BermLaunch
Documentation

BermLaunch docs

Portable identity → public proof → durable evidence → fixed launch rules → provable participation → fail-closed execution.

Berm Protocol

BermLaunch is built on Berm Protocol, the public verification layer for portable identity. Current X method: berm.external_account_binding.x/2. Read the Berm Protocol docs →

BermLaunch overview

What happens

Communities recruit under a campaign constitution before any token exists.

What you sign

Only bounded, purpose-specific evidence requests; this page never signs.

What becomes durable

Accepted evidence and campaign positions are portable records.

What can fail

Missing or conflicting evidence fails closed.

How you verify it

Inspect the campaign, evidence and public verification surface.

Identity

What happens

A BRM session establishes a portable npub identity.

What you sign

Identity-specific acts remain domain separated.

What becomes durable

Only accepted identity evidence is retained.

What can fail

Session mismatch and invalid evidence are rejected.

How you verify it

Compare the accepted binding to the displayed npub.

Proving an X account

What happens

A public X proof is checked against an npub binding.

What you sign

The binding claim has a fixed external-account purpose.

What becomes durable

Raw capture and accepted evidence references are retained.

What can fail

Unbound transport or mismatched proof is unavailable or rejected.

How you verify it

Review the accepted binding and its evidence chain.

Joining a campaign

What happens

R3 enrollment precedes a verified X publication and accepted campaign position.

What you sign

Enrollment and proof acts are separated by purpose.

What becomes durable

The unique campaignId/npub position and receipt are retained.

What can fail

Replay, rebind, corruption and conflicting positions fail closed.

How you verify it

Inspect the reconstructed portable receipt.

Campaign lifecycle

What happens

Recruiting precedes creation, curve activity, and any graduated market.

What you sign

No market action is implied by lifecycle display.

What becomes durable

Authoritative lifecycle evidence controls public stage.

What can fail

Absent asset/provider evidence leaves market unavailable.

How you verify it

Read the bound provider and lifecycle facts.

Cohorts & economics

What happens

Founders, Graduators and Boosters are public aliases for canonical cohorts.

What you sign

Participation does not rewrite constitution economics.

What becomes durable

Canonical cohort IDs, capacities and BPS ranges remain fixed.

What can fail

Closed, filled and unknown stages have no false join CTA.

How you verify it

Compare displayed shares to canonical BPS ranges.

Launch providers

What happens

Provider-specific evidence is normalized behind a provider-neutral product read.

What you sign

Provider selection is not a user signing request on this page.

What becomes durable

Bound launch/provider identities are evidence-backed.

What can fail

Unproved provider facts remain unavailable.

How you verify it

Inspect provider evidence and Trust & Verify.

Revenue / fees / commissions

What happens

Post-launch fee presentation uses canonical accounting evidence, not volume.

What you sign

No fee claim is signed from this public surface.

What becomes durable

Canonical asset accounting and eligible allocation evidence persist.

What can fail

Missing accounting is unavailable, never zero.

How you verify it

Compare canonical asset amounts to provider accounting evidence.

Trust & Verify

What happens

It explains what evidence supports a product claim.

What you sign

Verification does not create a signature.

What becomes durable

Only independently verified evidence can support a positive state.

What can fail

Missing roots, receipts or provider facts fail closed.

How you verify it

Use the dedicated Trust & Verify route.

Evidence

What happens

Raw artifacts are preserved with semantic verification.

What you sign

Evidence signatures retain their bounded domain.

What becomes durable

Hashes, receipts and references make reconstruction possible.

What can fail

Byte, hash or schema mismatch is rejected.

How you verify it

Run the supplied offline verifiers over exact bytes.

Security & self-custody

What happens

Private keys stay with the user and signing remains explicit.

What you sign

Only clearly scoped requests should be approved.

What becomes durable

Public evidence, not private key material, is retained.

What can fail

Unexpected origins, wrong identities and ambiguous outcomes stop.

How you verify it

Check origin, request fields and accepted evidence before approval.

Technical reference

What happens

Browser, server and provider seams expose typed fail-closed reads.

What you sign

Production signer scope is intentionally narrow.

What becomes durable

Versioned artifacts and complete history bind implementation.

What can fail

Schema, transport, projection and identity mismatches stop processing.

How you verify it

Use exact manifests, source bundles and behavioral tests.