Every chain says it's secure. It's the least falsifiable sentence in the industry — "secure" against whom, at what cost, under which assumptions, and how would you ever know it stopped being true? Security gets asserted the way privacy gets asserted: as an adjective you're expected to take on faith.
Celar publishes a number instead. It's called ℋ, and it's a single ratio:
The cost to break the system must stay at least twice the value that breaking it would capture. It's a floor the protocol is not allowed to operate below — and, more importantly, every input that goes into the ratio is published, so anyone can recompute it and check whether we're telling the truth.
01 /Why a ratio, not a promise
Confidentiality on Celar rests on a threshold committee: the network's decryption key exists only as shares across 100 seats, and producing any plaintext takes a threshold quorum of them. So the real question isn't "is the cryptography good" — it's "what would it cost an attacker to capture enough of that committee, and is that cost worth what they'd gain?"
That's an economic question, and ℋ answers it economically. The attack cost is what an adversary must acquire and put at risk — stake, and the slashing they'd eat — to control the decrypting threshold. The value at risk is what confidentiality protects: the value in the shielded pool. When attack cost is twice value at risk, breaking the system is a losing trade by construction. Security stops being a claim about intentions and becomes a claim about incentives — one you can price.
02 /The inputs are public, so the claim is falsifiable
A ratio is only honest if you can see what's in it. Celar's health page publishes every input — committee size and threshold, stake at risk, slashing parameters, the value in the pool — so the number isn't something you trust us to compute correctly. You recompute it. If our arithmetic is wrong, it's publicly wrong.
This is the same principle behind everything else Celar publishes — the leakage matrix, the PF-1 label: a security claim you can't check is indistinguishable from marketing. We'd rather be checkable and occasionally corrected than unfalsifiable and always "secure."
03 /A floor governance can't vote away
Two properties make ℋ more than a dashboard gauge:
Governance can tune many parameters, but it cannot lower the ℋ floor. The one lever that most directly trades safety for growth is removed from discretionary control.
As the ratio nears the floor — because the pool grew or stake thinned — the protocol throttles what the pool will accept until the margin is restored. It defends its own invariant.
A network under pressure to grow can't quietly relax its own security margin to let more value into the pool, and it doesn't rely on a committee to notice and act — the system enforces the invariant itself.
04 /What it does and doesn't cover — honestly
ℋ governs the economic security of the confidentiality layer — committee capture versus pool value. It is not a claim about base-layer consensus (that's standard BFT safety under f < n/3, a separate property), and it isn't a claim that the cryptography can't be broken by cryptanalysis rather than economics. It answers one specific, important question: is attacking the committee ever a profitable trade? No — by a factor of at least two.
And the pre-mainnet caveat, because the honest-disclosure thesis cuts both ways: today the health page runs on modelled inputs with published assumptions, not a live chain feed — and it's labelled as such. The on-chain feed that publishes the real numbers block by block goes live at mainnet. What exists now is the framework, the formula, and every assumption exposed for inspection; what comes at launch is live data flowing through it.
05 /The point
"Trust us, we're secure" asks you to believe a claim you can't test. ℋ replaces it with a number, its inputs, and a rule that the number can't drop below 2 — structured, as far as we know, as the first L1 security claim where being wrong is publicly checkable. That's a lower bar to clear than "perfectly secure," and a far more useful one, because you can actually hold us to it.
CONTACT — press@celar.network · LIVE METRIC — celar.network/health · $CELAR