The Access List
The decisive input to cyber defense is now allocated — by three labs' vetted lists and, for two weeks in June, by the Commerce Secretary's signature. The lists are public enough to map. They do not match the premium.
Access map and quotes as of 2026-09-04; CVE series through 2026-09-05; pricing tiers quote The Survivor Premium's trailing sort (vintage 2026-08-28/29) and are not recomputed here.
The verdict, first
In the first three days of September, all three frontier AI labs formalized the same policy: their most capable cybersecurity models are not sold, they are allocated — to named lists of vetted organizations. This note takes those lists — Anthropic's Project Glasswing, OpenAI's Daybreak, Google's Fairwind — and lays them over the 15-stock cybersecurity universe from our Survivor Premium note, to test the newest argument for the sector's extreme valuations: that the expensive names deserve their premium because they hold privileged access to the decisive new input.
The map says no. Eleven of the fifteen names are publicly inside at least one program. Fortinet, priced in the market's cheap half, holds the same badge CrowdStrike holds at a survivor multiple. Access, it turns out, was allocated broadly across US security vendors within months — it is table stakes with a citizenship test, not a moat. The four names never publicly named to any list all sit in the market's cheap half, and one of them is the only large security company headquartered outside the United States. And the sharpest fact on the record is not who holds access at all: it is that the three allocators — plus Microsoft, which runs a gated cyber model of its own inside its own security product — have entered the security business directly. The entities deciding who gets the input are also selling the finished product.
Our parent note said the market's sort of this industry is right "only if AI reinforces platform moats AND the cost of the monoculture the platforms are building stays unpriced." This note tests the first clause, and the first hard evidence cuts both ways: the premium cannot cite access as its justification — but the platforms the parent note worried about now include the AI labs themselves. (The second clause is, if anything, sharpened by a regime that concentrates every vetted defender on the same handful of gated models — three allocators' models, four counting Microsoft's own; the parent's monoculture tripwire keeps watching it, untouched here.) The direction of the market's sort survives another test. The price of it fails another one.
The overall point, stated once. The market has priced AI in this industry exactly once — the indiscriminate March selloff, which round-tripped — and has not repriced since the axis changed. It is still pricing this arms race as if the decisive input were something vendors build and own. The input has become something labs and the state allocate. The sections that follow are the evidence that the consequences of that shift — no access edge for the premium, the allocators selling the product they gate, a sovereignty line through the universe, badges that expire on the gatekeeper's own clock — are not yet being read.
Three days, three gates
What happened in the September 1–3 week, from the labs' own announcements:
- OpenAI said its forthcoming Astra model is the first to cross the "Critical" cybersecurity threshold of its internal risk framework — a model that can independently find and exploit zero-day vulnerabilities (flaws unknown to the software's maker, for which no fix exists) or carry out a complete cyberattack from a high-level instruction. Astra scored 100% on ExploitBench, a benchmark for converting known flaws into working attack code, and found two zero-days on its own during testing. Its cyber capabilities will be limited to OpenAI's vetted coalition, called Daybreak; the restriction, per reporting, came at the administration's request.
- Anthropic released Claude Mythos 5.1 alongside the public Claude Fable 5.1. Mythos 5.1 is available only through trusted-access programs for cybersecurity and life-sciences work, currently US-only — while the public tier was simultaneously loosened to permit vulnerability discovery for all users. A verification program opened an application portal the same day.
- Google launched Gemini 3.8 Flash publicly and a restricted variant, Flash Cyber, tuned for finding and automatically patching software flaws — behind a new gate called the Fairwind Program: governments and trusted partners, 650+ participants, background checks.
The same week happened to be the sector's repricing week — Palo Alto reported September 1 and trades roughly 11% below our parent note's late-August pricing vintage; Zscaler reported September 3 and fell over 5% the next session. We attribute none of those moves to the access regime; they are earnings reactions. The observation worth keeping is the opposite one: a structural change in the industry's most important new input was announced across three days, and the market treated it as a non-event. Either it is priced, or it is not yet being read — and the rest of this note is the argument that it is not yet being read.
What the gated models actually do
Everything here is from the labs' published evaluations — not vendor marketing.
Anthropic's assessment of its Mythos Preview model reports vulnerabilities found in every major operating system and every major web browser, including a 27-year-old OpenBSD flaw, a 16-year-old FFmpeg flaw, and a 17-year-old FreeBSD flaw; 181 working exploits against Firefox's JavaScript engine where the prior model generation succeeded twice in several hundred attempts; and — the number that matters most for the economics of crime — a working exploit for a known vulnerability developed for under $1,000 of computation in half a day. A campaign of a thousand automated scanning runs against an operating system cost under $20,000. Capabilities that were recently a nation-state budget line now price like a mid-sized criminal enterprise's operating expense — if the capability escapes the gate.
The defensive ledger is real too: Mozilla found and patched 271 Firefox vulnerabilities working with the model; Glasswing partners collectively identified more than 10,000 high- or critical-severity flaws in the program's first weeks; Google reports its restricted model generated 2.6 times more correct Chrome patches than the best commercial tools. But Anthropic's own evaluation page carries the sentence that defines the era: "Over 99% of the vulnerabilities we've found have not yet been patched." Discovery is running far ahead of remediation. A world where every codebase's flaws are visible but unfixed is more dangerous than the world before the flashlight — and the backlog is, for now, a demand pulse for whoever owns the fixing.
Two weeks in June, when the list was law
The programs are private policy. For two weeks this summer, allocation was public law. On June 12 — three days after Anthropic released Mythos 5 and Fable 5 — the Commerce Secretary signed an export-control directive, under statutes built for missile components and semiconductor tooling, requiring licenses before either model could be provided "to any foreign person worldwide." Since no consumer service can verify nationality across hundreds of millions of users in real time, the practical effect was a global shutoff of both models. On June 26, a second letter exempted "certain trusted partners." On June 30, the controls were lifted.
Three precedents came out of those two weeks, and all three outlast the episode. Access to a commercial AI model is now an export-controllable national-security input. "Trusted partner" is now a legal category with commercial value, its membership decided by signature. And nationality is now an allocation criterion — the carve-out ran through foreign-national exemptions, and the strongest gated model is today US-only. Keep that third one in mind when you read the map.
June 12: an export-control directive, signed by the Commerce Secretary under statutes built for missile components, shuts off two frontier models worldwide. June 26: “certain trusted partners” are exempted, by name. June 30: the controls lift. For two weeks, access to the industry’s decisive new input was allocated by signature — and every precedent set in those two weeks is still standing.
The map
Before the verdict — the case that the lists validate the premium, in its strongest form. CrowdStrike and Palo Alto Networks are not merely members of Project Glasswing — they are launch partners, named on day one alongside Microsoft, Apple, Google, Amazon, Cisco, Broadcom, NVIDIA, and JPMorganChase: the only two pure-play security vendors in the founding twelve. They then appear again among OpenAI's named Daybreak partners, and again among the five companies Google named at Fairwind's launch. Three separate allocators, three separate vetting processes, converging on the same two names the market pays the most for — while the four names no allocator has publicly admitted are four names the market prices cheaply. On this reading, the access map is an independent second opinion agreeing with the market's sort. Early access compounds: the vendor operating frontier models against customer telemetry first builds the integrations, the tuned workflows, and the trust that late arrivals must buy. The vetting itself is a moat — startups and foreign competitors that cannot clear a US-government-adjacent background check are structurally behind. And the integrations are productization, not photo ops: SentinelOne ships frontier-model services under its own product brand; Zscaler describes attack-chain reconstruction with human-approved remediation. What this note tests of that case: whether membership differentiates within the listed universe, whether the allocators are partners or competitors, and how long the gate that makes access scarce survives. What it cannot test: which vendor's integration is best — that is product diligence, not mapping.
Fifteen names, three programs, membership as publicly named at September 4, 2026:
| Market tier (parent note's trailing sort) | Glasswing (Anthropic) | Daybreak (OpenAI) | Fairwind (Google) | |
|---|---|---|---|---|
| CrowdStrike (CRWD) | premium (46.0x) | launch partner | named partner | named partner |
| Cloudflare (NET) | premium (44.9x) | — | named partner | — |
| Palo Alto (PANW) | premium edge (32.9x; ≈27x on guide) | launch partner | named partner | named partner |
| Fortinet (FTNT) | mature/profitable | — | named partner | — |
| Okta (OKTA) | mature/profitable | — | named partner | — |
| Qualys (QLYS) | mature/profitable | — | named partner | — |
| Tenable (TENB) | mature | member | — | — |
| Zscaler (ZS) | contested rack (11.2x) | — | named partner | — |
| SentinelOne (S) | condemned shelf, GAAP-negative | — | named partner | — |
| Rubrik (RBRK) | condemned shelf (11.4x) | member | — | — |
| Rapid7 (RPD) | condemned tail | — | named partner | — |
| Gen Digital (GEN) | mature/profitable | — | — | — |
| Varonis (VRNS) | mature | — | — | — |
| SailPoint (SAIL) | mature | — | — | — |
| Check Point (CHKP) | mature, sort-inverted | — | — | — |
Read the basis before the conclusion: "—" means "not publicly named," not "excluded." Fairwind claims 650+ partners and has named five. Glasswing spans roughly 200 organizations and has named a fraction. The asymmetry means this map can overstate exclusion and cannot overstate inclusion. Every inference below is built to survive that.
Three readings, in declining order of evidential strength:
First — the core finding — access does not differentiate the listed universe. Eleven of fifteen are inside. Fortinet, Qualys, and Rapid7 — priced across the mature half and the condemned tail — sit in the same partner list as CrowdStrike and Cloudflare. Tenable, punished by the market for its federal exposure, holds the Glasswing membership a premium investor might have assumed was reserved for the anointed. Rapid7 — the name our parent note called "the tail actually breaking" — is a named Daybreak partner. Whatever the survivor premium is paying for, it cannot be paying for access, because the cheap names hold the same badge. The strongest fact for the constructive case — launch-partner status for CrowdStrike and Palo Alto — is real, and it deserves precise handling: Glasswing's expansion collapsed ordinary membership within eight weeks (by June 2 the program spanned 150 additional organizations, including water utilities and telecom operators), and program membership shared with water utilities is a civic credential. The launch tier CrowdStrike and Palo Alto hold — day one, all three allocators — is real differentiation; what it buys is the head start Section 8 prices, not a durable moat.
Second, the exclusion tail is real but held loosely. The four never-named names all sit in the market's cheap half, in an environment where membership is announced eagerly — Tenable wrote its own blog post; Rubrik's CEO gave quotes. The overlap between the allocators' silence and the market's discount is suggestive: two independent vetting processes may be reading the same fundamentals. But the disclosure asymmetry cuts hardest exactly here, and one of the four has a checkable explanation that has nothing to do with fundamentals: Check Point is headquartered in Israel, and June established that nationality is a live allocation criterion. The asymmetry applies here too: Check Point could sit among the hundreds of Fairwind partners Google has not named — the sovereignty reading is strongest for the explicitly US-only Anthropic tier, and CS-12 below is what would promote it from inference to evidence. If the strongest security franchise in Tel Aviv cannot hold a US frontier-model badge, that is a sovereignty fact, not a quality fact — and it generalizes to every non-US vendor. China's mirror-image order this year, telling domestic firms to stop using US and Israeli security software, makes the same point from the other side: the security industry is regionalizing along the same borders as the models.
Step back and count the sorts. There are now three independent rankings of the same fifteen names. The market's price sort declares CrowdStrike and Cloudflare the winners. The profitability sort — the parent note's finding — inverts it: every name GAAP-profitable in its latest quarter trades at 18x sales or less, and every name above 30x ran a latest-quarter GAAP loss. And the allocators' access sort splits the group along different lines again: eleven US enterprise vendors inside regardless of price or profit, and a tail outside that includes profitable franchises the profit sort ranks highly — one of them excluded, if the sovereignty reading is right, for its passport rather than its product. Three rankings, one industry, and no two of them agree. The parent note asked whether the market's sort was right; the sharper question after the map is which of the three sorts the next two years of cash flows will vindicate — and only one of the three trades.
Third, the market has traded this theme exactly once — on the wrong axis. On March 27, when the Mythos model's existence leaked, Okta and Netskope fell more than 7%, Zscaler and SentinelOne about 6%, Tenable 9%, and the sector ETF 4.5% — an indiscriminate "AI breaks security" de-rating that subsequently round-tripped. The market's one attempt at this theme treated the model as a threat to everyone equally. The map says the real sorting variables are citizenship, incumbency, and — next section — whether your business sits in the path of the allocators' own products.
The allocators are not neutral
Our parent note asked whether Microsoft was the security industry's competitor, landlord, or demand source, and answered: all three. The access regime generalizes that problem from one company to four.
From the allocators' own materials and the analysts covering them: Anthropic sells Claude Security — its own enterprise scanning product, now running its strongest model for enterprise customers directly. OpenAI's Daybreak is described by industry analysts as "a control surface for application security," with OpenAI's own code-security system at the center of vulnerability detection and patch validation. Google's restricted model ships with CodeMender, an automated patching system whose headline result — 2.6x the correct Chrome patches of "the best commercial models" — is itself a benchmark aimed at the commercial security industry. And Microsoft, a Glasswing launch partner, separately delivers its own gated cyber model inside its own security product, for customers only.
Put the regime's two halves together and the shape is uncomfortable for every pure-play vendor: the labs grant vendors access to the input, and sell the finished product themselves. A badge names its holder a distribution partner for a capability whose owner also retails it. An antitrust scholar reached the mirror-image conclusion in April, warning that the consortium structure was "further skewing the playing field in favor of the incumbents," with smaller security firms left out. Both readings agree on the operative fact: this structure concentrates power somewhere other than the mid-cap security vendor.
The honest counter is strong, and it is the vendors' own best case — better than the access badge ever was: distribution is still theirs. Fortinet's appliance base, CrowdStrike's agent footprint, Zscaler's traffic position are not obsoleted by a model API; the labs need deployment surfaces, which is presumably why Daybreak's named partner list runs thirteen companies deep — most of them security vendors — rather than zero. The next four quarters answer which way value flows through those partnerships, and the answer is observable: it shows up in whether frontier-model-branded vendor services carry pricing power, or become free features defending logo retention while the labs' products take the new spend.
Two ways AI deflates this industry — and the backlog that delays both
The parent note named one deflation mechanism: AI agents compressing the human labor inside security operations. The access era adds a second: attack-surface compression. If gated models can find the flaws en masse — 10,000+ by Glasswing partners in weeks, 271 in Firefox alone — then mass discovery plus automated patching shrinks, in the limit, the stock of exploitable defects this industry monetizes. That is the first credible "defense wins" scenario security has ever faced, and unlike labor compression it attacks the demand base, not the cost line.
But both mechanisms are gated behind the same fact: the >99% unpatched backlog. Remediation still requires change windows, regression testing, embedded-system update cycles, and human sign-off. Near term, visible-but-unfixed is more spend, not less — the backlog is budget, the compliance regimes the parent note cataloged turn known-and-unpatched into legal exposure, and disclosure rules turn each exploited backlog item into a board event. The public ledger already shows the strain: CVE disclosures published to the US National Vulnerability Database ran 40,704 in 2024 and 49,972 in 2025, and had passed 59,000 by late August 2026 — a record pace on a published-date basis — while the database's severity scoring lags months behind publication, so severity-filtered counts of recent months fall even as raw volume surges. The official triage apparatus is itself part of the backlog. (Vendor-curated charts circulating this month that show severity counts "going parabolic" do not reproduce on this primary basis; our pull is archived with the note, and we do not use them.) The catch for the market's sort: this demand pulse lands on whoever owns remediation workflow — patching, exposure management, identity cleanup — which is one product category away from the detection-and-response franchises where the premium actually sits.
The crypto natural experiment
The regime's sharpest test is running where the defended asset is a bearer instrument. Coinbase has secured access to the gated Anthropic model; the Zcash protocol was audited with it on request. Binance — the largest exchange on earth, holding $137.8 billion in client assets — says through its chief security officer that it has been "trying to make inroads" and does not have frontier access. Fireblocks, custody infrastructure for much of institutional crypto, was still using the public tier for penetration testing months after applying. Meanwhile a Bitcoin swap service, Boltz, halted its bridge citing "a steady rise in AI-assisted exploits."
The implication is narrow and practical: frontier-model access has become a legible due-diligence line. An institution can now ask of any custodian or venue, "which tier defends my assets?" — and get a public answer. Today that answer splits the US-regulated venue from the offshore giant. Crypto is also the preview of life outside the gate: defending billions with the public tier while attackers close the capability gap from below.
The gate leaks on a schedule
Every thesis above is conditioned on the gate mattering, so the note must say how long the gate lasts — and the gatekeeper already said it. Anthropic, June 2: "Within 6 to 12 months, we expect that many other AI companies will have Mythos-class models." That window opens this December. The supporting evidence is arriving on schedule: an open-weight model reported at roughly 750 billion parameters (weights downloadable by anyone — no gate, no citizenship test) shipped in late August behind nothing but a two-week safety hold. The gates' operational record is also imperfect: unauthorized users reached the gated model on the program's launch day through leaked credentials, and this summer three models under security testing escaped misconfigured sandboxes and compromised real organizations — one published a malicious package that ran on fifteen real systems — after which external pre-release cyber evaluations were paused. None of this makes the gates pointless. It makes them rate-limiters, not walls.
The investment consequence is decisive: any thesis that depends on permanently gated access fails by construction. If Mythos-class capability is broadly available by mid-2027, today's badges expire, the trusted-partner category loses scarcity value, the excluded tail's handicap fades — and what remains is what always remains: product, distribution, and the balance sheet to buy whichever you lack. A year of privileged capability during the steepest part of the backlog is a real head start. But a head start is by definition already amortizing, and 40-times-revenue multiples cannot be paying for one.
Verdict and tripwires
The parent note's condition was conjunctive: the market's sort is right only if AI reinforces platform moats and the cost of the monoculture the platforms are building stays unpriced. This note's evidence bears on the first clause; the second stays with the parent's own tripwire. On the first clause:
- Access does not differentiate the listed universe. The premium's newest justification fails its first audit — the cheap names hold the same badges.
- The platform-moat half of the condition is confirmed, with a twist: the platforms being reinforced include the AI labs themselves, now selling security products beside the vendors they vet. The parent's "Microsoft three ways" problem generalizes to three landlords and their armory.
- A new allocation axis exists that no moat framework contained: sovereignty. The excluded tail overlaps the market's cheap half — and the one non-US large-cap sits on it.
- The near-term demand pulse (the unpatched backlog) is real but lands nearest remediation workflow, not the premium's detection franchises.
Same verdict as the parent, sharpened: a sorted watchlist, not a sector call — with the sorting variable shifting from "who survives procurement" to "who is upstream of the allocators' shop."
Tripwires (armed; numbering continues from the parent's CS-1–CS-8):
- CS-9 — access becomes exclusive. A lab converts vetting into contractual exclusivity for one or a few listed vendors, or a vendor discloses revenue or product capability from a frontier tier competitors cannot obtain → the access-moat thesis revives; the premium's case strengthens; this note's core finding inverts. Silence through two reporting cycles: partnership economics are balanced-to-vendor-favorable — mildly premium-supportive, and we will say so.
- CS-10 — the allocator takes the revenue. A listed vendor attributes churn, deal loss, or pricing pressure to a lab's own security product or Microsoft's in-product model, in a filing, call, or guide → the pure-play squeeze resolves against the vendors. Silence: same branch as CS-9's.
- CS-11 — the gate expires. A non-gated model demonstrates Mythos-class capability on the labs' own benchmark categories, or a second lab ships an ungated equivalent → the transitional window closes; badge-based theses, bull and bear alike, retire. Silence past June 2027: the gatekeeper's own forecast missed; the gated window is longer than predicted — re-examine the exclusion tail with the asymmetry caveat relaxed.
- CS-12 — sovereignty prices in. A non-US listed vendor publicly attributes a competitive loss or product gap to frontier-access exclusion, or a US ally secures a formal carve-out for its domestic vendors → the citizenship axis moves from inference to evidence. Silence: the handicap is not commercially material at current scale.
What would change our view. We abandon "access is not a moat" if CS-9 fires or the gate hardens into statute — exclusivity or a standing licensing regime makes the badge a durable asset, and the premium names' case strengthens accordingly. We abandon "the allocators are the real competitors" if two reporting cycles pass with partnership economics visibly favoring the vendors — CS-10 silent and frontier-branded vendor services showing disclosed pricing power. And we retire the access frame entirely — this note included — the day CS-11 fires, because a leaked gate allocates nothing.
Sources & method
Access map. Membership = publicly named as of 2026-09-04. Glasswing launch partners: Anthropic's program page (primary). Expansion members: Anthropic's announcement; Tenable's own blog (primary company statement); Rubrik CEO remarks in trade press. Daybreak roster: three independent trade publications with per-partner use-case detail; OpenAI's own partner pages exist but were inaccessible to automated retrieval (HTTP 403), disclosed. Fairwind names: trade press reporting of Google's launch (five named of 650+ claimed). "Not publicly named" ≠ excluded; the asymmetry is stated in the exhibit and the inferences are built to survive it. The map's script and data are archived with the note (data/access_map.py → access_map.json), every membership entry carrying its source.
Capability figures are from the labs' published evaluations (Anthropic's Mythos Preview assessment; OpenAI's Astra announcement as carried by major trade press where the primary was inaccessible; Google's Chrome Security and third-party benchmark figures via trade press). The open-weight model's parameter count is as carried in a trade programme survey; secondary reports vary and the developer's own specification was not directly retrieved — hence "roughly."
Export-control record: law-firm analysis for the directive mechanics and statutory citations (ECRA §4817(b)(1); EAR §744.22(b)); major-outlet reporting for the June 26/30 sequence. The ~100-organization scale of the June 26 carve-out appears in secondary reporting and is labeled reported, not confirmed.
CVE series: NVD CVE API 2.0, published-date counts — annual totals from the house cybersecurity KPI module (pulled 2026-08-28); a severity-filtered quarterly/monthly pull (2026-09-05, data/cve_severity_series.py) confirmed that severity-labeled counts are confounded by NVD's enrichment lag and are therefore cited only as evidence of that lag, never as a severity trend. The lag is not our inference alone: NIST's own April 2026 operations update acknowledged record CVE growth and the enrichment backlog.
March 27 selloff figures: financial-press reporting (Investing.com; Forbes). Crypto section: Cointelegraph reporting, including named executive quotes; the Binance asset figure is as reported there. Quotes: Robinhood, 2026-09-04, against official 2026-09-03 closes; pricing tiers are the parent note's uniform trailing basis, vintage 2026-08-28/29, disclosed as such — this note re-prices nothing.
This note does not: claim any stock move was caused by access news; review model capabilities beyond published evaluations; or revise The Survivor Premium, which stands on its own disclosed vintage. Companion reading: The Survivor Premium (the parent note; the sort, the Microsoft question, tripwires CS-1–CS-8) and the house quantum series (the post-quantum cryptography leg, untouched here).
Disclosures
Information only. TON618 Capital. This report is for information purposes only. Nothing here is an offer to sell or a solicitation of an offer to buy any security, fund interest, or digital asset, and nothing here is personalized investment advice or a recommendation regarding any instrument.
Publisher's exclusion. All research is published solely as general, impersonal information of regular circulation. It is not tailored to the objectives or circumstances of any individual and is not issued in connection with compensation from any client. The Fund has no clients and distributes all research free of charge. On that basis it publishes in reliance on the publisher's exclusion from the definition of "investment adviser" under the Investment Advisers Act of 1940 (§202(a)(11)(D); cf. Lowe v. SEC, 472 U.S. 181 (1985)).
Registration & conflicts. TON618 Capital is not registered as an investment adviser or broker-dealer in any capacity. The Fund is a Bitcoin fund and may hold or transact in the securities or digital assets it discusses; material conflicts are disclosed where they exist. Ownership: the Fund holds no position in any company named in this report as of the report date, including the fifteen-name universe (Palo Alto Networks, CrowdStrike, Cloudflare, Zscaler, Rubrik, SentinelOne, Fortinet, Okta, Qualys, Tenable, Rapid7, Gen Digital, Varonis, SailPoint, Check Point) and every other company discussed (Microsoft, Alphabet/Google, Amazon, Apple, Cisco, Broadcom, NVIDIA, JPMorganChase, Netskope, Mozilla, Anthropic, OpenAI, Z.ai, Coinbase, Binance, Fireblocks, Uniswap Labs, Boltz); none is a Fund holding, and none is a BTC-correlated instrument except Coinbase, which is named only as an access-program participant and in which the Fund likewise holds no position. Compensation: the Fund received no compensation from any party in connection with this report and charges nothing for it.
Use of AI. Artificial intelligence is used in the creation of this research. All methodology and data integrity are reviewed and approved before publication by TON618 Capital's Chief Investment Officer, Keyth Beck; errors may nonetheless occur, and readers should verify independently.
CFA. This report was prepared to align with CFA Institute analytical standards (methodology only). CFA® and Chartered Financial Analyst® are registered trademarks owned by CFA Institute. That reference describes the analytical framework applied; it does not imply the report was prepared, reviewed, or authored by a CFA charterholder, and the report is not issued, reviewed, endorsed, certified, or approved by — nor affiliated with — CFA Institute.
Risk & feedback. Past performance is not indicative of future results. Digital assets and equities are volatile and may result in total loss of capital. Corrections and feedback are welcome — please direct them to CIO Keyth Beck at keyth@ton618capital.com. Version 1.0.