// security
No single key controls user funds. Here is exactly who can do what, and what is still missing.
Audit status
Not audited
Do not use with real funds.
Bug bounty
Not launched
Planned alongside the first audit.
Deployment
Not deployed yet
Contracts tested, on-chain launch pending.
Contracts & permissions
| Contract | Upgradeable? | Admin | Timelock | Notes |
|---|---|---|---|---|
Sealed Vault | No | Timelock (replace manager / auditor) | 72h | Manager can only submit proofs; can't move funds. Stale after 3 days → deposits close |
Risk Registry | No | Timelock (add scenarios; never edit) | 72h | Results valid only for the current epoch and ≤48h |
Vault Factory | No | None | — | Launch requires owning a verified Proof of Alpha claim |
Collateral Oracle | No | None | — | Price is 0 whenever NAV or risk proofs are not fresh |
Trade Journal | No | None | — | Append-only hash chain, block-timestamped |
Alpha Registry | No | None | — | Claims must cover a real journal head |
Price Root Oracle | No | Timelock (poster) | 72h | Append-only; poster is trusted |
Privacy Pool | No | Guardian multisig (pause deposits only) | 72h (ASP poster rotation) | Withdrawals and ragequit can never be paused |
Payment Router | No | Timelock (pool allowlist) | 72h | Rejects unknown pools |
Receipt Verifier | No | None | — | Immutable verifier address |
Burn Message | No | Timelock (min burn within fixed bounds) | 72h | Append-only |
Treasury | No | Timelock | 72h | All spending categorised on-chain |
Relayer Registry | No | Timelock (slash ≤50%/call) | 72h | Permissionless registration; pool doesn't depend on it |
Credential Verifier | No | Timelock (claim types, attestor) | 72h | Attestor posts state roots (trusted) |
CPHR token | No | None | — | Fixed supply, no mint function |
Trust assumptions & open items
Vault circuit
BlockerNot implemented. Must prove state transition, mandate compliance and NAV from the price root. Mock verifier accepts forgeries.
Shielded custody
BlockerNot implemented. MockCustody holds assets in plain sight — positions would be visible on-chain. The real layer is a shielded multi-asset pool with private batch trading.
Stress disclosure
Proven stress losses reveal coarse aggregate exposure (e.g. roughly how much crypto). Scenarios are few and coarse on purpose.
Collateral integrations
SealedCollateralOracle is a reference. Any lending market using it still needs its own liquidation design and risk review.
Price roots
Posted by a single trusted poster in the MVP. Production: threshold of independent feeds (e.g. Chainlink, Pyth).
Securities law
Tokenized-stock vaults are regulated products. Launch requires licensing, KYC, and auditor view-key access — privacy from the public, not from regulators.
ZK circuits
BlockerNot implemented. The mock prover accepts forged proofs. Real circuits + trusted setup (or transparent system) + audit required.
Merkle hash
keccak256 in the MVP. Circuits need a SNARK-friendly hash (Poseidon); tree and circuit must change together.
Association sets
The ASP poster decides which deposits are in the accepted set. It can exclude deposits but cannot take funds: ragequit always returns them to the depositor.
Credential attestor
Posts activity-state roots. Trusted until roots are computed on-chain or via storage proofs.
Multisig
3-of-5 Safe proposes to a 72h timelock; anyone can execute after the delay. Signers must be independent and use hardware wallets.
Relayers
Can delay or refuse a proof, but can't change recipient or fee (bound in the proof). Users can switch relayer or self-relay.
Front-end
Notes are stored in the browser. Production must encrypt notes with a wallet-derived key and offer backups.
Emergency pause — and its limits
- • The guardian multisig can pause new deposits only.
- • Each pause lasts at most 7 days, followed by a 3-day cooldown.
- • Withdrawals and ragequit are never pausable.
- • No contract has a mint, sweep, or upgrade function.
Privacy limitations
- • Deposits and withdrawals are public events. Privacy comes from not knowing which deposit funds which withdrawal.
- • Small anonymity sets, unique amounts, fast withdrawals and address reuse all make linking easier.
- • Off-chain data (IP addresses, exchange KYC, social posts about a payment) can deanonymise users regardless of on-chain privacy.
- • Smart contracts may contain bugs. Funds could be lost.
- • Laws on privacy tools differ by jurisdiction and change. You are responsible for lawful use.