01
Runtime
Live health and discovery surfaces are publicly inspectable.
The production API answers an unauthenticated health check, and the discovery manifest states what the system claims to support before anyone authenticates.
Operational trust posture
Averray already has concrete operational trust anchors: deploy verification, multisig setup, public schemas, and an audit handoff package designed for external review.
Where trust comes from
Trust should be verifiable from public evidence, not internal reassurance. The strongest thing this page can do is reduce ambiguity.
01
Runtime
The production API answers an unauthenticated health check, and the discovery manifest states what the system claims to support before anyone authenticates.
02
Operations
Deployment verification, key playbooks, and the reviewer package are written down as procedure rather than reconstructed per release.
03
Outputs
Identity outputs stay schema-backed and readable from the open web, so a counterparty can check them without an account.
Operational controls
A healthy runtime, explicit operational controls, and schema-backed outputs give counterparties something concrete to inspect.
01
Ops
Deployment verification asserts bytecode, ownership, pauser wiring, verifier/arbitrator/service operators, approved assets, and pause state before promotion.
02
Keys
Hot / warm / cold key generation, SS58-to-EVM mapping for Polkadot Hub, testnet rehearsal, rotate-pauser, and lost-key recovery are documented.
03
Reviewability
Scope, trust model, adversary model, invariants, known quirks, deployment parameters, and expected deliverables are all gathered in one place.
04
External review
An independent external auditor examined the core escrow, settlement, and signing surfaces in mid-2026 and granted conditional mainnet approval; an independent re-verification of the remediations followed and is published in the repository. This is a point-in-time review, not a blanket endorsement — the package above exists so the next reviewer starts from the current surface.
Trust model
Counterparty checklist: open the health endpoint and verify auth mode plus service state, inspect the discovery manifest and onboarding surfaces directly, and check that public identity outputs remain reachable and schema-backed.
Public by design
Controlled by role
Verified after change
Signals you can verify now
Health
The live health endpoint exposes the current service posture, auth mode, and key backend component status for the production API.
Discovery
The public manifest and onboarding JSON show what the system claims to support before anyone has to authenticate or take an operator on trust.
Identity outputs
Hosted schema docs, example assets, and live profile reads make it possible to inspect what the system emits, not just what it says it emits.
Provider operations
Averray pulls candidate work from a fixed set of public sources. This lists each one, the mode it is running in, how it last looked, and whether it currently has capacity. Errors and skipped items are summarised here; the operator app shows the full per-row detail.
Loading provider operations… · raw JSON:api.averray.com/status/providers
Live status
Fetching the latest provider snapshot from api.averray.com/status/providers…
Operational checklist
averray.com and api.averray.com.Verification path
That sequence tells you whether the system is up, what it claims to support, and whether its public identity layer is actually inspectable by outside parties.