Operational Security
Evaluates whether the protocol's infrastructure can absorb real failures under adverse conditions. The cluster comprises sub-metrics — Incident Playbook, Privilege Scope, Key Custody Environment, Circuit Breaker Sophistication, Redemption Risk, and Loss Absorption Capacity — each scored on a three-tier rubric and combined into a cluster-level assessment.
Circuit Breaker Sophistication
Evaluates how quickly and reliably the protocol can halt fund-touching activity during an attack. Detection-to-halt latency, scope coverage, and separation of pauser authority from upgrade authority are the primary inputs.
Incident Playbook
Evaluates whether the protocol has a defined, rehearsed process for detecting and responding to a compromise. The existence and maturity of pre-agreed response procedures is the primary input.
Key Custody Environment
Evaluates how the keys controlling privileged roles are stored and whether a single point of failure exists. The cryptographic and operational protection around private keys is the primary input.
Loss Absorption Capacity
Evaluates whether an explicit, liquid backstop exists and how it is activated. The size, transparency, and activation mechanism of the backstop are the primary inputs; the top tier requires autonomous on-chain trigger rules rather than governance-vote activation.
Privilege Constraints
Evaluates how easily privileged actions can be executed and how much time the community has to respond. Quorum thresholds, timelock durations on non-upgrade/non-mint actions, and active monitoring are the primary inputs.
Privilege Scope
Evaluates the reliability of user exits under stress. Withdrawal predictability, unbonding behavior through dislocations, and whether any actor can unilaterally pause withdrawals are the primary inputs. The top tier is capped at middle whenever a privileged actor can discretionarily pause withdrawals.
Redemption Risk
Evaluates the blast radius of a single privileged-key compromise. The breadth of powers attached to privileged roles, and whether they include custodial reach over user funds, is the primary input.