- No Panofx-controlled key can move a taker’s, resolver’s, or LP’s funds. Ever. The keeper’s submitter key holds gas money only. The multisig can pause, set fee token and bps per corridor up to 5, set the treasury, and set the gas-fee formula parameters; nothing else.
- The reactor’s and the executor’s balances of every token are zero after every call. Fork test.
- The executor delivers at least the taker’s signed
minOutto the signedrecipientand charges at most the signedmaxGasFee, or reverts. Fork test over both fee-token directions. - The executor accepts only offers whose hash the taker signed and whose validation data names this executor and this taker. Fork test with a swapped offer and a swapped taker.
- An offer executes only for its named taker, only before its deadline, only once. Fork tests for each.
- The protocol fee never exceeds 5 bps and is only ever in the dollar token. Fork test that a controller returning 6 bps reverts in the reactor.
- A node signs nothing while disconnected, degraded, or above verified inventory. Unit and integration tests with fault injection.
- Solana: an offer is a signed message; any change to the message invalidates it. Relay and client reconstruct and compare bytes before trusting it.
- Hosted surfaces screen addresses; contracts and the relay protocol do not. No identity data exists to leak.
What the relay checks before ranking
Every offer is checked against what the chain will enforce: balance, allowance, nonce, reservation against other open quotes, the pause flag, and every term of the order against the RFQ. The winning offer is then simulated end to end before the taker sees a price. The list of reasons is under Why the relay rejected an offer.What the keeper checks before submitting
The keeper leader simulates the settlement with the taker’s signature attached. A revert becomes arequote to the taker and nothing moves. A revert the keeper traces to the resolver’s side counts toward
that resolver’s demotion.

