Least privilege
Every operator, service and partner receives only the authority required for an approved activity.
Security
The target security model treats keys, identities, policies, providers and operational evidence as distinct control domains.
Every operator, service and partner receives only the authority required for an approved activity.
High-impact actions are designed for independent approval, especially signing, minting, reserve and collateral workflows.
Key-management choices require threat modelling, independent review and audited integration before production use.
Policy decisions, approvals, ledger events, reconciliation and exceptions are designed to produce durable evidence.
Pause, recovery and incident processes are forward-only, rehearsed and human-governed.
A provider compromise should not silently inherit unlimited authority across the ecosystem.
Current boundary