Provably fair, forever verifiable
HMAC-SHA256 over a server seed committed before the round, a client seed the player controls, and a nonce. The commitment hash is published up front and every historical round stays verifiable after a seed rotation — fairness is versioned, so old games never break.

