CITIZEN CITADEL NEXUS GATEWAY — THE BROKEN LINEAGE ROUND 1 ARCHITECTURE CONTRACT 1. SYSTEM MODEL Round 1 consists of five logical components: PARTICIPANT | v GATE | v TARGET | v PROOF | v VERIFIER | v AUDIT 2. GATE The Gate is the public entry point for the active Challenge round. It provides the information and access required to reach the designated Challenge Target. Depending on the active configuration, this may include: - challenge identity; - published scope and rules; - Target connection information; - participant/session identification. The Gate is an entry component, not the victory authority. 3. TARGET The Target is the attackable technical system for Round 1. It: - exposes the published Round 1 challenge interfaces; - implements the authorization lineage under challenge; - maintains the protected state; - generates the Round 1 proof when the relevant state is reached; - operates inside the isolated Challenge environment. 4. PROOF The proof is the technical artifact connecting Target state to independent verification. It is: - generated by the designated Target; - bound to the relevant Round and challenge/session; - associated with the protected-state event; - independently verifiable. The proof does not contain Verifier-private validation material. 5. VERIFIER The Verifier is the authority for the Round 1 technical result. It receives the submitted proof and evaluates it against the frozen Round 1 verification rules. Its result is binary: ACCEPT REJECT The Round is technically complete when the Verifier returns ACCEPT for a proof satisfying the Round 1 contract. 6. AUDIT The Audit component records the integrity information necessary to reconstruct verification events. A verification record preserves at least: - round identity; - verification time; - proof identifier or digest; - verifier result; - relevant integrity references. 7. TRUST BOUNDARY PUBLIC / ATTACKABLE: PARTICIPANT | v GATE | v TARGET | v PROOF -------------------- TRUST BOUNDARY -------------------- PRIVATE / VERIFICATION INFRASTRUCTURE: VERIFIER | v AUDIT Round 1 authorization applies to the published Target surface. Verifier and Audit remain outside that attack surface. 8. PRODUCTION BOUNDARY The Challenge environment is separated from: - production NEXUS CITADEL; - SKYNET production systems; - organizer devices and accounts; - personal credentials and data; - third-party infrastructure; - unrelated participant systems. 9. ROUND FREEZE Before Round 1 becomes active, the organizer freezes: - Target source/build; - Verifier source/build; - Round configuration; - victory condition; - scope and rules. SHA-256 integrity references are recorded before participant access. ORGANIZER: CITIZEN CITADEL STATUS: PREPARATION