
Data sources
Market data
- Deribit DVOL API — implied volatility surface for BTC and ETH options. Commercial use subject to written confirmation per ACI Data Sourcing and Licensing Policy.
- CoinGecko — spot prices and historical price series for digital assets.
On-chain data
- Bitcoin block headers — for OpenTimestamps anchor verification.
- Provider attestations — proof-of-reserves and protocol audit posts.
Provider disclosures
- Audited financial statements
- Regulatory filings and compliance registrations
- Provider-issued public disclosures
Data refresh and fallback
Source refresh cadence is defined in the platform's source registry. When a source is unavailable, the most recent stored value is used and a staleness flag is applied to all affected Risk Indicators.