Skip to main content
Two opt-in primitives for anyone issuing a reserve-backed asset (a stablecoin, or any token promising 1:1 backing) or operating under a compliance regime. Both are Stellar-only.

reserve-attestation — proof of reserve

Designated attestors (an auditor, a custodian bank, the issuer’s treasury) post the current off-chain reserve balance. Anyone can check backing before transacting.
  • Quorum — with quorum = n, a report is finalized once n distinct attestors have submitted for the current round. The lowest submitted amount is published, so one attestor over-reporting can’t inflate the reserve. quorum = 1 is a single-poster setup shaped like manual-oracle.
  • Staleness — is_stale() is true with no report, or once the latest report is older than staleness_threshold seconds. A half-filled round older than the threshold is discarded on the next submission.
  • Units — amounts are in the asset’s smallest unit (same decimals as the token), so they compare directly against its live total_supply.
is_fully_backed() = fresh report and reserve ≥ the asset’s live total_supply.

compliance-policy — freeze, clawback, transfer rules

Beyond the yes/no identity gate, regulated issuance usually requires the issuer to be able to freeze or reverse a specific holder’s balance (court order, fraud, sanctions). Every fungible template (farmland, commodity, real estate, invoice, carbon credit, mining rights) now has an optional compliance_policy slot. When a policy is attached, the token asks it can_transfer(token, from, to, amount) before every transfer, mint (from = None) and burn (to = None). With no policy attached, tokens behave exactly as before. The reference compliance-policy contract enforces:
  • Freeze — a frozen account can’t send, receive or burn. The reason (e.g. a court-order reference) is stored on-chain.
  • Per-transfer cap — optional maximum for holder-to-holder transfers (mints and burns aren’t capped).
  • Clawback — forced burn, or forced transfer to a recovery address. Works even while the holder is frozen. Only the attached policy contract can trigger a token’s clawback, so a token without a policy can never be clawed back.
One policy can serve every token an issuer runs; freezes apply to all tokens pointed at it.