Skip to main content
Our meeting with SEC Crypto Task Force (opens in a new tab)
← Resources

· 14 min read

How Allocators Can Verify Onchain and Offchain Vault Hedges Without Position Disclosure

A practical diligence framework for verifying one mandate across onchain positions and offchain hedges while protecting sensitive portfolio data.

TL;DR

  • Allocators need evidence that one mandate covers onchain positions and offchain hedges without requiring disclosure of positions, venues, or strategy details.
  • Useful evidence tests aggregate exposure, hedge ratios, counterparty concentration, and leverage against defined limits while keeping underlying values private.
  • Pre-execution enforcement blocks an action that breaches the mandate. Monitoring and periodic attestations can identify a breach only after execution or at the next review.
  • Cryptographic evidence (opens in a new tab) can prove that defined checks ran correctly over committed or attested inputs. It cannot independently prove that a venue, custodian, or counterparty supplied truthful data, so conventional diligence remains necessary.

The verification problem hybrid vaults create

A hybrid vault creates a verification problem when one mandate governs assets held across incompatible venues. Onchain records may expose wallet balances and protocol transactions. They do not reveal futures, options, centralized exchange accounts, or prime broker obligations. An allocator therefore cannot calculate aggregate exposure or confirm a hedge by inspecting the vault’s wallets alone.

Cross-venue hedges also change the meaning of compliance. An onchain position may appear overexposed until an offchain short is included. The same vault may appear fully hedged even though a venue has liquidated the short or restricted withdrawals. Any mandate test must evaluate both sides within a defined time window and under a consistent valuation method.

Vault operators may address this problem through dashboards, contracts, human approvals, or periodic audit reports. Each control addresses a different part of the problem and leaves a timing or coverage gap. Dashboards depend on the data sources and refresh schedules chosen by the operator. Human reviewers may approve actions using incomplete records. Audit reports examine selected evidence after trades have executed. A multisig can control who authorizes a transaction without proving that the resulting exposure complies with the mandate.

Position disclosure would make some checks easier, but full transparency can reveal hedge structure, venue selection, and trading intent. Vault managers may reasonably restrict that information because other market participants could copy trades or trade against pending adjustments. The allocator still needs evidence that exposure caps and counterparty limits applied across the complete portfolio.

Evidence can support a capital decision when it connects a specific action to a defined policy and lets the allocator verify the result independently. Monitoring can show that a breach occurred. Periodic attestations can show that a condition held at a particular time. Pre-execution enforcement can prevent a covered action when the action would violate the mandate. The diligence question is whether the vault can prove which guarantee it provides without requiring disclosure of the underlying positions.

What "one mandate" has to mean before it can be verified

A verifiable mandate begins with a written specification of every position and action it governs. The specification should cover onchain transactions, centralized exchange orders, and prime broker activity. It should also identify which accounts, legal entities, and operators fall within scope.

A claim of unified risk management is incomplete unless the mandate defines how offchain actions enter its scope. An allocator should ask whether margin calls and contract rolls receive the same checks as ordinary trades. Rebalances and emergency deleveraging also need explicit treatment. Otherwise, a manager can comply onchain while changing aggregate exposure through an uncovered venue or operational action.

The mandate must identify the policy state used for each decision. Policy state records current exposure, available collateral, approved counterparties, and applicable limits. The written specification should state when those records update and which data source controls when records conflict. A limit calculated against yesterday’s prime broker balance may approve an action that breaches today’s exposure cap.

Scope boundaries require equal precision. The vault should document manual overrides, emergency powers, and actions routed through venues that lack an enforcement integration. Each exception should name the approving authority and the evidence retained afterward. An undocumented exception path prevents an allocator from knowing what the verification actually covers.

U.S. regulatory status does not replace a vault-specific operating specification. A CV5 Capital account of the U.S. regulatory framework (opens in a new tab) describes a joint SEC and CFTC crypto document as interpretive guidance rather than a rule that creates new obligations. Regardless of regulatory classification, allocators still need the vault to define its custody dependencies, counterparty boundaries, and covered actions.

Before evaluating any proof, an allocator should request a control map that connects each action to a policy rule, required input, enforcement point, and exception path. Evidence can establish compliance only for the actions and policy state included in that map.

Setting exposure caps and counterparty limits that survive contact with offchain venues

A usable exposure cap must aggregate economically related positions across onchain wallets and offchain accounts. Ask whether the vault calculates single-asset exposure using spot holdings, futures, options, borrowed assets, and collateral. The calculation should specify whether limits apply to gross exposure, net exposure, or both. Options require a stated method for converting contracts into exposure because their sensitivity changes with price and time.

Counterparty limits should apply to each legal entity that holds assets, extends credit, or creates a payment obligation for the vault. An order routed to an exchange may depend on a prime broker for financing and a custodian for collateral. CV5 Capital recommends mapping concentration across custodians, prime brokers, and trading venues (opens in a new tab). Ask whether related legal entities share one limit and how the vault treats collateral posted through an intermediary.

Venue limits need comparable definitions across different account structures. Ask whether the cap covers assets held at the venue, unsettled trades, posted margin, and receivables. A vault should also explain how it attributes exposure when one venue executes a trade but another entity clears or finances it. Without a consistent attribution rule, the same position can disappear between separate venue and counterparty reports.

Leverage limits must account for derivatives and financing rather than rely on onchain borrowing alone. Ask which denominator the vault uses, how often it updates, and whether pending orders reserve capacity before execution. A margin transfer can increase counterparty concentration even when portfolio exposure remains unchanged. The enforcement policy should therefore cover collateral movements as well as trades.

A written cap does not establish that the cap binds execution. Ask the vault to demonstrate what happens when a proposed order, roll, rebalance, or margin action would breach a limit. Pre-execution enforcement should reject the action or require an authorized policy change before it reaches the venue. Monitoring software may identify the same breach after execution, but the vault has already taken the prohibited exposure.

Allocators should test enforcement with boundary cases. Submit actions just below and just above the limit. Also test the exact limit and confirm that the result matches the mandate's stated treatment of equality. Repeat the test through each supported venue and execution route. The evidence should identify the policy version, committed exposure state, proposed action, and resulting decision without disclosing the underlying positions.

Authenticating the offchain inputs a mandate depends on

A pre-execution control inherits the quality of every offchain input it consumes. A circuit may calculate net exposure correctly while using a stale futures price or an incomplete margin balance. The resulting proof remains valid for the supplied data even when that data no longer represents the vault’s actual position.

A committed input binds the vault to a specific value or dataset without making the underlying value public. An attested input adds a signed statement from an identified source, such as a custodian, exchange, administrator, or prime broker. The verification record should expose the source identity, signing authority, timestamp, covered accounts, and data format. Those details let an allocator confirm who supplied the input and whether the mandate accepted it under the applicable freshness rules.

An allocator should require an inventory of every external input used by the mandate. Price inputs should identify the venue or provider, instrument, timestamp, and method for resolving conflicting marks. Exchange and custodian inputs should cover balances, collateral, open positions, pending transfers, and account scope. Prime broker statements should identify financing balances, margin requirements, pledged collateral, and unsettled activity. Options checks may also depend on volatility, expiry, and contract terms supplied by an external venue.

The input policy should state how often each record updates and what happens when a source becomes stale or unavailable. A control that reuses the last available balance without disclosure can approve an action against outdated collateral. The input policy should instead reject the action or apply a documented fallback. If an authorized exception permits execution, the vault should retain a separate record of the approval and inputs used.

A valid zero-knowledge proof (opens in a new tab) shows that the proof system accepted a defined computation over specific inputs. It does not establish that a custodian reported every liability or that a venue marked a position accurately. Attestations authenticate the source and preserve input integrity. Allocators must still assess whether the source is reliable, sufficiently independent, and subject to reconciliation.

Privacy boundaries: proving exposure without revealing positions

A vault can prove that exposure remained within a limit without publishing each position. The vault first binds position data to cryptographic commitments. Those commitments prevent the operator from changing hidden values after constructing the proof.

A zero-knowledge circuit then calculates aggregate exposure over the committed positions. A range proof can establish that the resulting exposure falls below a cap without revealing the exposure amount or its components. Similar circuits can prove that a hedge ratio stayed within an approved band or that no venue exceeded its concentration limit. A properly designed zero-knowledge proof can establish the defined claim without revealing the witness used to prove it. The guarantee still depends on the proof system, circuit, implementation, and disclosed public inputs, as discussed in this overview of zero-knowledge proofs (opens in a new tab).

Selective disclosure determines which facts become public. An allocator might receive the policy version, covered account set, valuation time, input issuers, and proof result. Position sizes, instruments, venues, and hedge timing can remain private. Vault curators may protect those details to reduce the chance that others infer or trade against the strategy. Full disclosure can expose trade construction, reveal upcoming hedge activity, and make thinly traded positions easier to front-run.

The public statement still needs enough context to support a decision. A verifier should know which accounts entered the calculation, which asset mappings applied, how fresh the attestations were, and which verification key corresponds to the accepted policy. A proof that merely says “compliant” lacks a usable scope.

Inherence (opens in a new tab) provides one implementation through an inline enforcement gate and a verifiable receipt. The relevant control boundary is whether Inherence can block a covered vault action before execution and produce evidence that the formalized mandate was checked. Allocators should verify that the integration actually withholds signing, order submission, or settlement authorization after a failed check.

Subject to the receipt's documented proof statement and verification procedure, an Inherence receipt can show that a covered action passed the specified aggregate-limit checks without exposing the underlying positions. Its guarantee remains bounded. The receipt proves the defined computation over committed or attested inputs. It does not establish whether a custodian reported the correct balance or whether an action bypassed the enforced path.

Pre-execution enforcement versus monitoring and periodic attestations

Pre-execution enforcement prevents a prohibited action before value moves. Monitoring detects a breach after execution, when remediation may require closing a position or adding collateral. During that lag, the vault can remain outside its exposure cap. An alert therefore provides a weaker guarantee than a control that withholds signing, order submission, or settlement authorization.

Periodic attestations leave a different timing gap. A SOC 2-style report evaluates controls over a defined period, but it does not prove that every covered trade satisfied the mandate. A proof-of-reserves snapshot establishes a claim at one point in time. Neither method shows what happened between assessment dates or snapshots. Per-action evidence can instead bind each covered decision to the policy version and inputs used at execution time.

Pre-execution timing and independent verification are separate properties. When evaluating Newton, Dfns, Predicate, or another policy system, allocators should determine when the product evaluates an action, what component can withhold execution, and what evidence a third party can verify. A vendor-signed verdict authenticates the vendor's statement, while cryptographic proof of a committed computation supports a different verification claim. Either approach blocks an action only when every covered execution route treats rejection as binding.

Inherence (opens in a new tab) evaluates covered onchain and bounded offchain actions through an inline gate. Allocators should confirm that a failed mandate check prevents execution and that the zero-knowledge receipt can be verified independently without revealing private positions. A verifier who validates the receipt against the accepted verification key can determine whether the defined check passed over the committed or attested inputs represented in the proof. It does not establish that every external input was truthful or that an action outside the gate never occurred.

Allocators should test enforcement by tracing an actual rejected action. The vault should identify which component withheld execution, how the proposed action was bound to the policy decision, and what happens when the gate or input feed becomes unavailable. Evidence issued after execution should be classified as monitoring even when it arrives within seconds. Evidence generated before execution still requires confirmation that no alternate route can bypass the control.

Testing exceptions and actions outside the enforcement path

Allocators should map the enforcement boundary before relying on any receipt or compliance claim. A cryptographic proof covers actions routed through the defined gate and evaluated against committed or attested inputs. An order placed through a separate venue account may receive no evaluation and produce no evidence. The absence of a failed receipt does not prove that no outside action occurred.

Diligence should test the main escape routes individually.

  • Ask whether manual overrides bypass policy checks or use a separate policy with additional approvals. The vault should identify who can invoke an override and what evidence the override produces.
  • Ask how emergency deleveraging works during a margin call or venue outage. An emergency path may accept broader permissions, but the vault should disclose those permissions and record each use.
  • Ask whether newly added venues begin with default-deny access. A venue that becomes usable before its integration enters the enforcement path creates an unverified trading route.
  • Ask whether traders, software agents, or service providers can submit offchain instructions directly. Venue permissions and signing controls should prevent covered actions from moving through an alternate account or interface.
  • Ask how the vault detects activity that produces no expected receipt. Reconciliation should compare venue, custodian, and prime broker records against the set of proved actions.

The vault should document its exceptions instead of claiming that every possible action passes through the enforcement path. Its answer should define each excluded route, explain when that route may be used, and state which conventional controls cover the residual risk. Depending on the excluded route, those controls may include dual approval and restricted credentials. Reconciliation or independent administrator review can then help detect activity that bypassed preventive controls.

For actions routed through the Inherence enforcement path, allocators should verify that the resulting evidence is independently checkable and bound to the covered action. Allocators still need account inventories, access reviews, and external records to detect actions taken elsewhere. Any route that remains both unenforced and unreconciled should count as an unresolved control gap.

Where cryptographic evidence stops and conventional diligence starts

Cryptographic evidence proves that defined checks ran correctly over committed or attested inputs. A valid zero-knowledge proof does not independently establish whether a custodian reported the correct balance, a venue omitted an account, or a counterparty holds the collateral it claims. Proof validity remains bounded by the computation and inputs (opens in a new tab).

Legal, counterparty, and completeness questions remain outside the cryptographic proof boundary. A proof cannot confirm legal title to assets, predict counterparty insolvency, or establish that an offchain contract will remain enforceable. It also cannot detect hidden liabilities or omitted positions unless the evidence set establishes that every relevant account entered the calculation. An authenticated statement can still contain inaccurate or incomplete information.

Conventional diligence addresses these remaining questions. Custody records support asset existence and control. Prime broker and venue statements document collateral, margin obligations, and open exposures. Administrator reports provide an independent calculation of portfolio values. Reconciliation compares those records against the vault’s books and the inputs used for enforcement. Audits examine financial reporting and whether specified controls operated over the review period.

Allocators should match each claim to evidence that can establish it. An independently verified Inherence receipt can show that a covered action passed the encoded mandate before execution without revealing private positions, provided that the receipt is bound to the action, policy version, and accepted inputs. Administrator, custodian, venue, and audit evidence must support the underlying facts and institutional relationships. Neither evidence category substitutes for the other.

A diligence file should also connect both categories. Reconciliation should bind the accounts in conventional records to the accounts represented in cryptographic evidence. Reviewers should confirm the applicable policy version, verification key, reporting period, and covered entities. Missing connections leave an allocator unable to determine whether a valid proof describes the full vault or only a selected subset.

Decision framework: when the evidence is enough to act on

  • Act when every material onchain and offchain action passes a defined policy gate before execution. Independent verification must bind each receipt to the relevant action and policy version. Conventional diligence must also support the custody, venue, counterparty, and input assumptions. Together, the enforcement evidence and conventional diligence can support an allocation, risk-limit approval, or access decision.
  • Escalate when the mandate covers the main trading path but leaves limited exceptions or venue gaps. The allocator can require lower exposure, additional approvals, or remediation deadlines while conventional controls cover the residual risk. Periodic attestations alone warrant escalation because breaches can occur between reviews.
  • Decline when material actions can bypass enforcement without disclosure or control. An allocator should also stop when the policy scope remains ambiguous, receipts cannot be verified independently, or external balances and market inputs lack credible support. Cryptographic proof cannot repair incomplete coverage or unreliable source data.

Inherence positions its defined path as providing pre-execution enforcement and independently verifiable receipts. Before relying on that claim, allocators should test whether failed checks block execution and whether they can verify receipts without trusting Inherence. When their scope, inputs, and verification procedure are documented, those receipts can reduce the number of mandate-compliance claims an allocator must accept solely from the vault operator. Audits, administrator reports, reconciliations, and counterparty review still cover risks outside the proved statement. Verifiable mandate enforcement can support a capital decision when it covers the relevant actions and relies on authenticated, reconciled inputs. Conventional diligence remains necessary for custody, legal, counterparty, valuation, and completeness claims outside the proof.

Request Access To Inherence