The verification ledger.
Promotion belongs on a front page; proof belongs here. This page keeps the diligence we would want to read if we were in your seat: dated captures, re-runnable commands, pinned sources, and the caveats in full. Nothing below asks to be believed.
Every check below was captured on 6 August 2026 (UTC), and every one can be re-run today by anyone; where an entry has been re-verified since, the newer date sits beside it in the entry itself. Since these claims were first written, both codebases have become publicly readable on GitHub; the strongest claims on this site point at primary sources anyone can open.
The Bridgeless Bridge is a design brief: nothing at that layer is shipped. Suwappu is live, in production. The Suwappu Lattice Protocol runs on two testnets; no mainnet deployment exists.
Suwappu and the Suwappu Lattice Protocol share a name and a doctrine. They do not share a codebase: as of 6 August 2026 (UTC), neither repository imports, links, or calls code from the other, and each is deployed and operated without the other. Neither yet implements the brief: the brief requires settlement gated on a verified validity proof, and while the Lattice repository now holds zkVM verifier circuits for post-quantum signatures, machinery on the axis the brief describes, no end-to-end proof has yet been produced and the deployed on-chain verifier is simulated, per the project's own trust-model document (25 July 2026). The framework is a thesis; one of the projects beneath it is live.
The public commit log names its own money-path fixes, dated and identified: a CCTP fund-loss fix (35884c8d), a rule never to refund a swap whose outcome is unknown (48c70ab3), and an account-takeover hotfix that requires demonstrated Turnkey wallet ownership before authorising a swap (dc176317). Fixed and disclosed, not audited: the project's security page lists SOC 2 and public protocol audit reports as roadmap items rather than achievements, and now claims an independent red-team review of its wallet and key-management paths, a claim this site has not verified (checked 31 August 2026, UTC).
Upstream surfaces disagreed on chain count when this ledger opened: the repository's README badge said 14, the product docs 40-plus, and the live /chains endpoint served 18 (all checked 6 August 2026, UTC). This site filed the drift upstream as pull request #755; the maintainer confirmed the drift was real, superseded the patch with a fuller fix, and merged it on 9 August 2026 (#827). The README now carries counts generated from source: 45 platform chains, 18 agent-API chains, 21 routing integrations (re-checked 31 August 2026, UTC). The two chain counts measure different things, 45 is every chain the platform touches, 18 is what the public agent endpoint serves, and the live endpoint served exactly those 18 the same day. This site cites only the live endpoint, and recorded the disagreement while it lasted rather than smoothing it over.
The codebase is public at github.com/0xSoftBoi/suwappubot (pinned to commit a60ba9ec) under the Apache License 2.0 per the repository LICENSE; the three published npm packages are MIT. CodeQL, Scorecard, and a checked-in SBOM are in the repository, and the count of 21 routing integrations is derived from source at build time, with a continuous-integration drift check failing the build when published numbers drift from code (all re-verified 31 August 2026, UTC).
The settlement layer's trust root remains classical and administrative, and the project says so in a public document of its own: the bridge trust-model paper (25 July 2026, describing the live Base Sepolia deployment, pinned to block 39,928,377) states that the fast path, as deployed, provides no cryptographic guarantee, that the optimistic path is arbitration rather than on-chain proof verification, and that with both bonds at zero, slashing has no economic effect today. A fix exists in source (v7) and is not deployed.
Two zkVM verifier circuits for ML-DSA-65 signatures, one RISC0 and one SP1, sit in the repository; the SP1 circuit executes under the real prover toolchain (first execution 24 July 2026, commit c50d2eb), and no end-to-end proof has ever been produced. Until one is, the brief's finish line is a stated destination, not a property of the deployed system. This is the single most load-bearing caveat on this site.
In May 2026 an internal red team replayed ten historical bridge exploits against the stack across 33 scenarios; the campaign surfaced one new HIGH finding, fixed in the same branch (May 2026 report). A second internal campaign was chartered in June 2026, targeting economic and griefing attacks on the bridge's bond mechanism; it has produced no tests or findings yet. The standing findings catalogue stays open on purpose: 31 findings logged to date, 20 closed, 11 deferred with severity and rationale recorded, two of them critical. All of it is internal self-assessment, not an independent audit, and the reports label themselves that way.
The culture cuts both ways: on 24 July 2026 the project fixed and disclosed a composite ML-DSA plus Ed25519 signing path whose verification had accepted any 64-byte value, committing the regression test alongside (commit b4897cf).
The Lattice code licence is the Elastic License 2.0 per the repository's LICENSE file, source-available and not an OSI-approved open source licence; as of 6 August 2026 the README still carries an MIT badge, an unresolved upstream inconsistency. The source is public at github.com/Suwappu-Labs/suwappu-lattice-protocol (pinned to commit e52c4f0).
Where this site cites a market figure, the source and date sit beside the number. A capture date is a promise that the value was read at the named primary source on that day: when a number changes upstream, the site changes the number and the date together, or not at all.
Source links are pinned to the commits current at each entry's stated verification date, so the page you open is the page that was checked; each repository's main branch carries whatever came after. Re-pinning happens only together with re-verification.
Statuses use three words on purpose: live means running in production today; testnets means deployed where value is not at risk; brief means paper. The front page is written to persuade; this page is written to be checked. Where the two could ever disagree, this page wins.