Vectant

How the vault is meant to hold

Reserves are designed to leave the source chain only with an M-of-N signature. Canton is not supposed to be able to drain the vault. No audit report is published yet.

Security model

Built so no single party can break it

The source-chain multisig is the hard boundary. A compromised Canton side could, at worst, mint an unbacked token. A certificate of reserves is meant to catch that, and that certificate is not published yet.

No single point of failure

Threshold M-of-N on both chains, run by independent operators. The system keeps running when one node drops.

Reserves leave only via multisig

Funds can be released only by an M-of-N signature on the source chain. No Canton action can drain the vault.

Non-upgradeable vault

Fixed contract code, per-transaction and daily caps, a pause switch, and replay guards on every release.

Verifiable backing

Supply and reserves are designed to be reconciled continuously. A public certificate for every instrument is planned, and none is published yet.

Audited before mainnet

Before any asset reaches mainnet, the vault, the watcher, and the Canton wiring are planned to be independently audited, and a certificate of reserves published. No audit is published yet.

Private by default

Canton settlement is confidential. Counterparties see only what they need, with permissioning at the ledger level.

Proof of reserves status: no certificate and no audit report are published.