Skip to content

Verification

Watchtower

Monitoring of every admitted asset after it is listed. Rules watch evidence that ends, reviews and reports that fall due, distributions and redemptions against their own dates, screening results, the holder register, facts we hold from two sources, and the chain the assets are on. When one fires, VORUNEX staff are alerted, and a person decides what happens next.

The pill
GreenNo open rule has fired in the last 30 days
AmberAt least one Medium or Low rule is open, or evidence expires within 30 days
RedA High or Critical rule is open, or a protective flag is set

The rules

57 rules in rule set 2026.10-v10. 34 can fire today; each of the others says why it cannot yet, so a quiet rule is never mistaken for a clean one. Under each rule is what it reads.

Watchtower rules
Rule, and what it readsSeverity when it firesCan fire todayCan be published
Admin key or signer changeOwner and role changes seen on chain on a contract we followCriticalYesYes, once approved
Record fingerprint refused or changed on chainOur requests to write a record fingerprint on chainHighYesStaff only
Units destroyed (burn) seen on chainThe total supply we read from each token contract we follow, compared with our read before itMediumYesStaff only
Chain readings in doubtEach chain's identity and history, compared with what we storedCriticalYesStaff only
Published records out of stepEach publication, checked against every place it must appearCriticalYesStaff only
Complaint deadline breachedThe deadlines on each complaintHighYesStaff only
Compliance case overdueThe due date on each compliance caseMediumYesStaff only
Compliance check disagreementOur compliance decisions, recomputed and compared with what was recordedCriticalYesStaff only
Compliance switch off for four hoursThe switches that turn a compliance check offHighYesStaff only
Largest holder changedThe holder register of each token linked to a listed asset: which wallet holds the most units, and whether one wallet holds more than halfMediumYesStaff only
Contract upgradedThe code at each contract address we followCriticalYesYes, once approved
Data source staleOur own readings of each chain we follow: whether it is making blocks, and how far behind we areHighYesStaff only
Distribution past its record date, not yet computedDistributions an issuer or the CRYMAD engine declared: the record date, the stated payment date, and whether what each holder is owed was computedMediumYesYes, once approved
Distribution not computed by its stated payment dateDistributions an issuer or the CRYMAD engine declared: the record date, the stated payment date, and whether what each holder is owed was computedHighYesYes, once approved
Holders no longer eligibleHolders touched by a published change to a market's rules, and holders found not eligible at the check after a mintHighYesStaff only
Evidence expiryThe end date on each piece of evidence held for a listed assetMediumYesYes, once approved
Holding differs from the chainOur count of each holding, compared daily with the token contract's own answer at the same blockHighYesStaff only
Insurance lapseThe end date on the insurance evidence held for a listed assetHighYesYes, once approved
Lifecycle request past its deadline with no executor reportLifecycle requests two people accepted for the record (corporate actions, migrations, maturity and wind down, token recovery), each with the deadline for its executor's report, and the reports recorded against itHighYesStaff only
Material event past its embargoDeclared material events that are not published yetHighYesStaff only
Oversight access log brokenThe access log kept for each outside reviewerCriticalYesStaff only
Protective switch pulledEvery pull of a protective switchHighYesStaff only
Redemption held up or not matching its requestRedemption requests where units were burned and the payer has reported no payment within its own stated days, or where the burn the payer reported differs from the requestHighYesStaff only
Redemption closed by the payerThe redemption terms each payer states, and whether they still allow redemptionHighYesYes, once approved
Reporting dueEach listed asset's reporting dates on the monitoring schedule, and the reports its issuer has sentMediumYesYes, once approved
Reporting overdueEach listed asset's reporting dates on the monitoring schedule, and the reports its issuer has sentHighYesYes, once approved
Review overdueEach listed asset's review dates on the monitoring scheduleHighYesYes, once approved
Possible sanctions matchPossible matches from the sanctions screening of people, organisations and wallets, as the CRYMAD engine reports themCriticalYesStaff only
Source disagreementFacts we hold from two sources: an escrow balance from the CRYMAD engine and from the chain, a CMX-U operation from CrymadX and from the chain, a distribution snapshot against the transfers and the supply, and a score check whose sources disagreeHighYesStaff only
Independent timestampThe independent timestamp on each day's recordsHighYesStaff only
Token paused or unpausedPause and unpause events seen on chain on a token contract we followCriticalYesYes, once approved
Units created (mint) seen on chainThe total supply we read from each token contract we follow, compared with our read before itMediumYesStaff only
Valuation stalenessThe end date on the valuation evidence held for a listed assetMediumYesYes, once approved
Wallet link method changedHow the CRYMAD engine says each wallet is linked, compared with what it said beforeHighYesStaff only
Address frozenFreeze events on a token contractCriticalNot yet. A CRYMAD token does not block an ineligible holder, and has no on chain control attached that could do this, so it cannot happen on chain todayYes, once approved
Record fingerprint not yet on chain (anchor pending)Record fingerprints waiting to be written on chainHighNot yet. We do not yet write fingerprints of our records to the chain (anchoring), because the CRYMAD engine has no way to receive themYes, once approved
Bridge transfer limit reachedA bridge's transfer limitsHighNot yet. No bridge exists to move a token to another chainYes, once approved
Token deployed on another chain, or its route changedA bridge's routesHighNot yet. No bridge exists to move a token to another chainYes, once approved
Token holder rules changedA token's on chain rules about who may hold itHighNot yet. We do not yet check a token on chain for rules about who may hold it, so a change to them cannot be seenYes, once approved
Covenant breachThe promises in an asset's terms (its covenants)HighNot yet. The promises an issuer makes in an asset's terms (its covenants) are not tracked yetYes, once approved
Custodian changeMaterial events declared under CustodyHighNot yet. A change of custodian, the firm that holds the asset, is declared as a material event instead, under CustodyYes, once approved
Unusual document downloadsThe log of document downloadsMediumNot yet. Every document download is logged; no rule reads the log for unusual patterns yetStaff only
Forced transfer or clawbackForced transfer events on a token contractCriticalNot yet. A CRYMAD token does not block an ineligible holder, and has no on chain control attached that could do this, so it cannot happen on chain todayYes, once approved
Issuer non-responsiveThe requests we send to issuersMediumNot yet. We do not yet track how long an issuer takes to answer our requestsYes, once approved
Activity on a token's old contractA token's old contract, after a move to a new oneHighNot yet. No token has moved to a new contract, so there is no old contract to watchYes, once approved
Liquidity dropTrading figures from a licensed venueMediumNot yet. No licensed venue reports trading figures to us yet, so there is nothing to measureYes, once approved
Mint outside dilution rulesA mint, compared with the most new units the asset's terms allowHighNot yet. The most new units an asset's terms allow is not recorded yet, so a mint cannot be checked against itYes, once approved
Net asset value (NAV) deviationThe net asset value a payer states with its redemption termsMediumNot yet. A payer states a net asset value with its redemption terms. We hold no second figure to compare it with, and no size of move has been agreed as one to raise, so this rule has nothing to test yetYes, once approved
Outside data feed (oracle) out of dateAn outside data feed (oracle)MediumNot yet. No oracle, an outside service that puts prices or other data on chain, is usedYes, once approved
Recovery executedRecovery events on a token contractHighNot yet. A CRYMAD token does not block an ineligible holder, and has no on chain control attached that could do this, so it cannot happen on chain todayYes, once approved
On chain list of approved holders differsAn on chain list of approved holdersHighNot yet. No CRYMAD token checks who may hold it on chain, so there is no on chain list to compare with oursYes, once approved
Regulatory actionMaterial events declared under RegulatoryHighNot yet. A regulatory action is declared as a material event instead, under RegulatoryYes, once approved
Reserve does not match CMX-U supplyCrymadX's signed reserve snapshot, and our own reads of the reserve and of the CMX-U supplyCriticalNot yet. CMX-U does not exist yet, so CrymadX publishes no signed reserve snapshot and there is nothing to compare our reads with.Staff only
Unusual change in a scorePublished scoresMediumNot yet. We have not yet defined what counts as an unusual change in a scoreYes, once approved
Status changeThe status registerInfoNot yet. A status change is published on the status register and holders are told in a notice; a separate alert for it waits until watchers can set alerts of their ownYes, once approved
Supply reconciliationA token's supply, compared with the most units it may haveCriticalNot yet. We hold no record yet of the most units any token may have, so there is nothing to check its supply againstYes, once approved
Unconfirmed input overdueScore inputs waiting for a second sourceMediumNot yet. No automated source feeds a score yet, so nothing waits for a person to confirm itYes, once approved

What happens when a rule fires

1. Staff are alerted

An alert goes to VORUNEX staff with its severity. If the same thing is seen again, it is counted on the same alert rather than raising a new one.

2. A person decides

Watchtower never changes a status, a score or a Risk Class by itself. Staff review the alert; any change of status goes through the Committee and appears on the status change register with its reason.

3. What the public sees

An alert appears on the asset page, and the asset's watchers are told in the app, only after a second person at VORUNEX approves it. Material events are published the same way, with their hash on the register.
    Watchtower, VORUNEX