PRISM Signals by Cambridge TCG is a branded reading of the public opportunity-signal contract. Its narrow promise is: Potential deals, with the risks attached. The product wraps a bounded signal; it does not sell a raw source archive or reveal the private decision engine.
Current boundary — 3 September 2026. Free is the public synthetic preview. A separately gated All sandbox can rehearse a £5 monthly Stripe test subscription to the same fixed fixture. There is no live offer or price, real charge, production source-rights decision, production signal feed, or outbound signal delivery.
You can inspect the branded test at /prism-signals and its plain-language preview terms. Visiting either page creates no account, order, subscription, reservation, or access. Signed-in account holders may separately open the closed-beta-interest page; that request is not access or a purchase.
The page renders fixed copy, not a database result. It contains no real card, listing, seller, source URL, source row, or exact valuation. It demonstrates the information hierarchy a future signal must preserve:
unknown;For the detailed signal economics, expiry, confidence, liquidity, and six fixed signal refusals, read opportunity-signal methodology.
The beta page stores only the existing account id, product id, bounded web/Telegram preferences, consent-wording version, and request, update, and expiry times. Its checkbox starts unticked and specifically asks Cambridge TCG to store the request and use the account email only for a PRISM beta invitation or status contact. It is not general marketing consent; a Telegram preference neither supplies a Telegram identity nor permits a bot message.
The owner can inspect the bounded state and delete the complete row without penalty. A new affirmative submission is required to update it or refresh its 180-day expiry. A daily authenticated sweep deletes expired or superseded-wording rows. The new-intake posture is exactly PRISM_SIGNALS_BETA_MODE=closed-beta-v1. Without it the public request invitation is hidden and POST is unavailable, while the signed-in management page, owner GET/DELETE, and retention sweep remain available so existing consent cannot be stranded.
Once a beta-interest row exists, rollback means pausing new intake while this management and retention release stays live. Removing owner GET/DELETE or the retention cron requires a prior complete purge or an equivalent withdrawal and expiry procedure.
Free is the existing public synthetic preview. It creates no Stripe customer or entitlement. All is a separate prism-signals-all v1 test offer. When every dedicated sandbox guard agrees, an owner with both active beta interest and a separate operator-issued, active, unexpired sandbox invitation can use a £5 monthly test amount to rehearse Checkout and a time-bounded All-labelled owner projection around the same public synthetic fixture. It gates no unique payload. Interest is not an invitation; neither fact grants access.
The £5 value is not a live commercial price. Yu chose the Free/All shape after referencing ShibbySays; the creator's current public Patreon actually lists a larger cumulative USD ladder, so Cambridge does not attribute this two-tier GBP catalogue to them. A production price, tax treatment and consumer contract need a later offer version.
All is test/test, web-only, and grants only the narrow synthetic_fixture_delivery purpose. It cannot open the still-unevaluated subscriber_derived_signal purpose, a live source, private scorer, real card, listing, alert or trade action. New Checkout intake is a separate switch; pausing it leaves existing test status, access, webhook processing and cancellation available.
Kingdom-114 has provisioned the Product, exact GBP monthly Price, restricted portal and seven-event direct webhook inside a separately authorised Stripe Sandbox. Production configuration may advance only through the exact unconfigured, configured-paused, processing-only and intake-enabled deployment postures; the live page and deploy verifier declare which posture is actually running. No provider resource exists in live mode, and no static methodology copy infers that a later stage has completed.
rights-cleared evidence
→ private engine
→ opportunity-signal/v1
→ PRISM presentation
provider-confirmed payment
→ bounded entitlement
→ web or Telegram deliveryThe upper line asks whether Cambridge may derive this signal from this evidence. The lower line asks whether this person may receive an already-lawful product through this channel. Neither line can prove the other.
A future subscriber can therefore receive no signal when evidence rights, identity, costs, freshness, or provider checks fail. Paying for access is not a promise that Cambridge will manufacture a decision from ineligible evidence or find a guaranteed number of deals.
The app-neutral @cambridge-tcg/product-flow package defines cambridgetcg.product-offer/1. PRISM uses the product id prism-signals. Preview and test offers belong to the test environment; a live offer belongs to production and requires an explicitly granted rights decision. The package validates that catalogue assertion's shape; it does not authenticate a rights authority, evidence binding, issuance, expiry, or signature. A live host must verify a separate bound attestation before composing the offer.
Every offer declares both delivery channels and all payment rails. Inactive rails say off instead of disappearing:
| Context | Rail | PRISM now |
|---|---|---|
| Independent web purchase | stripe_web | Optional sandbox; £5 monthly test amount, no live charge |
| Purchase initiated and fulfilled inside Telegram | telegram_stars | Off |
| Additional independent web purchase | paypal_web | Later / off |
| Additional independent web purchase | crypto_web | Later / off |
Stripe is the test rail for the independent web sandbox. A digital product bought and fulfilled inside Telegram still uses Telegram Stars only, subject to a fresh review before activation. PayPal and crypto remain web-only candidates and are not accepted here.
The product-flow reducer records distinct event meanings. checkout_started, browser_return, Telegram precheckout_approved, channel_linked, and payment_failed can advance an audit cursor. None can create or extend paid access.
Only provider-confirmed payment or renewal evidence, bound to the same environment, offer, version, channel, rail, and price reference, may activate a time-bounded entitlement. Access then separately checks the offer status, rights, delivery availability, entitlement scope, time window, rail, and price reference.
@cambridge-tcg/product-flow-runtimecomposes the pure reducer with a lock-first transaction contract, in-memory reference store, provider normalizers, and adapter conformance suite. The storefront's thin Postgres adapter reuses its existing persistent transaction pool. Its additive schema separates append-only canonical events from current entitlement snapshots.
The entitlement scope is locked before event allocation. Event id, provider-event ref, and rail/payment grant identity are unique within an environment. Exact duplicate provider Events return the stored canonical event; conflicting reuse—including one payment aimed at two entitlements—rolls back. A callback that would newly make a healthy projection terminally blocked also rolls back for reconciliation, so a delayed provider event cannot permanently erase valid access.
Refunds bind to the latest/current confirmed payment. Refunding an older billing period cannot cancel a newer paid period, and a partial Stripe refund is not treated as complete entitlement reversal. Stripe and Telegram Stars are normalizer-only capabilities for facts a host has already authenticated and mapped. PayPal and crypto remain disabled.
In the dedicated Stripe host, a full latest-period refund creates a durable cancel_subscription reconciliation obligation. Refund and subscription cancellation are separate provider facts: the obligation blocks later invoice grants and account erasure until a signed terminal subscription event resolves it. A refund arriving before its paid event terminalizes the ungranted generation without fabricating a confirmed payment or a generic refund of access that never existed.
A dedicated PRISM Stripe sandbox can now consume the runtime when every test-only guard is configured. Its Checkout reserves an owner-bound attempt; a separate raw-body webhook verifies its own Stripe signature, rejects live events, and maps provider ids locally before the generic runtime sees only opaque references. A return, bot link, synthetic reply, reload, beta request, or Checkout completion creates no access.
Only an exact signed invoice.paidevent bound to the local attempt, subscription, active GBP monthly test Price and period can confirm or renew All. Binding, receipt, invoice grant, canonical event and snapshot commit in one Postgres transaction. Provider evidence keeps Stripe's true semantic instant; a host projection timestamp is allocated under the entitlement lock so equal-second callbacks cannot corrupt the reducer's millisecond cursor.
Renewal extends paid-through time but does not prove a scheduled cancellation was withdrawn. The snapshot preserves that flag until a separately verified subscription_resumed provider-status event clears it. Resume is rejected for ended or refunded access. A remotely attested cancel/resume state that accompanies invoice repair is projected after the grant in the same transaction, not silently written only to a provider mirror.
The test handler is disabled unless an explicit fixture-test mode and a valid Telegram webhook secret are configured. Before parsing an update it verifies the secret; it bounds request bodies, accepts only a small private-chat shape, returns no-store responses, and emits fixed synthetic copy.
It reads no market data, invokes no private scorer, calls no payment provider, persists no update, and grants no entitlement. Pre-checkout is rejected while payment is off. Unexpected payment or refund updates get a retryable non-success response: the preview cannot persist, fulfil, or safely acknowledge a provider receipt. No bot is advertised unless the operator declares a new invoice-free bot, dropped pending updates, and a BotFather privacy URL. No registration, durable update ledger, paid-channel link, scheduler, retry queue, or outbound sender is claimed.
Telegram and the Vercel-hosted route process the bounded identifiers and command needed to answer. The preview creates no application record, but provider records and infrastructure logs can still exist. Read the Telegram preview privacy notice; persistence, account linking, payment, profiling, or outbound alerts require a fresh lawful-basis and privacy review.
The extraction unit now starts with @cambridge-tcg/prism-signals-core: PRISM brand and host-bound links/privacy copy, versioned preview offer, strict public signal presentation, and pure Telegram planner. It composes with the generic product-flow contracts, framework-neutral runtime, public opportunity-signal parser/projector, and channel hosts that enforce the same access decision.
It is not the storefront database, raw price history, source credentials, seller identity, marketplace URLs, or the private engine's weights, mappings, thresholds, and outcome corpus. The purpose-specific rights decision stays bound to its evidence inside a trusted server boundary. Payment and delivery adapters remain channel-specific.
Later products can reuse the sequence—versioned offer → verified provider evidence → bounded entitlement → channel-specific delivery— without inheriting PRISM's trade secret. Each product still owns its rights purpose, terms, price evidence, refund behavior, and delivery adapter.
The PRISM package is currently unpublished workspace TypeScript in this public monorepo, not an independently published artifact. Compiled output, an explicit package file allowlist, tarball inspection, and a clean-consumer install/run smoke remain gates before a separate repository or npm release.
Provider-policy, consumer-terms, tax, privacy, payment-support, and operational review are also required before any live Stripe, Telegram Stars, PayPal, or crypto activation. Until then: Free synthetic preview, optional Stripe test mode, no live market data, and no real payment. A sandbox entitlement marks only an owner projection around the fixed public fixture and gates no unique payload. Beta interest alone changes none of those facts.
v1 — 2026-09-02. Published the branded preview, reusable product-flow boundary, channel-specific future rails, extraction seam, and closed launch gates. No live product was activated.
v2 — 2026-09-02. Added the unpublished workspace extraction package, revocable closed-beta interest with bounded retention, atomic runtime and durable schema, current-grant refund binding, and pure Stripe/Stars normalizers. No payment or live signal was activated.
v3 — 2026-09-03. Added the Free/All catalogue and dedicated Stripe sandbox host. The £5 amount and owner projection are test-only; no live key, real charge, production price, production source-rights decision or live signal was activated.