01
Specify
Write the method down before the code: inputs, assumptions, calibration source, and the failure modes you expect. The specification is published with the engine.
02
Implement
Build to the guest-program interface in fixed-point arithmetic, with a floating-point twin. Both must agree bit-exactly at the parity gate.
03
Backtest
Run the archetype suite and a real historical tape. Anchoring behaviour is checked at both ends of the credit spectrum, not just the comfortable middle.
04
Review
An independent actuarial reviewer signs the specification and the parity evidence. Their name is recorded against the engine, as the officer's is at the gate.
05
Pin
The engine is compiled to a zkVM image and registered as a type entry with its own image id. From that moment it can never change. A revision is a new entry, not an update.
Pinning is what makes the arrangement fair in both directions. Underwriters know the model behind their capital cannot be recalibrated after they commit, and you know your work cannot be quietly edited and still carry your reviewer's signature.