BASTIONPROTOCOLTelegramOpen terminal

SECURITY / DISTINCT TRUST BOUNDARIES

THE CONTROLS
ARE THE PROTOCOL.

Custody, market admission, oracle observations, upgrades and liquidations require separate permission boundaries.

Bastion guardian behind a transparent shield and distinct key modules

01 / PERMISSION MAP

DEFINE THE POWER.
THEN LIMIT IT.

RoleCapabilityBoundary
BorrowerDeposit collateral, borrow within limits, repay, withdraw when healthyCannot withdraw pledged LP beyond permitted health
LenderSupply the quote asset to a selected isolated marketWithdrawals constrained by available liquidity and market solvency
LiquidatorRepay unhealthy debt and receive bounded collateralMust pass health, freshness and seizure checks
Risk authorityAdmit pools, set caps, pause risk-increasing actionsDelayed parameter increases; immediate restrictive controls
Upgrade authorityUpgrade programs under the authority policyPublished multisig and timelock; centralization risk remains

02 / FAILURE CONTAINMENT

ISOLATED LEDGERS.
SHARED CODE RISK.

Each market owns its debt book and lending assets. Bad debt is not automatically shifted to another market. Buffer support, if any, must follow a separately disclosed cap.

All markets may still share a vulnerable program or dependency. Isolation does not remove common software, operator, governance or RPC risks.

03 / BEFORE THE FIRST LOAN

Adversarial valuation

Test reserve manipulation, flash liquidity, burns, virtual reserves, stale windows and withdrawal failures.

Atomic accounting

Test decimal handling, integer rounding, interest accrual, cross-market accounts and partial liquidation.

Operational readiness

Verify independent signers, monitoring, bounded caps, incident procedures and observable upgrade controls.

Read the risk register