Seal before you ship
A coding agent that deploys a token or a strategy asks for a review of its own repo, and launches with the mark without handing out its edge.
repo + commit → review
bytecode hash → sealProve the code is safe. Eclipse the rest.
Orbital gives Orbio agents a private audit. An AI auditor agent runs through Orbio with zero data retention, reads your source alone and signs what it found. Eight fixed checks run on your bytecode, and the seal goes on Robinhood Chain. Nobody else ever reads a line, human or agent.
Orbio gives agents one key to every model and routes only to zero data retention endpoints. That is the missing piece for a private audit: the only reader of your source is a model that keeps nothing. Orbital is the privacy layer on top.
The review runs only on Orbio's ZDR routes. Prompts and responses pass through and are not written anywhere, so your source exists in one place for one call.
Orbio holders earn inference credits from the token's fees. Bring your key and the agent's review is paid from them, used once and never stored.
Orbio sends the request to the model it names, unchanged. The seal records which model wrote the review and that it went through Orbio.
Hold $ORBIO? Your credits pay for your review.
Paste your Orbio key when you send the contract. It is used for one call, never stored, and the seal says the review ran through Orbio.
Privacy onchain has meant hiding balances and transfers. Orbital, the first onchain privacy layer for Orbio, hides the other thing people keep private: the code itself. Each layer does one job, and the source never crosses from one to the next.
The layers are separate on purpose: what is proven, what an agent thinks, and what is at stake are never mixed into one green tick.
Eight fixed checks run on the compiled bytecode: mint, drain, tax, blacklist, pause, upgrade, sell path, self-destruct. The answers are yes or no, the same for everyone, bound to the hash of the code.
An AI auditor agent reads the source in isolation through Orbio, with zero data retention. It describes what the code does and who holds which powers, scores the risk, and never quotes a line. The auditor signs its output, labelled as an opinion.
The registry on Robinhood Chain writes the seal against the code hash, holds the auditor's stake behind it, splits the fee and pays the cover pool when a claim passes.
Every audit so far has asked the same price: publish the code, then we will tell people it is safe. Orbital keeps the security check and leaves the privacy where it was. Here is the line, exactly.
A read-only grant on one repo, at one commit. Nothing else is asked for.
The repo is compiled and matched to the chain byte for byte. Eight fixed checks run, then a model reads the source and the auditor signs what it says.
The seal follows the bytecode wherever it is deployed, and anyone can read it without asking.
What the chain receives is a hash, a proof and a signature. It never receives the source, and the proof does not contain it either. A launchpad, a wallet or a marketplace can show the mark without asking anyone.
No path creates supply after deployment other than the ones declared in the interface.
No function lets one address move balances that are not its own.
If there is a tax, it is fixed or bounded, and the bound is ten percent.
No function can stop a specific address from selling.
Transfers cannot be switched off after launch.
No proxy, no delegatecall to an address that can change.
A buy followed by a sell completes, from a fresh address, on a fork.
Nothing can remove the code once it is sealed.
Agents already write contracts, launch tokens and trade them. None of them can read a stranger's source, and none of them should have to publish their own. Orbital gives them a trust signal a machine can read: a hash in, a verdict out.
A coding agent that deploys a token or a strategy asks for a review of its own repo, and launches with the mark without handing out its edge.
repo + commit → review
bytecode hash → sealA trading agent checks the seal of any contract in one call before it buys. No source to parse, no report to trust: a hash, eight answers, a score.
badge(codehash)
→ score, passed, ran, standingThe one agent that sees the source. It works in isolation, its review is signed by a staked auditor, and the tree is deleted when it is done.
source → agent → signature
source → deletedIt says these checks ran on this code and passed, and that someone locked money behind saying so. It does not say the code is good, and it cannot see what the checks do not look for.
Read the rulesA Pons launch, a bot, a strategy for sale: get it reviewed before anyone sees the code. The seal follows the bytecode wherever it is deployed.