One canonical engine plan
The Community engine validates compatibility, paths, automatic mode, RAM, and scratch headroom. Guard consumes that exact plan instead of reimplementing proof-critical decisions.
Guard is the foreground supervisor around the open engine: it enforces the exact release package, manages signals and checkpoint lifecycle, produces support-safe diagnostics, activates qualified releases, and applies CI resource policy. The Guard subscription is withdrawn and is no longer offered for purchase; TinyZKP is moving to a metered proving utility priced per unit of trace, with a free resource estimator that covers Goldilocks, BabyBear, KoalaBear, and Mersenne31 configurations.
The Community engine validates compatibility, paths, automatic mode, RAM, and scratch headroom. Guard consumes that exact plan instead of reimplementing proof-critical decisions.
Run the engine as a foreground child, preserve atomic state on interruption, prevent orphan work, and bind resume to the exact owning release.
Emit a versioned result for schedulers, JSON Lines progress for operators, and a redacted SupportReportV1 for defect reporting.
The MIT engine owns AIR evaluation, commitments, FRI, proof assembly, verification, resource estimation, conventional and bounded execution, and public schemas. Guard calls that engine through versioned file contracts; it does not change proof semantics.
| Surface | Community engine | Guard supervisor |
|---|---|---|
| Proof behavior | Open and MIT | Calls the exact released engine |
| Doctor and compatibility | Included | Consumes the canonical plan |
| Automatic mode and resource preflight | Included | Enforces the engine result |
| Checkpoint primitives | Included | Supervises lifecycle and signals |
| Support-safe diagnostic bundle | Not a DoctorReport | SupportReportV1 |
| CI regression policy | Machine reports | Operational check |
| Hosted service | None | None |
Each exact Guard release is activated once. Successful activation writes a release-scoped local entitlement. Proving, resume, verification, and continued use of that activated release make no license-network request. A current subscription is required only to activate a newer release.
Release-index limit: superseded and withdrawn states control ordinary distribution, recommendation, and support. An already-downloaded activated copy makes no channel request, cannot learn either state, and remains locally usable; this is not a technical resume-only restriction. V1 has no release-specific denylist, so an already-downloaded unactivated copy may still activate when Lemon Squeezy reports an active subscription.
No TinyZKP worker fleet, queue, database, metering, artifact upload, account dashboard, or pager sits in the proof path.
No custom AIR work, private branches, service-bureau rights, onboarding calls, SLA, SSO, or architecture consulting is included.