// pcp-1 · draft standard

A portfolio token that carries its own proofs. Any wallet or contract on Robinhood Chain can ask it: is your NAV right, are you following your rules, what do you lose in a crash, who runs you — and get a verified answer without seeing a single position.

Query a portfolio

$ cast call $LENS "attestation(address)" nocturne.vault
Attestation {
  navPerShare: 1.595058
  epoch: 540
  lastProofAt: 1790629200
  stale: false
  mandateHash: 0x890541adee037147…
  worstStressLossBps: 1900 /* 19.00% */
  riskFresh: true
  hasTrackRecord: false
}

// SealedCollateralOracle.price()
1.212244 USDC/share (haircut 24.0%)

// not in the response: holdings · weights · trades · timing · manager wallet

Private, yet composable

Until now a portfolio was either public (and copyable) or private (and useless to DeFi). A proof-carrying portfolio is both private and usable as collateral, in indexes, or in structured products.

Risk you can price without seeing

Stress tests are proven against the sealed state each epoch. Lenders size haircuts from proven worst-case losses, not from trust.

Talent → capital, verifiably

A vault can only be launched from a verified Proof of Alpha. The track record is bound to the vault forever.

The interface

contracts/src/interfaces/IProofCarryingPortfolio.sol

interface IProofCarryingPortfolio {
  struct Attestation {
    uint256 navPerShare;        // proven NAV
    uint64  epoch;              // last proven epoch
    uint64  lastProofAt;
    bool    stale;              // proofs stopped
    bytes32 mandateHash;        // public, immutable rules
    uint16  worstStressLossBps; // Proof of Risk, all scenarios
    bool    riskFresh;          // proven on current epoch, < 48h
    uint256 trackRecordClaimId; // Proof of Alpha at launch
    bool    hasTrackRecord;
  }
  function attestation(address portfolio)
    external view returns (Attestation memory);
}

Integrate as collateral

contracts/src/SealedCollateralOracle.sol

// A lending market on Robinhood Chain accepting sealed-vault shares as collateral.
// It never learns what the vault holds — only what has been proven.
SealedCollateralOracle oracle = new SealedCollateralOracle(
    lens,          // PCP-1 lens
    vault,         // sealed vault share token
    500,           // +5% buffer over the worst proven stress loss
    1_500          // never less than a 15% haircut
);

uint256 p = oracle.price();   // 0 if NAV or risk proofs are stale
require(p > 0, "collateral unproven");
uint256 maxBorrow = shares * p / 1e18 * ltvBps / 10_000;

* Performance figures are simulated — not a real track record and not investment advice.

Stress results disclose coarse aggregate risk by design — scenarios are few and coarse to limit what can be inferred about holdings.