> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tayho.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Independent security review scope

> Blocking contract and operational-plane review scope and evidence required before Tayho production launch.

# Independent launch review scope

An independent reviewer must sign off both planes before production. Repository tests and the
internal review workflow are evidence, not a substitute for independent review.

The contract review covers role assignment, Permit2 session limits, stateless signed-intent execution,
hard and session cancellation races, nonce replay protection, OCO and percentage/whole-position closes,
per-child maintenance batching, liquidation and oracle failure modes,
vault solvency, FIFO claims, freeze/resolution behavior, upgrade/owner powers, and all existing
adversarial regression tests.

The operational review covers the signerless public Elysia API/private engine/private relayer boundary, encrypted executable
payloads and local versioned intent-key rotation, soft-reservation oversubscription/funding loss, durable
lifecycle legality, PostgreSQL RLS/column grants, Redis-as-derived-state rebuild fencing and checksum drift,
market checkpoint quorum/reorg behavior, duplicate and cancellation/execution races, microbatch gas limits,
least-privilege signer separation, encrypted journal key rotation,
nonce and replacement invariants, RPC quorum independence, Postgres/Redis recovery, queue fencing,
audit immutability, trace/metric data leakage, Railway secret handling, image provenance/SBOM,
dependency and container scanning, incident commands, restore evidence, and 24-hour injected-failure
soak results. It also covers the Ponder writer/query boundary, isolated database ownership,
deployment-schema/view promotion, earliest-start-block completeness, event-key idempotency, block-pinned
contract reads, reorg rollback, RPC failover, bounded REST queries, GraphQL exposure, and proof that
off-chain automatic-order state cannot enter the on-chain projection.

The review also covers API-key hashing, scope/origin/CIDR/quota enforcement, receipt-capability
isolation, relayed session/add-margin/vault/staking actions, the closed public route allowlist, and
proof that Ponder is the only `eth_getLogs` consumer. Auditor independence comes from restricted
database identity and bounded RPC-quorum verification, not from a competing log scanner.

Required evidence: reviewed commit SHA, deployed image digest, SBOM, BuildKit provenance metadata,
threat model, findings with severity and disposition, restored-database drill record, Redis rebuild
record, RPC partition/reorg record, indexer replay/PITR/reorg record, engine/relayer failover record, signer/intent/journal-key rotation
record, 5,000-burst and 1,000/s load profile, 24-hour soak report, and named
reviewer approval. Open critical/high findings block launch; accepted medium findings require an
owner and deadline.

The deployed Railway digest must equal the provenance subject exactly. A successful CI build is
not sufficient evidence if Railway rebuilt the repository or resolved a mutable image tag.

Use the [Security model](/operations/security-model) as the threat-boundary index and the
[launch checklist](/operations/launch-checklist) as the blocking approval manifest.
