Allowed outcomes
Every failure must land on one of these public outcomes. Anything else is an incomplete product state.
Awaiting live data
Awaiting live data
Awaiting live data
InfraVerifiable Storage
Wallet, purchase, storage, proof, retrieval, contracts, and status are kept as separate product lanes.
Every failure must land on one of these public outcomes. Anything else is an incomplete product state.
Awaiting live data
Awaiting live data
Awaiting live data
The matrix is intentionally concrete: wrong signer is not the same as wrong chain, and hot-provider failure is not the same as cold-retention delay.
Awaiting live data
Failure receipts explain what happened, what can be retried, and what cannot be inferred from the failure.
Awaiting live data
A visible failure is healthier than a hidden success claim. Infra should say stale, refused, queued, quarantined, downgraded, repairing, or terminal when that is the real state.
Replay and duplicate evidence links to canonical state instead of creating duplicate payment, work, or storage.
Hot provider failure, cold restore delay, provider proof mismatch, repair exhaustion, and capacity exhaustion stay separate.
Website stale head or public stats conflict becomes stale or refused public state, not chain truth.
QUAD/Core, Bridge, and Liquid outages queue, retry, or stale-label their paths without inventing sibling-chain facts.