Fairness
What we prove, how, and where trust is still required.
The protocol (AERQIX-M4 v1)
- Snapshot: at close, accepted entries are sorted by entry ID; each becomes a Merkle leaf SHA256("AERQIX-M4:entry:" + entryId + ":" + userId + ":" + drawId + ":" + passUnitId + ":" + createdAt). The snapshot hash and Merkle root are stored.
- Commitment: after the snapshot, a 32-byte server seed is generated and only SHA256("AERQIX-M4:server-seed:" + seed) is stored; the seed is revealed in the proof bundle after settlement.
- Randomness: one randomness reference and round are pinned in the commitment. Exactly one value is accepted for it; a conflicting second value is rejected.
- Selection: trigger = uniformBelow(SHA256("AERQIX-M4:trigger:" + R), 100). Jackpot winner and weekly winners use domain-separated SHA-256 streams with 256-bit rejection sampling — never a plain modulo.
- Package: all inputs and outputs are hashed into a package hash. Verification recomputes every step.
What you can verify yourself
- That the seed matches the commitment.
- That the published entry list produces the published snapshot hash and Merkle root, and that your entry is included.
- That the jackpot trigger, the jackpot winner, every weekly prize slot and every winner follow from the published randomness.
- That nothing in the package was edited after it was hashed.
Where trust is still required — honestly
- Randomness source: this demo uses a public deterministic fixture (SHA-256 of a fixed prefix and the draw ID). It was predictable in advance and proves only the computation. A verifiable public randomness source (drand) is planned; until it is integrated and its signatures are verified, live draws must not run.
- Completeness: the Merkle root proves an entry is in the list, not that no accepted entry was left out. Completeness is reconciled against the operator ledger, which is not public.
- Payout: proofs show who won; payouts are tracked in the operator ledger and shown in each winner’s account.
Tools
- Browser verifier on the Verify page — it downloads the bundle and recomputes locally.
- Command line: fortulox-verify https://fortulox.com/api/v1/public/draws/DRW-0-W4/proof
- Proof bundles are plain JSON and can be checked with any SHA-256 implementation.