None of these is a promise. Each one is the absence of a function, which is a thing you can check in the bytecode rather than a thing you have to believe.
There is no mint function anywhere. Not for the operator, not for the chip's owner, not for the factory. A billion units exist and that is the end of it.
step() takes no owner check. Whoever pays the gas takes the cycle and is written into the event as its sponsor.
The only door out of the mining reserve is a step. There is no path that moves the token in bulk, including for whoever deployed the thing.
It is pure, holds no state and has no owner. The silicon your chip runs on is the silicon it will always run on.