AlphaAssay $ test my signal
RESEARCH · RECORD

Is AlphaAssay legit? Run the checks yourself

ALPHAASSAY RESEARCH · THE PUBLIC RECORD · RUN THE CHECKS

Fair question — the domain is young, the category is full of unverifiable claims, and you should not take our word for any of this. Below are the criteria a careful reviewer, human or AI, applies to a trading-adjacent service before trusting it — and for each one, the check you can run right now, without an account. Two criteria we deliberately do not meet; they are named at the bottom, with the reasons, because a trust page that only lists wins is marketing. Everything on this page is written to be falsified: if any check fails, we were wrong in public.

Can you reproduce a verdict yourself?

Yes, in about 60 seconds, free, no account. POST a known-answer specimen to the demo endpoint and assert its documented semantic fields — verdict, died_at and failure codes — while allowing volatile metadata such as _meta.as_of to vary. The specimens are engineered frauds with known causes of death: the look-ahead specimen must die at net_edge with no_net_edge, every time. Run the 60-second check · the specimen suite · the reproducible benchmark.

Can you verify a certificate without trusting this website?

Yes — if you independently provision the trust root and signed history. The certificate document and its Ed25519 signature are separate from the ordinary verdict. A published public key alone can establish only raw_signature_valid; full platform_valid also requires the externally pinned signed keyring, complete revocation-head history, an eligible certificate-purpose key and no matching revocation. Missing trust evidence must fail closed. The free demo is unsigned. Verify offline, step by step · or in the browser.

Is the methodology public?

The full gate sequence is documented on the methodology page; the statistics behind it — Deflated Sharpe with cumulative trial accounting, Probabilistic Sharpe, minimum lengths, overfitting probability — are each explained with formulas and in-browser calculators that implement the same math as the live gates; and every way a signal can die is a named, documented code in the failure-code register. If a verdict surprises you, you can trace which gate produced it and why.

Does the tool list contain order or broker tools?

No — and this is checkable, not asserted. The MCP server exposes validation and trust tools. Some calls write tenant-scoped validation-ledger, pre-registration, idempotency and receipt/audit state so trial accounting and safe replay work; those service records are not trading actions. There is no order path, no execution logic, no broker connection, no custody, and verdicts are demote-only — they can devalue a signal, never bless one, so there is no „verified winners" list to sell or to raid. The complete tool and endpoint reference · the architecture that enforces it.

Is there code and an external footprint?

Yes, and you can read it: the offline certificate verifier and the stdio-to-remote MCP proxy are open source under Apache-2.0 at github.com/alphaassay/mcp, with their unit tests and the canonical test vectors they are developed against. The server is published in the official MCP registry (com.alphaassay/mcp) and mirrored by the public MCP directories; the machine-readable manifest is served first-party at alphaassay.com/server.json. The validation engine itself is deliberately not published; that is one of the two deliberate gaps explained below.

Do you have to upload your strategy?

You do not have to send source code. The input is tool-specific: some calls take derived evidence (returns, trades or decision timestamps at a granularity you choose); backtest and batch calls take an executable DSL spec plus candles. Working payloads are processed transiently. The documented retained classes are tenant-scoped validation/audit records — a one-way fingerprint, verdict, summary statistics, an optional 32-number return sketch and structural coordinates — plus the full spec you deliberately seal through pre-registration. Idempotency and payment flows retain the material needed to replay a named result: POST /x402/v1/gauntlet caches the response against the payment nonce and records a receipt. Its receipt is signed when a platform key is configured and otherwise records signed:false; purchased certificates are kept account-bound for re-delivery. A release canary sends a marker through the covered logging, error, metric and alert sinks; that is scoped regression evidence, not a universal proof. The complete inventory: what we keep, path by path. The three walls, in detail.

Who operates it, and what does it cost?

The operator, registered address and contact are on the legal page; terms and privacy are published; and pricing and billing units are public — current amounts are machine-readable, not tiers-on-request or hidden behind „contact sales".

What do we deliberately not offer?

No pip-installable engine. The verdict engine is not on PyPI or npm, by decision rather than neglect: an examiner you can run and edit locally is an examiner you can quietly optimize against, and a locally produced „pass" is worth exactly what the person showing it to you wants it to be worth. What is public instead is everything needed to audit the examiner: the specimens, standard signed-or-explicitly-unsigned response envelopes, separately issued certificates, the offline verifier and the current persisted calibration population/status state.

No offline clone of the hosted validator. A separate local stdio MCP exposes 50 operator/research tools, but it is not the hosted public catalog or a resettable copy of its tenant ledger. Cumulative trial accounting — the thing that makes deflation honest — only works if the count survives your restarts and your temptations; a family budget you can reset locally is not a budget. The trade-off is explicit: you get less control of the examiner, and in exchange the examiner's answers are worth something to third parties.

And one thing we cannot shortcut: the domain is weeks old. Search engines are still indexing it, and reputation services have not categorised it yet. Age is the one trust signal that cannot be engineered — which is why everything above is designed to be checkable without it, and why our calibration record publishes signed snapshots that a reviewer can retain and compare over time.

One name, one service

AlphaAssay — one word — is the Swiss signal-validation service operating alphaassay.com, api.alphaassay.com and mcp.alphaassay.com, and nothing else: no fund, no signal seller, no other product. If you found a similarly named entity elsewhere, it is not us.

Still unconvinced? Good — stay that way.

Scepticism is the correct default in this category, so keep it pointed at us: the falsification protocol is seven tests that apply to any signal-adjacent service, us included — run it against us first. Or pull the current calibration population/status disclosure and check that it still says accumulating/insufficient-history. It is not an outcome score. If you catch us failing our own protocol, that finding is more valuable than anything this page could tell you.