reserve-attestation — proof of reserve
Designated attestors (an auditor, a custodian bank, the issuer’s treasury) post the current off-chain reserve balance. Anyone can check backing before transacting.- Quorum — with
quorum = n, a report is finalized oncendistinct attestors have submitted for the current round. The lowest submitted amount is published, so one attestor over-reporting can’t inflate the reserve.quorum = 1is a single-poster setup shaped likemanual-oracle. - Staleness —
is_stale()is true with no report, or once the latest report is older thanstaleness_thresholdseconds. A half-filled round older than the threshold is discarded on the next submission. - Units — amounts are in the asset’s smallest unit (same decimals as the token), so
they compare directly against its live
total_supply.
is_fully_backed() = fresh report and reserve ≥ the asset’s live total_supply.
compliance-policy — freeze, clawback, transfer rules
Beyond the yes/no identity gate, regulated issuance usually requires the issuer to be able to freeze or reverse a specific holder’s balance (court order, fraud, sanctions). Every fungible template (farmland, commodity, real estate, invoice, carbon credit, mining rights) now has an optionalcompliance_policy slot. When a policy is attached, the token
asks it can_transfer(token, from, to, amount) before every transfer, mint (from = None)
and burn (to = None). With no policy attached, tokens behave exactly as before.
The reference compliance-policy contract enforces:
- Freeze — a frozen account can’t send, receive or burn. The reason (e.g. a court-order reference) is stored on-chain.
- Per-transfer cap — optional maximum for holder-to-holder transfers (mints and burns aren’t capped).
- Clawback — forced burn, or forced transfer to a recovery address. Works even while
the holder is frozen. Only the attached policy contract can trigger a token’s
clawback, so a token without a policy can never be clawed back.
One policy can serve every token an issuer runs; freezes apply to all tokens pointed at it.