No single point of failure
Threshold M-of-N on both chains, run by independent operators. The system keeps running when one node drops.
Vectant
Reserves are designed to leave the source chain only with an M-of-N signature. Canton is not supposed to be able to drain the vault. No audit report is published yet.
The source-chain multisig is the hard boundary. A compromised Canton side could, at worst, mint an unbacked token. A certificate of reserves is meant to catch that, and that certificate is not published yet.
Threshold M-of-N on both chains, run by independent operators. The system keeps running when one node drops.
Funds can be released only by an M-of-N signature on the source chain. No Canton action can drain the vault.
Fixed contract code, per-transaction and daily caps, a pause switch, and replay guards on every release.
Supply and reserves are designed to be reconciled continuously. A public certificate for every instrument is planned, and none is published yet.
Before any asset reaches mainnet, the vault, the watcher, and the Canton wiring are planned to be independently audited, and a certificate of reserves published. No audit is published yet.
Canton settlement is confidential. Counterparties see only what they need, with permissioning at the ledger level.
Proof of reserves status: no certificate and no audit report are published.