// security

No single key controls user funds. Here is exactly who can do what, and what is still missing.

Audit status

Not audited

Do not use with real funds.

Bug bounty

Not launched

Planned alongside the first audit.

Deployment

Not deployed yet

Contracts tested, on-chain launch pending.

Contracts & permissions

ContractUpgradeable?AdminTimelockNotes

Sealed Vault

NoTimelock (replace manager / auditor)72hManager can only submit proofs; can't move funds. Stale after 3 days → deposits close

Risk Registry

NoTimelock (add scenarios; never edit)72hResults valid only for the current epoch and ≤48h

Vault Factory

NoNone—Launch requires owning a verified Proof of Alpha claim

Collateral Oracle

NoNone—Price is 0 whenever NAV or risk proofs are not fresh

Trade Journal

NoNone—Append-only hash chain, block-timestamped

Alpha Registry

NoNone—Claims must cover a real journal head

Price Root Oracle

NoTimelock (poster)72hAppend-only; poster is trusted

Privacy Pool

NoGuardian multisig (pause deposits only)72h (ASP poster rotation)Withdrawals and ragequit can never be paused

Payment Router

NoTimelock (pool allowlist)72hRejects unknown pools

Receipt Verifier

NoNone—Immutable verifier address

Burn Message

NoTimelock (min burn within fixed bounds)72hAppend-only

Treasury

NoTimelock72hAll spending categorised on-chain

Relayer Registry

NoTimelock (slash ≤50%/call)72hPermissionless registration; pool doesn't depend on it

Credential Verifier

NoTimelock (claim types, attestor)72hAttestor posts state roots (trusted)

CPHR token

NoNone—Fixed supply, no mint function

Trust assumptions & open items

  • Vault circuit

    Blocker

    Not implemented. Must prove state transition, mandate compliance and NAV from the price root. Mock verifier accepts forgeries.

  • Shielded custody

    Blocker

    Not implemented. MockCustody holds assets in plain sight — positions would be visible on-chain. The real layer is a shielded multi-asset pool with private batch trading.

  • Stress disclosure

    Proven stress losses reveal coarse aggregate exposure (e.g. roughly how much crypto). Scenarios are few and coarse on purpose.

  • Collateral integrations

    SealedCollateralOracle is a reference. Any lending market using it still needs its own liquidation design and risk review.

  • Price roots

    Posted by a single trusted poster in the MVP. Production: threshold of independent feeds (e.g. Chainlink, Pyth).

  • Securities law

    Tokenized-stock vaults are regulated products. Launch requires licensing, KYC, and auditor view-key access — privacy from the public, not from regulators.

  • ZK circuits

    Blocker

    Not implemented. The mock prover accepts forged proofs. Real circuits + trusted setup (or transparent system) + audit required.

  • Merkle hash

    keccak256 in the MVP. Circuits need a SNARK-friendly hash (Poseidon); tree and circuit must change together.

  • Association sets

    The ASP poster decides which deposits are in the accepted set. It can exclude deposits but cannot take funds: ragequit always returns them to the depositor.

  • Credential attestor

    Posts activity-state roots. Trusted until roots are computed on-chain or via storage proofs.

  • Multisig

    3-of-5 Safe proposes to a 72h timelock; anyone can execute after the delay. Signers must be independent and use hardware wallets.

  • Relayers

    Can delay or refuse a proof, but can't change recipient or fee (bound in the proof). Users can switch relayer or self-relay.

  • Front-end

    Notes are stored in the browser. Production must encrypt notes with a wallet-derived key and offer backups.

Emergency pause — and its limits

  • • The guardian multisig can pause new deposits only.
  • • Each pause lasts at most 7 days, followed by a 3-day cooldown.
  • • Withdrawals and ragequit are never pausable.
  • • No contract has a mint, sweep, or upgrade function.

Privacy limitations

  • • Deposits and withdrawals are public events. Privacy comes from not knowing which deposit funds which withdrawal.
  • • Small anonymity sets, unique amounts, fast withdrawals and address reuse all make linking easier.
  • • Off-chain data (IP addresses, exchange KYC, social posts about a payment) can deanonymise users regardless of on-chain privacy.
  • • Smart contracts may contain bugs. Funds could be lost.
  • • Laws on privacy tools differ by jurisdiction and change. You are responsible for lawful use.