Verification
Watchtower
Monitoring of every admitted asset after it is listed. Rules watch evidence that ends, reviews and reports that fall due, distributions and redemptions against their own dates, screening results, the holder register, facts we hold from two sources, and the chain the assets are on. When one fires, VORUNEX staff are alerted, and a person decides what happens next.
- The pill
- GreenNo open rule has fired in the last 30 days
- AmberAt least one Medium or Low rule is open, or evidence expires within 30 days
- RedA High or Critical rule is open, or a protective flag is set
The rules
57 rules in rule set 2026.10-v10. 34 can fire today; each of the others says why it cannot yet, so a quiet rule is never mistaken for a clean one. Under each rule is what it reads.
| Rule, and what it reads | Severity when it fires | Can fire today | Can be published |
|---|---|---|---|
| Admin key or signer changeOwner and role changes seen on chain on a contract we follow | Critical | Yes | Yes, once approved |
| Record fingerprint refused or changed on chainOur requests to write a record fingerprint on chain | High | Yes | Staff only |
| Units destroyed (burn) seen on chainThe total supply we read from each token contract we follow, compared with our read before it | Medium | Yes | Staff only |
| Chain readings in doubtEach chain's identity and history, compared with what we stored | Critical | Yes | Staff only |
| Published records out of stepEach publication, checked against every place it must appear | Critical | Yes | Staff only |
| Complaint deadline breachedThe deadlines on each complaint | High | Yes | Staff only |
| Compliance case overdueThe due date on each compliance case | Medium | Yes | Staff only |
| Compliance check disagreementOur compliance decisions, recomputed and compared with what was recorded | Critical | Yes | Staff only |
| Compliance switch off for four hoursThe switches that turn a compliance check off | High | Yes | Staff only |
| Largest holder changedThe holder register of each token linked to a listed asset: which wallet holds the most units, and whether one wallet holds more than half | Medium | Yes | Staff only |
| Contract upgradedThe code at each contract address we follow | Critical | Yes | Yes, once approved |
| Data source staleOur own readings of each chain we follow: whether it is making blocks, and how far behind we are | High | Yes | Staff only |
| Distribution past its record date, not yet computedDistributions an issuer or the CRYMAD engine declared: the record date, the stated payment date, and whether what each holder is owed was computed | Medium | Yes | Yes, once approved |
| Distribution not computed by its stated payment dateDistributions an issuer or the CRYMAD engine declared: the record date, the stated payment date, and whether what each holder is owed was computed | High | Yes | Yes, once approved |
| Holders no longer eligibleHolders touched by a published change to a market's rules, and holders found not eligible at the check after a mint | High | Yes | Staff only |
| Evidence expiryThe end date on each piece of evidence held for a listed asset | Medium | Yes | Yes, once approved |
| Holding differs from the chainOur count of each holding, compared daily with the token contract's own answer at the same block | High | Yes | Staff only |
| Insurance lapseThe end date on the insurance evidence held for a listed asset | High | Yes | Yes, once approved |
| Lifecycle request past its deadline with no executor reportLifecycle requests two people accepted for the record (corporate actions, migrations, maturity and wind down, token recovery), each with the deadline for its executor's report, and the reports recorded against it | High | Yes | Staff only |
| Material event past its embargoDeclared material events that are not published yet | High | Yes | Staff only |
| Oversight access log brokenThe access log kept for each outside reviewer | Critical | Yes | Staff only |
| Protective switch pulledEvery pull of a protective switch | High | Yes | Staff only |
| Redemption held up or not matching its requestRedemption requests where units were burned and the payer has reported no payment within its own stated days, or where the burn the payer reported differs from the request | High | Yes | Staff only |
| Redemption closed by the payerThe redemption terms each payer states, and whether they still allow redemption | High | Yes | Yes, once approved |
| Reporting dueEach listed asset's reporting dates on the monitoring schedule, and the reports its issuer has sent | Medium | Yes | Yes, once approved |
| Reporting overdueEach listed asset's reporting dates on the monitoring schedule, and the reports its issuer has sent | High | Yes | Yes, once approved |
| Review overdueEach listed asset's review dates on the monitoring schedule | High | Yes | Yes, once approved |
| Possible sanctions matchPossible matches from the sanctions screening of people, organisations and wallets, as the CRYMAD engine reports them | Critical | Yes | Staff only |
| Source disagreementFacts we hold from two sources: an escrow balance from the CRYMAD engine and from the chain, a CMX-U operation from CrymadX and from the chain, a distribution snapshot against the transfers and the supply, and a score check whose sources disagree | High | Yes | Staff only |
| Independent timestampThe independent timestamp on each day's records | High | Yes | Staff only |
| Token paused or unpausedPause and unpause events seen on chain on a token contract we follow | Critical | Yes | Yes, once approved |
| Units created (mint) seen on chainThe total supply we read from each token contract we follow, compared with our read before it | Medium | Yes | Staff only |
| Valuation stalenessThe end date on the valuation evidence held for a listed asset | Medium | Yes | Yes, once approved |
| Wallet link method changedHow the CRYMAD engine says each wallet is linked, compared with what it said before | High | Yes | Staff only |
| Address frozenFreeze events on a token contract | Critical | Not yet. A CRYMAD token does not block an ineligible holder, and has no on chain control attached that could do this, so it cannot happen on chain today | Yes, once approved |
| Record fingerprint not yet on chain (anchor pending)Record fingerprints waiting to be written on chain | High | Not yet. We do not yet write fingerprints of our records to the chain (anchoring), because the CRYMAD engine has no way to receive them | Yes, once approved |
| Bridge transfer limit reachedA bridge's transfer limits | High | Not yet. No bridge exists to move a token to another chain | Yes, once approved |
| Token deployed on another chain, or its route changedA bridge's routes | High | Not yet. No bridge exists to move a token to another chain | Yes, once approved |
| Token holder rules changedA token's on chain rules about who may hold it | High | Not yet. We do not yet check a token on chain for rules about who may hold it, so a change to them cannot be seen | Yes, once approved |
| Covenant breachThe promises in an asset's terms (its covenants) | High | Not yet. The promises an issuer makes in an asset's terms (its covenants) are not tracked yet | Yes, once approved |
| Custodian changeMaterial events declared under Custody | High | Not yet. A change of custodian, the firm that holds the asset, is declared as a material event instead, under Custody | Yes, once approved |
| Unusual document downloadsThe log of document downloads | Medium | Not yet. Every document download is logged; no rule reads the log for unusual patterns yet | Staff only |
| Forced transfer or clawbackForced transfer events on a token contract | Critical | Not yet. A CRYMAD token does not block an ineligible holder, and has no on chain control attached that could do this, so it cannot happen on chain today | Yes, once approved |
| Issuer non-responsiveThe requests we send to issuers | Medium | Not yet. We do not yet track how long an issuer takes to answer our requests | Yes, once approved |
| Activity on a token's old contractA token's old contract, after a move to a new one | High | Not yet. No token has moved to a new contract, so there is no old contract to watch | Yes, once approved |
| Liquidity dropTrading figures from a licensed venue | Medium | Not yet. No licensed venue reports trading figures to us yet, so there is nothing to measure | Yes, once approved |
| Mint outside dilution rulesA mint, compared with the most new units the asset's terms allow | High | Not yet. The most new units an asset's terms allow is not recorded yet, so a mint cannot be checked against it | Yes, once approved |
| Net asset value (NAV) deviationThe net asset value a payer states with its redemption terms | Medium | Not yet. A payer states a net asset value with its redemption terms. We hold no second figure to compare it with, and no size of move has been agreed as one to raise, so this rule has nothing to test yet | Yes, once approved |
| Outside data feed (oracle) out of dateAn outside data feed (oracle) | Medium | Not yet. No oracle, an outside service that puts prices or other data on chain, is used | Yes, once approved |
| Recovery executedRecovery events on a token contract | High | Not yet. A CRYMAD token does not block an ineligible holder, and has no on chain control attached that could do this, so it cannot happen on chain today | Yes, once approved |
| On chain list of approved holders differsAn on chain list of approved holders | High | Not yet. No CRYMAD token checks who may hold it on chain, so there is no on chain list to compare with ours | Yes, once approved |
| Regulatory actionMaterial events declared under Regulatory | High | Not yet. A regulatory action is declared as a material event instead, under Regulatory | Yes, once approved |
| Reserve does not match CMX-U supplyCrymadX's signed reserve snapshot, and our own reads of the reserve and of the CMX-U supply | Critical | Not yet. CMX-U does not exist yet, so CrymadX publishes no signed reserve snapshot and there is nothing to compare our reads with. | Staff only |
| Unusual change in a scorePublished scores | Medium | Not yet. We have not yet defined what counts as an unusual change in a score | Yes, once approved |
| Status changeThe status register | Info | Not yet. A status change is published on the status register and holders are told in a notice; a separate alert for it waits until watchers can set alerts of their own | Yes, once approved |
| Supply reconciliationA token's supply, compared with the most units it may have | Critical | Not yet. We hold no record yet of the most units any token may have, so there is nothing to check its supply against | Yes, once approved |
| Unconfirmed input overdueScore inputs waiting for a second source | Medium | Not yet. No automated source feeds a score yet, so nothing waits for a person to confirm it | Yes, once approved |
What happens when a rule fires
1. Staff are alerted
An alert goes to VORUNEX staff with its severity. If the same thing is seen again, it is counted on the same alert rather than raising a new one.
2. A person decides
Watchtower never changes a status, a score or a Risk Class by itself. Staff review the alert; any change of status goes through the Committee and appears on the status change register with its reason.
3. What the public sees
An alert appears on the asset page, and the asset's watchers are told in the app, only after a second person at VORUNEX approves it. Material events are published the same way, with their hash on the register.