Prove it's safeKeep the far side
Tidelock is a private audit for contracts on Robinhood Chain. An AI keeper reads your source once on zero-retention routes, runs eight fixed checks and locks the answers to the code hash. The near side is public. The far side never turns.
One reader goes inNothing comes back out
The keeper only reaches models over zero-retention routes. Nothing it sends or gets back is logged, so your source lives in exactly one place, for exactly one request.
The chain tonight
Two sides of one contract
The Moon shows Earth one face and keeps the other. A lock does the same: everything a holder needs faces the chain, and the code itself stays on the side nobody sees.
The near side
- The code hash
- keccak256 of the deployed bytecode, which anyone can recompute straight from the chain.
- Eight answers
- Each one passes, fails or is skipped, and says why in a line.
- The keeper's review
- A signed write-up of what the contract does and who controls what. It explains the code without ever reproducing it.
- The stake
- $TIDE locked behind this lock by the keepers who vouch for it.
The far side
- The source
- Opened once, by one keeper, through read-only access, then wiped.
- The repo
- Its name, its history, every other branch. The lock keeps a commit hash, never a link.
- You
- You never sign up. The paying wallet is all anyone learns about you, and a brand-new one works.
The source stops at the keeper and is deleted there. Only the near side crosses to the chain.
The keeper at work
A demo keeper pressing the launches people are buying on Pons right now: verified source, compiled in your tab, matched byte for byte, eight checks and the sell path on the live chain. Every line is real. It writes nothing, because $TIDE is not live yet.
reading the latest Pons buys…Read the near side of any contract
Drop in any Robinhood Chain address. Your browser fetches the source, builds it, confirms it equals the deployed code byte by byte and runs all eight tests, including a live round trip. Add a model key to get a written review as well.
When a test can't reach a verdict, it fails and tells you why. A pass only means these eight tests found nothing; it is not a promise that the code is safe.
Tonight on Pons
Pons launches people are buying right now on Robinhood Chain, read in your tab. New ones join the list as they are bought. Each has its own code hash, because a token's name and settings live in its bytes, but most are built from one template: the same opcodes with different constants.
| Token | Code hash | Checks | Score | ||
|---|---|---|---|---|---|
| Reading the last hour of Pons buys… | |||||
Eight checks, eight phases
Every test answers yes or no, by the same rule for every contract. The answers light the Moon one phase at a time, and eight passes make it full.
Outside the lock's view
- StateWho controls this deployment, and what it was set up with at launch
- LiquidityWhere the pool sits, how deep it is, and who could drain it
- HoldersA token can pass every test while one wallet owns nearly all of it
- Everything elseEight tests set a minimum bar, they are not the final word
How a lock is made
Grant
Read-only access to a single repo, pinned to one commit. That is all it needs.
Match
The keeper builds it and compares the result with the deployed code, byte by byte. If they differ, there is no lock.
Check
The compiled contract goes through the same eight tests, and every answer comes with a one-line reason.
Forget
The keeper signs the hash, the answers and the review as one, records the lock on Robinhood Chain and wipes the source.
Three ways to trust a contract
| Audit firm | Verified source | Tidelock lock | |
|---|---|---|---|
| Source made public | Usually | Always | Never |
| Same checks for every contract | No | No checks at all | Eight, fixed |
| Bound to the exact bytes | A commit in a PDF | Yes | The code hash |
| Someone loses money if wrong | Reputation | Nobody | Staked $TIDE |
| Readable by another contract | No | No | Yes, on chain |
| Time to a result | Weeks | Minutes | One review |
Keepers stand behind every lock
Every lock is paid in $TIDE. Holders who stake behind a lock earn from the fees on that code, and lose part of the stake if a check they vouched for was wrong.
Stake
Lock $TIDE behind code you trust. Every review fee paid on that code hash is split across its stake.
Cover
If a test passed and turns out wrong, the cover pool pays the claim and the stake on that lock is slashed.
Creator
Like every Pons token, $TIDE pays its creator 70% of the 1% trading fee. That share runs the keeper until fees can.
Keeper calculator
Bring your own model key
Add an Anthropic key beside the address. The model goes through the project's own source once and writes its review without reproducing a single line. The key covers that one request, is never saved, and the lock notes which model wrote it.
Before you trust a lock
What does a lock prove?
That this exact bytecode went through eight fixed tests and what each one said, that a keeper read the source and signed a summary of it, and how much $TIDE is staked on it. A lock is not a verdict that the code is good, and it is blind to anything the tests don't cover.
What is the Tidelock Score?
A single number out of 100. Each passing test adds 7.5 (60 in all), the code analysis adds up to 25 (owner-only functions, addresses that can be changed, risky primitives, a well-known base) and the review's risk level adds up to 15. Anything that did not run is taken out of the total instead of scored as zero, and the score tells you what it was computed on. 70 and up reads lower risk, 35 to 69 caution, below 35 high risk.
Who reads my source?
Verified source is public already, and your tab reads it from the chain explorer. Your own files are compiled in this tab and never uploaded. Only the review sends the project's own files out: to the model, for one call, on the key you paste. Nothing from the source reaches the chain.
What works today?
All of a lock except putting it on chain: your browser fetches or accepts the source, builds it, confirms a byte-for-byte match, runs the eight tests (07 against the live chain), scores the code and, if you add a key, gets the review written. You can sign the draft with your wallet. The on-chain registry, keeper stakes and the cover pool switch on once $TIDE launches on Pons.
Why lock the code instead of the address?
A lock belongs to the code, not to an address. Any deployment with the identical runtime carries it; change a single byte and it is gone. Two Pons launches cut from the same template still need two locks, because their constants, and so their hashes, differ.
How do keepers earn?
From review fees on code they stake behind: 60% of each fee is split by stake. It is not a promise of income. If nobody pays for locks, there is nothing to split.
Is $TIDE live?
Not yet. $TIDE launches on Pons, Robinhood Chain. The only contract address will be posted on our X account, and we will never DM you first.
Tidelock