CITIZEN CITADEL NEXUS GATEWAY — THE BROKEN LINEAGE CHALLENGE RULES / 1_1_0 1. AUTHORIZED CHALLENGE The NEXUS Challenge is an authorized security challenge conducted against a specifically designated isolated Challenge Target. Authorization is limited to the active Challenge round, its designated Target and the attack surface explicitly published by the organizer. 2. IN SCOPE Participants are authorized to analyze and interact with the exposed attack surface of the designated Challenge Target for the purpose of satisfying the published technical victory condition. The active round documentation identifies the Target and applicable interfaces. 3. AUTHORIZATION BOUNDARY Challenge authorization ends at the boundary of the designated Target surface. The following remain outside that authorization: - production NEXUS CITADEL; - SKYNET and its production infrastructure; - organizer devices, accounts and credentials; - devices or accounts belonging to other participants; - SIM/mobile-operator systems; - personal or unrelated user data; - GitHub and other third-party services; - hosting-provider infrastructure outside the designated Target; - systems, addresses and services not explicitly designated as part of the active Challenge Target. Social engineering and physical attacks are outside the Challenge authorization. 4. ROUND 1 VICTORY CONDITION Round 1 requires the participant to break the intended authorization lineage of the designated Target through the published Challenge surface. Successful completion requires: NO VALID AUTHORIZATION + TARGET REACHES PROTECTED STATE + TARGET PRODUCES AUTHENTIC ROUND 1 PROOF + VERIFIER ACCEPTS PROOF A vulnerability report by itself is not the Round 1 victory condition. 5. VERIFICATION The Verifier is separate from the attackable Target. The participant submits the designated Round 1 proof for independent verification. Verifier-private validation material and Audit storage remain outside the participant attack surface. The authoritative technical result is: VERIFIER = ACCEPT 6. ROUND INTEGRITY Before an active round opens, the organizer records: - Challenge version; - SHA-256 integrity references for frozen artifacts; - Target configuration; - initial Target state; - victory condition. The verification logic, victory condition and recorded initial state remain fixed for the duration of that round. A change to frozen technical state creates a different round state and requires a new integrity record. 7. ISOLATION The Challenge Target is treated as potentially compromised throughout the active round. Its environment is isolated so that compromise of the Target does not provide authorized access to production systems or unrelated infrastructure. The Target contains no production credentials, production NEXUS keys, personal user data, or credentials providing access to production SKYNET or Challenge control infrastructure. 8. EVIDENCE AND AUDIT The Challenge maintains an audit trail sufficient to reconstruct a verified Round result. For a verified completion, retained evidence may include: - Challenge round identifier; - timestamp; - submitted proof; - relevant audit records; - Target SHA-256; - integrity information required to reproduce and verify the result. 9. REPRODUCIBILITY A claimed Round completion must be verifiable against the frozen technical state and corresponding audit evidence. The Round result is determined by the published victory condition and the independent Verifier. 10. REWARDS Challenge participation does not by itself establish a monetary reward, bounty, employment relationship or contractual entitlement. Any reward program associated with a Challenge round must be announced separately and explicitly before that round begins. 11. EFFECTIVE AUTHORIZATION These rules authorize activity only against the explicitly designated Challenge Target and only for the duration and interfaces specified for the applicable active round. Activity outside that boundary is not part of the NEXUS Challenge. ORGANIZER: CITIZEN CITADEL