Skip to content

[Docs] Write a consolidated trust-model document #726

Description

@collinsezedike

Problem

Admin-authority and immutability facts are scattered across multiple places: contract immutability is discussed in docs/contracts.md, admin-key risk is discussed piecemeal in the open #557 bug thread, and SECURITY.md is a vulnerability-disclosure policy, not a trust or permissions explainer. Nothing states in one place, for a depositor or a future auditor, exactly what the admin key can and cannot do, or what happens if it's lost or compromised.

Why it matters for mainnet

A single reference document shrinks the scope of a future paid security audit and gives depositors and auditors one place to evaluate custody risk before mainnet, rather than reconstructing it from scattered docs and issue threads.

Suggested fix

Add apps/docs/overview/trust-model.md covering:

Location in codebase

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

docsDocumentation, guides, README, inline docs, or ADRsmediumRequires familiarity with the Meridian codebase or relevant tooling; expect 4–8 hourssecuritySecurity hardening, vulnerability fixes, or audit-related work

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions