Architecture Security Model
Assets, invariants and dependency failures that define the security boundary.
#Properties to protect
- Integrity of Stock Token identity, amount and multiplier state.
- One-to-one relationship between accounted exposure and call notional.
- Integrity of strike, expiry, premium and terminal observation.
- Uniqueness and conservation of settlement claims.
- Isolation of unrelated markets and positions.
#Threat model
| Actor or failure | Capability |
|---|---|
| Searcher or manipulative trader | Exploit ordering, slippage or temporary price |
| Compromised authority | Change configuration or block a privileged transition |
| Faulty oracle or API | Supply stale, incorrect or mismatched input |
| Adversarial token or adapter | Reenter, pause or violate unit assumptions |
| Broken external market | Remove a reliable price or arbitrage path |
| Robinhood Chain dependency failure | Delay state, price observation or settlement |
#Control principles
- Keep modules narrow and validate state transitions against explicit invariants.
- Minimize privileged authority and make it reconstructable from onchain state.
- Version external dependencies, asset identity and settlement rules.
- Treat liveness failure as a first-class state, not an impossible condition.
- Test rounding, oracle, corporate-action and repeated-settlement boundaries adversarially.