Independent launch review scope
An independent reviewer must sign off both planes before production. Repository tests and the internal review workflow are evidence, not a substitute for independent review. The contract review covers role assignment, Permit2 session limits, stateless signed-intent execution, hard and session cancellation races, nonce replay protection, OCO and percentage/whole-position closes, per-child maintenance batching, liquidation and oracle failure modes, vault solvency, FIFO claims, freeze/resolution behavior, upgrade/owner powers, and all existing adversarial regression tests. The operational review covers the signerless public Elysia API/private engine/private relayer boundary, encrypted executable payloads and local versioned intent-key rotation, soft-reservation oversubscription/funding loss, durable lifecycle legality, PostgreSQL RLS/column grants, Redis-as-derived-state rebuild fencing and checksum drift, market checkpoint quorum/reorg behavior, duplicate and cancellation/execution races, microbatch gas limits, least-privilege signer separation, encrypted journal key rotation, nonce and replacement invariants, RPC quorum independence, Postgres/Redis recovery, queue fencing, audit immutability, trace/metric data leakage, Railway secret handling, image provenance/SBOM, dependency and container scanning, incident commands, restore evidence, and 24-hour injected-failure soak results. It also covers the Ponder writer/query boundary, isolated database ownership, deployment-schema/view promotion, earliest-start-block completeness, event-key idempotency, block-pinned contract reads, reorg rollback, RPC failover, bounded REST queries, GraphQL exposure, and proof that off-chain automatic-order state cannot enter the on-chain projection. The review also covers API-key hashing, scope/origin/CIDR/quota enforcement, receipt-capability isolation, relayed session/add-margin/vault/staking actions, the closed public route allowlist, and proof that Ponder is the onlyeth_getLogs consumer. Auditor independence comes from restricted
database identity and bounded RPC-quorum verification, not from a competing log scanner.
Required evidence: reviewed commit SHA, deployed image digest, SBOM, BuildKit provenance metadata,
threat model, findings with severity and disposition, restored-database drill record, Redis rebuild
record, RPC partition/reorg record, indexer replay/PITR/reorg record, engine/relayer failover record, signer/intent/journal-key rotation
record, 5,000-burst and 1,000/s load profile, 24-hour soak report, and named
reviewer approval. Open critical/high findings block launch; accepted medium findings require an
owner and deadline.
The deployed Railway digest must equal the provenance subject exactly. A successful CI build is
not sufficient evidence if Railway rebuilt the repository or resolved a mutable image tag.
Use the Security model as the threat-boundary index and the
launch checklist as the blocking approval manifest.