Trust should be inspectable, not implied.
This surface brings together SSS claims, system components, funding routes, authority boundaries, release evidence, risks, incidents, and governance. Unknown, stale, or unverified information stays visible as such.
One system, bounded planes, one financial judge.
The Trust Center is not a new business authority. It explains who owns each responsibility and what each plane must never do.
User intent
WWWExpresses actions; never judges financial success.
Financial kernel
CoreBalances, reservations, trades, liquidity, and final receipts.
External execution
Asset Hub + GatewaysRoutes, signing, broadcast, and finality evidence.
Read & evidence
Data API + PortalRebuildable views and public evidence; never rewrites finance.
Production components and public IDs
IDs are the stable baseline. Module hashes, controllers, and observation times are rolling evidence and remain Pending until collected.
| Component | Canister ID | Authority | Evidence |
|---|---|---|---|
| CoreCanonical internal balances, reservations, trades, orders, liquidity, fees, and authoritative financial receipts. | dlhkk-raaaa-…yl5a-cai | FINANCIAL CORE | Observation pendingModule Hash / Controllers |
| WWWApplication frontend and user interaction surface. | dmgm6-4yaaa-…yl5q-cai | USER INTERACTION | Observation pendingModule Hash / Controllers |
| PortalBrand and public positioning surface. | bpfil-eiaaa-…lkrq-cai | CONTENT | Observation pendingModule Hash / Controllers |
| DocsTechnical and product documentation surface. | rmlok-daaaa-…lrea-cai | CONTENT | Observation pendingModule Hash / Controllers |
| Data APIRebuildable market, history, reporting, daily-close, and public-safe projections. | xobtb-pyaaa-…lrsq-cai | DATA PROJECTION | Observation pendingModule Hash / Controllers |
| Agent GatewayIntent interpretation, draft, preview, confirmation, callback, and nonfinancial orchestration. | yq5eu-qqaaa-…zaga-cai | AGENT INTENT | Observation pendingModule Hash / Controllers |
| Dataroom / GrowthContribution records, Growth programs, and nonfinancial operational records. | 5jtld-gaaaa-…eekq-cai | NONFINANCIAL PROGRAM | Observation pendingModule Hash / Controllers |
| Asset HubAsset-route registry, external funding evidence, route coordination, and supported external execution state. | 7uamq-xiaaa-…grha-cai | EXTERNAL EXECUTION | Observation pendingModule Hash / Controllers |
| EVM GatewayEVM signing, broadcast, submission journal, finality observation, and bounded recovery. | 7tbke-2qaaa-…grhq-cai | EXTERNAL EXECUTION | Observation pendingModule Hash / Controllers |
| Solana GatewaySolana evidence, signing, broadcast, finality observation, and bounded recovery. | za2zu-caaaa-…gwpa-cai | EXTERNAL EXECUTION | Observation pendingModule Hash / Controllers |
| ETH Bridge LedgerDefined Ethereum-side bridge or route ledger support; exact authority requires production review. | 5o4em-jyaaa-…gria-cai | FINANCIAL SUPPORT | Observation pendingModule Hash / Controllers |
| BNB Bridge LedgerBNB-route bridge-ledger support. | zoyu4-zqaaa-…gwoa-cai | FINANCIAL SUPPORT | Observation pendingModule Hash / Controllers |
| BTC Bridge LedgerBTC-route bridge-ledger support. | 43aff-eqaaa-…gwqa-cai | FINANCIAL SUPPORT | Observation pendingModule Hash / Controllers |
| SOL Bridge LedgerSolana-route bridge-ledger support. | zjzsi-uiaaa-…gwoq-cai | FINANCIAL SUPPORT | Observation pendingModule Hash / Controllers |
| USDC Bridge LedgerProduction USDC bridge-ledger support across configured routes. | 5j5cy-eaaaa-…griq-cai | FINANCIAL SUPPORT | Observation pendingModule Hash / Controllers |
| USDT Bridge LedgerProduction USDT bridge-ledger support across configured routes. | 5a6je-siaaa-…grja-cai | FINANCIAL SUPPORT | Observation pendingModule Hash / Controllers |
Configured does not mean currently healthy.
The current preview exposes the stable route catalog. Fees, finality, gateway health, canary, reconciliation, and freshness will be attached as rolling evidence.
EVM · Arbitrum
3EVM · Base
3EVM · BNB Smart Chain
4EVM · Ethereum Mainnet
3ICP_ICRC · ICP
5SOLANA · Solana Mainnet
3Every public promise has an ID, status, and boundary.
LIVE, BETA, PARTIAL, TARGET, and RESEARCH are not interchangeable. Missing evidence can only downgrade a claim, never strengthen it.
CLAIM-PRIVATE-001PARTIALPrivate Trading System for the AI Era
SSS is building a Private Trading System for the AI Era.
CLAIM-EXPERIENCE-002BETACEX Experience
SSS is pursuing a CEX-style account experience with DEX trust boundaries.
CLAIM-TRUST-003PARTIALDEX Trust
DEX Trust means explicit financial authority, inspectable rules, production verification, visible dependencies, and governed upgrades.
CLAIM-CROSSCHAIN-004BETASupported multichain funding
SSS supports published, allowlisted multichain funding routes.
CLAIM-SETTLEMENT-005LIVEInternal onchain settlement
Internal financial outcomes settle on ICP canisters.
CLAIM-GASLESS-006LIVEGas-token abstraction for internal actions
Users do not need to prepare a gas token for every internal SSS trade or liquidity action.
CLAIM-BALANCE-007BETACanonical Balance
Supported funding routes feed canonical balances.
CLAIM-VERIFY-008PARTIALPrivacy-preserving verification
SSS has foundations for separating public market information from owner records.
CLAIM-AGENT-009BETAPermissioned AI-agent intents
The Agent may interpret and prepare supported actions.
CLAIM-THESIS-010LIVEYou should trade crypto on a blockchain.
You should trade crypto on a blockchain.
CLAIM-INSTITUTION-011TARGETPrivate Trading for Institutions
SSS is designing Private Trading for Institutions.
CLAIM-GOVERNANCE-012TARGETSNS governance
SNS-governed financial and privacy rules are a target architecture.
CLAIM-CRYPTO-013RESEARCHCryptographic confidentiality
SSS is researching cryptographic confidentiality.
Observe facts during iteration; attest versions at release.
The main development line is still moving, so this page does not present an interim commit as the final production release. Full source, Wasm, and deployed-module binding happens at an explicit release point.
Source-controlled registries and evidence contracts
Anonymous module-hash and controller observation
Local Wasm and production module-hash comparison
Release attestation and reproducible-build evidence
A public risk register is a trust surface.
This view exposes structural risks, current controls, and target controls. A risk remains OPEN until closure evidence exists.
RISK-CONTROLLER-001Pre-SNS controller authority
Critical canisters remain upgradeable by current controllers before the SNS transition.
- explicit production identities
- manual release review
- source and deployment records
- public controller manifests
- reproducible builds
- proposal-based upgrades
RISK-REPRO-002Incomplete reproducible production builds
Published source is not yet independently linked to every deployed critical Wasm.
- source-controlled release records
- pinned build environment
- deterministic builds
- public build manifests
RISK-PRIVACY-PUBLIC-003Remaining public-detail privacy gaps
Some public transaction-detail or recent-trade paths may expose exact or fingerprintable information.
- owner-oriented major read paths
- existing source audits
- owner scoping
- public aggregate contract
- recent-trade minimization
RISK-PRIVACY-OPERATOR-004Broad operator or administrator data access
Early-beta operational paths may expose more user-level information than the target model permits.
- admin authentication
- manual operational controls
- access inventory
- aggregate health
- user-authorized support
RISK-CROSSCHAIN-005External-chain and gateway risk
Deposits and withdrawals depend on external chains, contracts, gateways, RPCs, signatures, fees, evidence, and finality.
- route allowlists
- evidence
- finality thresholds
- fresh route registry
- bounded execution
- stronger canary evidence
RISK-KEY-006Signing and key-management risk
External execution depends on signing authority and key-management systems.
- narrow operational procedures
- restricted identities
- narrow signing scope
- rotation
- minimum-authority keepers
RISK-LIQUIDITY-007Limited liquidity and execution quality
Public Beta liquidity does not yet match mature CEX or leading DEX markets.
- current pools and market workflows
- core-market depth
- measured spread and slippage
- market-maker program
RISK-STABLE-008Upgrade and stable-state compatibility
Critical financial upgrades may create stable-state compatibility risk.
- stable-state inventories
- targeted audits
- post-upgrade checks
- versioned migrations
- upgrade simulations
- rollback boundaries
RISK-PROJECTION-009Data freshness and projection mismatch
Projection lag may cause stale or contradictory displays relative to Core.
- source cursors
- rebuildable projections
- existing freshness checks
- visible freshness
- automatic refresh after recovery
- mismatch alerts
RISK-FRONTEND-010Frontend, domain, and delivery risk
A compromised frontend or domain can mislead users even when canisters remain correct.
- frontend security audits
- controlled domains
- bundle hashes
- release manifests
- independent verification links
RISK-AGENT-011Agent permission expansion
An Agent or integration may receive broader read or execution authority than intended.
- confirmation flows
- current grant foundations
- Core execution
- scopes
- limits
- nonce
RISK-TELEMETRY-012Telemetry and browser-storage privacy
Telemetry, receipt caches, sessions, addresses, or device context may create user-data exposure.
- current client isolation and diagnostics
- data minimization
- purpose and retention
- expiry
RISK-INCIDENT-013Incomplete public incident process
Operational events can be fragmented or underexplained without one versioned incident registry.
- development and deployment records
- severity model
- incident IDs
- timelines
RISK-ISSUER-014Token issuer and contract risk
Stablecoins and wrapped assets depend on issuers, contracts, mints, bridges, or chain-key systems.
- canonical route controls
- asset registry
- contract disclosure
- route provenance
- pause and retirement process
RISK-CYCLES-015Canister resource and availability risk
Cycles, memory, or operational health can affect availability.
- cycles monitoring
- manual replenishment
- public-safe health
- threshold alerts
- funding policy
RISK-GOVERNANCE-016Premature or concentrated governance
Launching SNS before product, privacy, reproducibility, and distribution readiness may formalize weak or concentrated control.
- pre-SNS controller phase
- readiness planning
- launch gates
- public threat model
- distribution analysis
Incidents should be permanent, traceable, and correctable.
SSS has opened its first formal incident record. Facts, user protection, recovery status and unresolved boundaries remain visible while the audit continues.
SSS-INC-20260728July 28, 2026 CLMM exploit
The known exploit path has been contained. Seven affected assets were reconciled to atomic units, user liabilities remain fully covered, and the external proceeds are under continuing multi-chain monitoring.
Who may do what—and what they must never do.
Governance is not an SNS badge. It is the verifiable combination of controllers, upgrade rights, financial authority, operational permissions, and emergency boundaries.