Kerne Logo

Kerne Honesty Index

Reproduce the board.

The Honesty Index publishes a yield figure about twenty one named companies, and it is published by one of the companies on it. There is an obvious objection to that and there is exactly one answer to it: somebody else runs the measurement and says what they got. Nobody does that if checking costs an afternoon, so it costs one command.

The checker is a second implementation. It shares no code with the engine that writes the board. It reads the same public chain state, decodes it with its own decoder, does the arithmetic in its own arithmetic, and verifies the snapshot signature with keccak256 and secp256k1 written from scratch in that repository rather than with a library. If the two agree, that is two independent programs agreeing about a public fact. If they disagree, the board is wrong, and we would rather find out from you.

One command. No account, no key, no clone.

Zero install

npx -y github:kerne-protocol/realized-apy check

Or from a clean clone, which is the same thing without npm in the way, and is the version to use if you would rather read the code before you run it:

git clone https://github.com/kerne-protocol/realized-apy
cd realized-apy
node bin/realized-apy.mjs check

It reads the signed snapshot, re-derives every row from public archive RPC at the block heights the snapshot names, and prints PASS or FAIL per row. It exits non-zero if any row fails to reproduce or if the signature does not verify, so it drops into CI as it stands. Node 20 or later. No dependencies, so there is nothing in the supply chain between you and the answer.

What a PASS actually asserts.

The comparison is deliberately unforgiving. Both block heights are published in the snapshot, so there is no legitimate source of disagreement about the share price at either one. Those two are compared exactly, to the last digit. Only the annualized figure carries a tolerance, and only for floating point rounding across platforms.

CheckedTolerance
Share price at the start blockexact string match
Share price at the end blockexact string match
Annualized figure0.0002 percentage points

Every read is taken from two independent public endpoints that must return the same bytes. One endpoint is one party you are trusting, which is the thing this exercise is trying to avoid. If two nodes disagree about state at a pinned block, the tool says so and fails that row rather than picking a favourite.

The signature check has three parts and each can fail on its own: that the published hash really is sha256 over the published canonical bytes, that the signature recovers under EIP-191 to the published signer, and that rebuilding the canonical form from the rows in the document reproduces those exact bytes. The third is the one that catches an edited row, and it is the one most signature checkers skip: a snapshot with one figure changed still passes the first two, because the signature is a perfectly good signature over the original bytes.

What it does not check.

  • The advertised column. That is a human reading a marketing surface on a date, and no script can confirm what a website said last Tuesday. The snapshot carries the source URL, the capture date and a verbatim quote for every advertised figure precisely so you can open the page and diff the transcription yourself. The signature binds those quotes, so a quote cannot be revised later while the signature still verifies.
  • Whether a protocol is any good. A share price is denominated in its underlying, not in dollars. A vault can grow steadily in units of an asset that is itself broken. Rows whose underlying is off peg carry a note saying so. This tool measures one axis and is silent about the rest.
  • The hedge, the reserves, the custody. Not this instrument. Kerne's reserve side is a separate page with a separate verifier, at proof of reserves.
  • Whether the window was chosen fairly. Both block heights come out of our snapshot, so running the checker verifies our arithmetic inside a window we picked. If you want to remove that too, the same tool measures any vault from scratch, finding its own window and never reading our snapshot at all.

If you get a different answer.

That is the interesting outcome and it is the one this whole apparatus is built for. What follows is a standing commitment, not a courtesy, and it is written here so it can be quoted back at us.

  • Send the row, both block heights, both share prices you read and the endpoint you read them from. That is enough for anyone to settle it, including you.
  • If a figure we published is wrong, it is corrected on the board with both readings and a date, in the append-only corrections log, and the correction says what the method change was rather than only what the number changed to.
  • Your finding is linked from this page whether it agrees with us or not, and a disagreement is listed above the agreements.
  • None of that depends on how you tell us. A public post, a GitHub issue on the checker, or an email all get the same treatment, and you never have to talk to us at all.

Who has run it, and what they found.

Public runs by anyone other than us, listed with disagreements first. A run by Kerne is not an independent check and is not listed here; the repository's own README prints ours and labels it as ours.

Nobody outside Kerne has published a run yet. The checker was released on August 14, 2026, so this register is empty because it is new, not because the board has been confirmed by anyone.

Right of Reply.

The section above is for a reader who checked the arithmetic. This one is for the twenty one companies the board publishes a number about, none of whom asked to be measured. Every row on the Honesty Index has a free, permanent, unedited reply slot, and the reply appears on the row itself rather than somewhere quieter.

The reason to offer it is not generosity. A board that only ever speaks is a judgement, and a judgement is the one shape of this thing that could never be fair to the people on it. A board a graded party can answer, in full, in its own words, on the same page, is a standard.

The terms.

  • It is free. There is nothing to buy, nothing to sign, and no commercial conversation of any kind is a condition of it. If we are already selling you something, or trying to, that changes nothing here.
  • It is published verbatim. We do not edit it, shorten it, correct its spelling, or soften it. What you send is what appears.
  • It is permanent. Once published it is never removed, never re-dated and never reordered. If you later want to withdraw it, we record that you withdrew it and leave the words up.
  • It is published whether or not it agrees with us. A reply arguing our method is wrong is the one we most owe you, and it goes up the same way as any other.
  • We do not answer inside it. If we have something to say back, it appears underneath, dated, in our own name, and it never changes a word of yours.
  • Replying is not the same as asking for the row to come down. The row stays, your reply sits on it, and neither has ever been a condition of the other. A reply is also not a substitute for a correction: if you send arithmetic showing a figure is wrong, we correct the figure as well, in the append-only log on the board.
  • Keep it under 800 words if you can. If yours is longer we publish it in full anyway and link your own version.

The three things we will not publish.

Unedited is a promise, and a promise with unstated exceptions is worse than one with stated exceptions. These are the only ones, they are narrow, and none of them is about a reply being hostile, embarrassing or convincing.

  • Anything unlawful to publish, which is a legal limit rather than an editorial one.
  • Personal information about a private individual. A named employee speaking for the protocol is fine; a third party who did not choose to be in this is not.
  • Text that is not about the row. This is a reply slot on a specific measurement, not a general posting surface, and we would say the same to a reply that flattered us.

What has been said back.

No protocol has used this yet. The slot opened on August 14, 2026 and this register is empty, which is a fact about how new the offer is and not evidence that anybody agrees with us.

Use it.

The terms, before you spend time on this

  • It is free. There is nothing to buy, nothing to sign, and no commercial conversation of any kind is a condition of it. If we are already selling you something, or trying to, that changes nothing here.
  • It is published verbatim. We do not edit it, shorten it, correct its spelling, or soften it. What you send is what appears.
  • It is permanent. Once published it is never removed, never re-dated and never reordered. If you later want to withdraw it, we record that you withdrew it and leave the words up.
  • It is published whether or not it agrees with us. A reply arguing our method is wrong is the one we most owe you, and it goes up the same way as any other.
  • We do not answer inside it. If we have something to say back, it appears underneath, dated, in our own name, and it never changes a word of yours.
  • Replying is not the same as asking for the row to come down. The row stays, your reply sits on it, and neither has ever been a condition of the other. A reply is also not a substitute for a correction: if you send arithmetic showing a figure is wrong, we correct the figure as well, in the append-only log on the board.
  • Keep it under 800 words if you can. If yours is longer we publish it in full anyway and link your own version.

The only things we will not publish

  • Anything unlawful to publish, which is a legal limit rather than an editorial one.
  • Personal information about a private individual. A named employee speaking for the protocol is fine; a third party who did not choose to be in this is not.
  • Text that is not about the row. This is a reply slot on a specific measurement, not a general posting surface, and we would say the same to a reply that flattered us.

Used to confirm the reply came from the protocol, and for nothing else.

0 words. The stated cap is 800; a longer reply is published in full anyway.

We reply from kerne.systems@protonmail.com. Prefer email? Write kerne.systems@protonmail.com directly and say it is a right of reply; the terms are identical either way.

The rest of the apparatus.

  • The board : every row, its basis, its source and its corrections log.
  • The signed JSON : free, no key, no rate limit, CORS open. What the checker reads.
  • The dataset mirror : the same data under CC BY 4.0, refreshed on a schedule and therefore lagging. When it disagrees with the live endpoint, the live endpoint is right.
  • The same question on Solana : a separate board and a separate checker, published at solana honesty.
  • signed-por : the vendor neutral verifier for the reserve attestations, which is the other axis and a different instrument.