Product Vaults and Fund Flows
Each product has a distinct ProductToken, DepositVault, RedemptionVault and price feed. DepositVault receives payment assets and issues product tokens; RedemptionVault burns product tokens and pays redemption assets. Product-specific contracts create technical boundaries between the assets and processing conditions they handle. Legal custody and segregation of assets are defined in the product contracts. Deposit balances and redemption payout balances are managed separately, so a deposit does not automatically provide redemption liquidity. Operators move deposited assets under approved allocation arrangements and prepare payout assets in line with the recovery and settlement schedules of the product’s assets or strategy. The mainnet operating standard is to record the purpose of each movement, destination address, approval and settlement evidence. Asset and strategy holding, valuation and settlement records are reconciled against the relevant ARCO vault records. Where an externally issued product is connected, the scope of the connection to external issuance, distribution and custody records is also specified. Verification materials for assets and strategies and those for ARCO contracts and permissions each identify their subject and scope.Permissions and Approvals
Contracts restrict administrative functions through role checks. Partners confirm the permission holders and approval procedures for the following actions in each product’s permissions policy.
Issuance and burn permissions affect user balances, while permissions to move deposited assets enable external fund allocation. The permissions policy includes the permitted scope of normal and exception handling, approvers and recordkeeping responsibilities. Issuance, burns and fund movements outside the vault must also be included in product balance, holdings and settlement reconciliation.
The mainnet operating standard separates approval procedures for routine processing, price changes, fund movements and upgrades. Where multiple approvals or change delays apply, the permissions policy specifies signers, approval thresholds, delay periods, emergency exceptions and key recovery procedures. The application of these controls is verified against the published policy and deployment settings.
Pricing and Transaction Conditions
Deposit and redemption quotes are calculated from the ratio of the product price to the payment asset price. Price feeds check for positive values, permitted ranges and data age. Whether price movement limits apply, and their thresholds, are defined in the operating specification according to the product’s valuation frequency and volatility. A process is needed to connect the asset or strategy’s valuation source, valuation date and currency, fee treatment and published onchain value. Mainnet launch verification checks product and payment asset feed mappings alongside actual issuance and redemption quotes. Technical price validity and evidence of asset or strategy valuations and holdings are verified separately. Deposit and redemption functions may apply controls such as reentrancy protection and minimum amounts received. Partner interfaces are designed to reflect approval amounts and permitted price changes in transaction parameters, and to check prices, limits, pause status and token policies at execution. Product token address allowlisting and blocking are tools for applying participation and transfer policies, and are combined with identity review procedures.Limits and Redemption Liquidity
Product operating limits cover issuance size, processing capacity per vault and payout capacity. The standard is to manage pending requests, direct issuance and burns, and external fund allocations alongside limits on contract processing paths. The prices, limits and reservation methods used at request submission and processing are recorded in the product’s deposit and redemption specification. Internal direct Instant Redemption is processed within available liquidity after reserved claims are deducted from the payout balance. OTC Instant follows executable quotes and settlement conditions. Standard Redemption prepares payouts according to the recovery and settlement schedules of the assets or strategy. Product specifications provide the following policies.Reserve Assets and OTC Settlement
ArcoUSD manages sufficient spare stablecoin reserves to support ongoing swaps and withdrawals. Reserve holdings and valuations, outstanding arcoUSD supply, reserved payouts, incomplete obligations and assets actually available for payout are reconciled. If available reserves fall below operating thresholds, MMF redemption and recovery rebalancing begins, with an operating target of replenishing reserves within T+0 to T+2 days from the recovery request date, T. Replenishment thresholds, recovery assets and quantities, submission cutoffs, settlement schedules, progress and replenishment results are recorded. The reserve replenishment target is not a payout commitment to an individual user or a redemption deadline for every product. Day-count conventions, external product business days and submission cutoffs, and applicable payout deadlines are defined in each product’s specification and contracts. Funds purchases record the arcoUSD burn, treasury reserve withdrawal, external purchase and receipt of product tokens separately. Reserve assets already paid out are not also counted as backing for remaining arcoUSD, and claim and return conditions for incomplete purchases are linked. Any required reissuance is managed through separate approvals and records while preserving the original burn record. OTC arrangements apply conditions for approved partners and payout assets, execution limits and validity periods, and settlement for either token acquisition or redemption liquidity provision. A partner’s committed capacity is distinguished from payout balances already secured, and user payouts are reconciled separately from subsequent partner settlement. Optional extension strategies such as Morpho specify assets and collateral forms, markets and strategy limits, and recovery and loss conditions. The risk and operating scope of extension strategies is presented separately from the base MMF reserve composition.Pausing and Contract Changes
Global and function-level pauses can restrict new deposits and redemptions or define the scope of incident response. Depending on what is paused, claims for already approved redemptions and ProductToken transfers, issuance and burns may also be affected. Operating policies must distinguish new transactions from existing requests and specify user notifications, the scope of suspension and conditions for resuming operations. A proxy upgrade changes the contract implementation used by the same calling address. Mainnet change standards include approval procedures, code and storage layout verification, preservation of existing balances and requests, implementation schedules and change records. Partners review deployment addresses and implementation versions alongside administrator permissions and change policies.Settlement and Monitoring
The mainnet standard for completed settlement is reconciliation of the request with the actual movement of funds. Product, chain, vault and request identifiers are linked to the payout asset, quantity and recipient, successful transaction results and settlement records. Transaction hash creation, request receipt and completed payout are displayed as distinct states. The verifying party, verification method and completion criteria are specified in each product’s settlement policy. Each request is managed to completion through its selected payout route. If a payout outcome is unclear, another payout is withheld until the fund movement is confirmed. The standard is to retain approvals and evidence for exception handling and recovery. Operating monitoring covers price validity, deposit and redemption balances, reserved amounts and pending requests, issuance and burns, permissions, pause status and implementation changes. Asset and strategy holding, valuation and settlement records are reconciled against vault records, and the timing of indexed interface updates is distinguished from transaction results. Operating policies include responsible contacts, notification and recovery procedures for missing prices, liquidity shortfalls and key or permission incidents.Product Verification Materials
Partner review materials for a mainnet product link the information below. Each material records the actual responsible legal entity, preparer and reviewer, applicable product, version and reference date, update frequency and owner, and original document URL. Onboarding and Due Diligence describes preparation roles and how to request materials.
Independent audits and external reviews are described according to the actual reports’ subjects and scopes. Reviews of underlying code or an underlying product do not replace verification of the complete ARCO vault. Product-specific materials record both applied controls and remaining operating conditions.