Account identities
Fund accounts are derived from the configured index mint. Each constituent has a distinct vault. Redemption tickets include fund, owner and a monotonically increasing nonce.
The Verify page shows the configured program, mint, vaults and observed custody information. An unconfigured address is never replaced with a sample deployment.
Protected obligations
Spendable book balances and reserved owed balances are separate. Trades cannot use ticket reserves. A written-off slot has zero spendable book balance while existing ticket obligations remain payable.
A recovery instruction cannot sign as an active or retired vault authority. The fund program does not hold index-mint authority.
Composition changes
An owner can mark an asset Exiting, allowing bounded sales. After 72 hours it can be written off. This discards its economic backing; it does not prove the asset is worthless.
Replacement requires both spendable book and outstanding owed to be zero. An unclaimed entitlement can block replacement indefinitely. Written-off assets are not swept or re-admitted.
Deployment and review
This local build does not establish a funded deployment or an independent security audit. Check the current configuration, upgrade authority and review evidence on Verify before participating.