// MAINNET ROADMAP

Devnet today.
Mainnet next.

Entros is live on devnet: three programs, a shipped SDK, and a private validation service with published, scoped red-team results. T5 and population-level uniqueness evidence remain open. The token funds the path to mainnet.

  1. Protocol hardening

    Now
  2. Trusted setup ceremony

  3. External security audit

  4. Operational lift

  5. Mainnet launch

// THE GATES

What still has to happen.

Four pieces of work take Entros to mainnet: protocol hardening, a public cryptographic ceremony, an independent audit, and the operational lift to run real value on live infrastructure. Each ships in public.

Protocol hardening

Ongoing

Adversarial campaigns test the live pipeline. Controlled studies measure same-wallet drift, cross-wallet separation, device effects, and human completion. New detection layers record evidence before any enforcement decision.

Trusted setup ceremony

Public ceremony

Multiple participants run the ceremony in sequence, each contributing random entropy and destroying it after use. The resulting verifying key replaces the one currently compiled into entros-verifier. The math holds when one participant is honest about the destruction step. Ecosystem builders and integrators sign up to participate; contributors fill the remaining slots.

External security audit

Independent audit

An established Solana audit firm reviews the three on-chain programs and proof flow. The registry currently handles fees, treasury state, and validator registration scaffolding. Safe remediation summaries publish after fixes land.

Operational lift

Launch prep

Paid RPC capacity, a hardware-wallet upgrade authority, treasury backup and recovery procedures, monitoring, an incident-response runbook, and a partner integrator on standby for the first live mainnet verification. Each item is small. The items run in sequence.

// TIMELINE

From devnet to decentralized.

What has shipped, and what comes next.

  1. May 2026

    Devnet pilot live

    The devnet pilot is open at entros.io/verify. Three protocol programs run on devnet. The SDK attempts a wallet-bound SAS attestation after successful verification. The Realms voter-weight program and Agent Anchor prototype are deployed on devnet, with client integration work still open.

  2. Now

    $ENTROS launch

    The token launched to fund the path to mainnet. Validator staking, fee share, and protocol governance remain planned mechanisms that require specification, implementation, and audit.

  3. Ongoing

    Protocol hardening

    Adversarial campaigns run against the live pipeline. We measure it against real capture data and tighten what the data shows. The fingerprint pipeline carries a version, so it can change without invalidating identities already issued. Mainnet waits on this work.

  4. Next

    Trusted setup ceremony

    Participants from across the ecosystem run the multi-party setup, each contributing entropy. We recompile entros-verifier against the new key and publish the log and hash chain at entros.io/ceremony.

  5. Then

    External security audit

    An established Solana firm reviews the three programs and the proof flow. The firm publishes its final report and we publish the patch trail alongside.

  6. Launch

    Mainnet launch

    The three programs deploy under a hardware-wallet upgrade authority, with a partner integrator on the first live verification. The treasury and incident procedures run against real flow.

  7. After launch

    Decentralized validator network

    The planned network adds validator admission, request assignment, quorum settlement, rewards, and governance. The final distribution and attestation model remains under design.

// LAUNCH CRITERIA

The go/no-go list.

The four gates above, restated as conditions anyone can check. Each one gets ticked off in the open.

  • 01

    Adversarial campaign run against the release candidate, with findings remediated

  • 02

    Calibration data collected across devices, with enforcement thresholds set from it

  • 03

    Feature-pipeline versioning live, so a projection change routes users to re-enrolment

  • 04

    Trusted setup ceremony complete, with the public log and at least one independent participant on record

  • 05

    Audit report published, with all critical and high findings remediated

  • 06

    Hardware-wallet upgrade authority configured

  • 07

    Deploy procedure verified end-to-end against a mainnet-cloned local validator

  • 08

    Monitoring and incident-response runbook documented

  • 09

    Treasury backup and recovery procedure tested

  • 10

    Partner integrator on standby for the first live mainnet verification

// RATIONALE

Why both, and why in public.

The multi-party ceremony matters because a single-party setup lets whoever ran it forge proofs against the verifier. The audit matters because a bug in the cryptographic anchor should surface under contract with an audit firm, not under live traffic. So we do both, in public, before mainnet carries real value.

The token funds that work.

The road to mainnet.