# What is Ontorium?

Ontorium is a modular full-stack on-chain financial system for real assets.

Ontorium is built as a unified financial stack where assets are issued, activated through liquidity, and made accessible for real use by users.

Real-world assets are sourced, secured through established custody partners, and issued on-chain in a scalable and verifiable manner.

However, bringing real-world assets on-chain is not enough.

Most RWA systems stop at representation. They tokenize assets, but fail to integrate them into a functional financial system.

While U.S. Treasury-backed stablecoins have achieved product-market fit, this success has not extended to most other real-world assets.

This creates structural limitations:

* **Assets remain idle instead of generating financial activity**
* **Liquidity is fragmented across isolated markets**
* **Access to real-world value is indirect and inefficient**

As a result, real-world assets introduce value into crypto, but fail to activate, circulate, or scale it.

***

Ontorium addresses these limitations through an integrated financial architecture.

Ontorium is structured as a three-layer architecture, where real-world assets are issued, activated, and utilized within a unified on-chain financial stack.

* **Asset Layer**: Real-world assets are brought on-chain with verifiable backing and custody
* **Financial Layer**: Assets become active collateral within lending and liquidity markets
* **Application Layer**: Users access these financial capabilities through real-world use cases

These layers form a unified stack that connects real-world asset issuance, on-chain financial activity, and real-world utility. This is what enables Ontorium to move beyond tokenization and turn real-world assets into continuously utilized financial primitives.


# Asset Layer

The **Asset Layer** establishes the foundation of Ontorium,&#x20;bringing real-world assets on-chain as verifiable and usable financial primitives.

This layer defines how real-world assets are structured, verified, and represented on-chain,\
including their backing model, minting and redemption mechanisms, and reserve integrity.

It ensures that each asset maintains a clear and enforceable link to its underlying real-world value,\
making it suitable for financial utilization across the stack.

Rather than serving as static representations,&#x20;assets at this layer are designed to support continuous on-chain utilization,&#x20;forming the basis for liquidity, credit, and broader financial activity.

The first asset introduced within the Asset Layer is **OXAU**,&#x20;**a gold-backed** on-chain asset designed to combine real-world value with on-chain financial utility.

OXAU represents physical gold with verifiable backing, held in custody by an independent third-party custodian. It enables users to hold, transfer, and utilize gold as an on-chain financial asset.

It is designed not only for ownership,&#x20;but for integration into lending, liquidity, and broader financial strategies within the Ontorium stack.

<figure><img src="/files/7TRvhP8qOIL5KAVeCxgT" alt=""><figcaption></figcaption></figure>


# Backing Structure

OXAU is a gold-backed digital asset issued on-chain by Ontorium. Each OXAU token represents exactly 1 gram of physical gold, held in custody by an independent, regulated third-party custodian in secure vaulting facilities.

**1 OXAU = 1 gram of physical gold**

The minimum unit for minting and redemption is 1,000 OXAU, equivalent to 1 kilogram of gold.

***

#### **How the Backing Works**

When a user mints OXAU, the equivalent amount of physical gold is allocated and held in custody on behalf of the token holder. The gold is segregated and held in secure vaulting facilities. OXAU tokens in circulation are fully backed by physical gold at all times on a 1:1 gram basis.

When a user redeems OXAU, the corresponding gold is released from custody in accordance with applicable redemption terms. For physical gold redemption inquiries, please contact <contact@ontorium.io>.

***

#### **Why Physical Gold?**

Gold has served as a store of value for thousands of years and remains one of the most widely recognized and liquid real-world assets globally. Key characteristics that make gold suitable as a backing asset include:

* Globally recognized store of value with deep liquidity
* Historically resilient against inflation and currency devaluation
* Tangible, scarce, and independently verifiable asset
* Widely accepted as collateral in traditional financial markets

By anchoring OXAU to physical gold, Ontorium connects on-chain financial activity to one of the most trusted real-world assets.

***

#### **Custody Arrangement**

Physical gold underlying OXAU is held by an independent, regulated third-party custodian in secure vaulting facilities. The custody structure is designed to ensure that gold backing OXAU is:

* Held in segregated, secure vaulting facilities
* Independently managed from Ontorium's operational activities
* Subject to ongoing verification processes


# Reserve Integrity and Transparency

#### **Reserve Integrity and Transparency**

Every OXAU token in circulation is backed by 1 gram of physical gold held in custody. Reserve integrity is verified and disclosed on an ongoing basis.

***

#### **Proof of Reserves**

Ontorium publishes a monthly Proof of Reserves report to verify that the total supply of OXAU in circulation is fully backed by physical gold held in custody.

Each monthly report includes:

* Total OXAU tokens in circulation
* Total physical gold held in custody (in grams)
* Confirmation that the 1:1 backing ratio is maintained

Reports are published on a regular monthly basis and are accessible to all users.

***

#### **On-Chain Verification**

The total supply of OXAU tokens is publicly verifiable on-chain at any time. Users can independently verify the circulating supply of OXAU directly on the blockchain and cross-reference it against the published monthly Proof of Reserves report.

This approach combines on-chain supply transparency with monthly custody verification, allowing any user to independently confirm that OXAU remains fully backed.


# Mint & Redemption

### Overview

A credible on-chain real asset requires more than issuance. It must maintain a clear and enforceable path between the on-chain token and its underlying reserve.

Within Ontorium, minting and redemption are designed as core mechanisms of the Asset Layer. They preserve a direct link between the on-chain token and its underlying asset, and ensure that OXAU issuance remains disciplined and grounded in its real-world reserve model.

***

#### Mint & Redemption Parameters

<table><thead><tr><th width="343">Parameter</th><th width="460">Value</th></tr></thead><tbody><tr><td>Supported assets</td><td>USDC, USDT</td></tr><tr><td>Mint Fee</td><td>0.25%</td></tr><tr><td>Redemption Fee</td><td>0.25%</td></tr><tr><td>Mint Price</td><td>+1.5%</td></tr><tr><td>Redemption Price</td><td>-1.5%</td></tr><tr><td>Minimum Mint/Redemption Size</td><td>1,000 OXAU</td></tr><tr><td>Mint/Redemption increment</td><td>1,000 OXAU</td></tr><tr><td>Mint/On-Chain Redemption Window</td><td>01:00~10:00 UTC</td></tr><tr><td>Mint Settlement </td><td>Immediate during operating hours</td></tr><tr><td>Redemption Settlement </td><td>Immediate where buffer is available; otherwise T+3</td></tr></tbody></table>

For physical gold redemption inquiries, please contact <contact@ontorium.io>.


# KYC Framework

### Overview

To ensure regulatory compliance and secure access to asset-backed functionality, Ontorium integrates a tiered KYC system powered by Sumsub.

Each level of verification unlocks different capabilities within the minting and redemption process.

KYC verification is required to access core functionalities within the Asset Layer, including **minting, redemption, and physical settlement.**

***

#### **KYC Levels & Access**

{% columns %}
{% column %}

**L1 (Identity Verification)**

* Liveness and identity verification required
* Enables:
  * OXAU minting
  * On-chain redemption
    {% endcolumn %}

{% column %}

**L2 (Proof of Address)**

* Address verification required
* Enables:
  * All L1 functionality
  * Physical gold redemption
    {% endcolumn %}

{% column %}

**L3 (Institutional KYC)**

* Institutional onboarding and whitelisting
* Enables:
  * Full access to all platform services
    {% endcolumn %}
    {% endcolumns %}

***

#### **What is required for KYC/KYB?**

{% columns %}
{% column width="41.66666666666667%" %}

**Individuals:**

* Full Legal name
* Date of Birth&#x20;
* Country of citizenship and residence

**Identity Verification (L1):**

* Government-issued ID\
  (e.g. passport, driver’s license, national ID)

**Address Verification (L2):**

* Proof of address document\
  (e.g. utility bill, bank statement, government-issued document)
  {% endcolumn %}

{% column width="58.33333333333333%" %}

**Entities:**

* Legal entity name
* Business name (DBA or trading name if different)
* Country of incorporation
* Addresses:
  * Principal place of business
  * Registered office address (if different)
  * Mailing address (if different)
* Official identification number
  {% endcolumn %}
  {% endcolumns %}

***

### **Jurisdiction Restrictions**

**Access to Ontorium services is restricted in certain jurisdictions due to regulatory and compliance requirements.**

***

#### **Restricted Countries**

* Users located in or associated with the following jurisdictions are not permitted to access minting, redemption, or asset-related services:

**FATF Blacklist:**

* DPRK (North Korea)
* Iran
* Myanmar

**FATF Greylist (Subject to enhanced due diligence):**

* Algeria, Angola, Bolivia, Bulgaria, Cameroon, Côte d'Ivoire, DR Congo, Haiti, Kenya, Lao PDR, Lebanon, Monaco, Namibia, Nepal, South Sudan, Syria, Venezuela, Vietnam, Yemen

***

#### **Sanctions Compliance**

* Addresses and individuals listed under **UN, US, EU, or UK sanctions programs** are subject to:
  * Account restriction
  * Transaction blocking
  * Service denial

***

#### **United States Restrictions**

* The following users are restricted:
  * US persons
  * US entities
  * Users accessing from US IP

> This restriction applies due to applicable regulatory requirements.


# Progammability and Expansion

#### Programmable Financial Primitives

Assets within Ontorium are not static representations of value. They are structured as programmable financial primitives that integrate directly into on-chain financial systems.

***

#### Verifiable Linkage to Real-World Assets

Each asset, starting with **OXAU**, maintains a clear and enforceable linkage between its underlying real-world backing and its on-chain representation. This ensures that assets are not only held, but can be actively utilized across financial contexts.

***

#### Collateral and Liquidity Utility

At the Financial Layer, **OXAU** functions as collateral within lending markets such as **AQUA**, enabling borrowing activity and liquidity formation. It can also be integrated into curated vault strategies to support structured yield generation.

***

#### Beyond Passive Ownership

This design allows assets to move beyond simple ownership. They become active components of financial systems, participating in lending, liquidity provision, and capital allocation.


# Financial Layer

The Financial Layer is responsible for transforming base assets into productive financial primitives.

Where the Asset Layer establishes trust, backing, and representation, the Financial Layer activates those assets within on-chain markets. Its role is to unlock liquidity, enable collateral utility, and create capital-efficient financial use cases for real assets.

This layer exists because ownership alone is not enough. A real asset represented on-chain becomes significantly more useful when it can support borrowing, lending, liquidity access, and yield-generating financial activity. The Financial Layer is the mechanism through which this transformation occurs.

Within Ontorium, the current flagship implementation of the Financial Layer is **AQUA**, a lending market designed for real-world assets collateral.


# AQUA Overview

**AQUA** is the flagship implementation of the Financial Layer. It is designed as a capital-efficient lending market optimized for real-asset collateral such as **OXAU**.

The purpose of AQUA is to allow users and institutions to access liquidity and yield without requiring real assets to remain passive. In this model, OXAU and future real-asset primitives can be activated within lending markets rather than held solely as static stores of value.

AQUA is therefore not positioned as a general-purpose lending market first. Its design logic is centered on the requirements of real-asset finance. This includes how collateral should be evaluated, how liquidity should be managed, and how risk controls should be tailored to a market built around trusted base assets rather than only crypto-native volatility.


# Liquidity, Collateral and Borrowing

#### **Liquidity, Collateral and Borrowing**

AQUA operates as a two-sided lending market where users can supply assets to earn yield or deposit collateral to access borrowing capacity.

***

#### **Supplying Liquidity**

Users can supply supported assets such as OXAU, USDC, and USDT to AQUA lending pools. Supplied assets earn yield generated from borrowing activity within the protocol. Interest rates are variable and are determined by the utilization rate of each asset pool, adjusting dynamically as borrowing demand changes relative to available supply.

***

#### **Collateral and Borrowing**

Users may deposit OXAU as collateral to borrow supported assets within AQUA.&#x20;

The following parameters apply:

| Parameter             | OXAU             | USDC             | USDT             |
| --------------------- | ---------------- | ---------------- | ---------------- |
| Max LTV               | 65%              | 75%              | 75%              |
| Liquidation Threshold | 75%              | 88%              | 88%              |
| Liquidation Bonus     | 5%               | 4.5%             | 4.5%             |
| Borrow Assets         | OXAU, USDC, USDT | OXAU, USDC, USDT | OXAU, USDC, USDT |
| Reserve Factor        | 10%              | 10%              | 10%              |

***

#### **Liquidation**

If the value of a borrower's collateral falls and the position exceeds the liquidation threshold of 85%, the position becomes eligible for liquidation. Liquidation may occur automatically and without prior notice. Users are solely responsible for monitoring their collateral ratio and managing their positions accordingly.


# AQUA Vaults

## Overview

AQUA Vaults are ERC-4626-based curated vaults built on AQUA Market. Users deposit a supported asset, receive Vault shares, and gain exposure to market-based yield generated through approved strategies without having to manage individual positions directly.

Each Vault accepts a single designated deposit asset and operates under its own strategy allocation, liquidity parameters, risk limits, and reporting framework.

***

### Available Vaults

<table><thead><tr><th width="142.54541015625">Vault</th><th width="167">Target Yield</th><th width="189.7271728515625">Withdrawal Period</th><th width="110.727294921875">Chain</th><th>Deposit Asset</th></tr></thead><tbody><tr><td><sub>AQUA USDC Vault</sub></td><td>Target APY: TBD</td><td>Instant / T+1 Queue</td><td><img src="/files/X7ufaiOfk5GjZWz0CqaO" alt=""></td><td><img src="/files/BdavyKB7q2A1Hmbt5pmI" alt=""></td></tr><tr><td><sub>AQUA OXAU Vault</sub></td><td>Estimated APY: TBD</td><td>Instant / T+1 Queue</td><td><img src="/files/X7ufaiOfk5GjZWz0CqaO" alt=""></td><td><img src="/files/zq7Le8yYC8RNjDZBB2sb" alt=""></td></tr></tbody></table>

{% hint style="info" %}
Displayed APY figures are indicative, variable, and based on recognized Vault performance or applicable incentive programs. They do not represent fixed or guaranteed returns.

Actual yield may vary depending on strategy performance, market conditions, liquidity availability, Vault utilization, fees, and changes in the value of underlying positions.
{% endhint %}

***

### How It Works

```
Deposit supported asset
        ↓
Receive Vault shares
        ↓
Vault allocates assets to approved strategies
        ↓
Strategy performance is reflected in the Vault share price
        ↓
Withdraw instantly when liquidity is available
or use the T+1 withdrawal queue
```

Vault shares represent a proportional claim on the Vault’s recognized assets.

Base yield is reflected through changes in the Vault share price. When the Vault generates positive net returns, each share may become redeemable for more of the underlying asset. Strategy losses or negative valuation changes may cause the share price to decline.

Vault shares do not rebase, and Base APY is not distributed through a separate reward token.

***

### Yield Structure

Vault yield may be displayed in two separate components:

#### Base APY

Base APY represents the historical annualized performance generated by the Vault’s approved strategies after applicable Vault-level performance fees, unless otherwise stated.

Base APY accrues through the Vault share price and may increase or decrease depending on recognized strategy performance.

#### Boost APY

Boost APY represents additional yield distributed through time-limited incentive programs, protocol rewards, or ecosystem campaigns.

Boost APY is displayed separately from Base APY and does not form part of the Vault share price unless explicitly stated. Incentive programs may be adjusted, extended, suspended, or discontinued according to their applicable campaign terms.

APY is backward-looking or indicative and should not be interpreted as a forecast of future performance.

***

### Key Design Principles

* **Standards-based accounting:** Each Vault follows an ERC-4626-based tokenized vault model, with Vault shares representing a proportional claim on recognized Vault assets.
* **Curated strategies:** Assets may be allocated only to approved strategies operating within configured allocation limits and risk parameters.
* **Defined withdrawal paths:** Withdrawals may be completed instantly when sufficient Vault liquidity is available. Otherwise, users may submit a request through the T+1 withdrawal queue.
* **NAV-based pricing:** Vault share value is determined using recognized Vault assets and outstanding Vault shares, with defined controls for fees, rounding, stale valuations, and off-chain reporting where applicable.
* **Transparent reporting:** Vault portfolio information, strategy allocations, valuation updates, and material on-chain activity may be made available through the AQUA interface, blockchain records, and linked reports.
* **Role-separated controls:** Strategy management, reporting, allocation, governance, and emergency actions are separated through designated roles. Selected privileged actions may be subject to configured timelock delays.
* **Asset-level verification:** For the OXAU Vault, Vault-level portfolio and NAV reporting is complemented by OXAU Proof of Reserve. Proof of Reserve verifies the applicable backing of OXAU but does not independently verify the performance or liquidity of Vault strategies.

***

### Fees&#x20;

The default Vault fee structure is:

* 0% deposit fee
* 0% withdrawal fee
* 0% management fee
* Performance fee applied only to generated yield

Displayed Base APY is shown net of the applicable performance fee unless otherwise stated.

Applicable fees may vary by Vault and may be updated through the relevant governance or protocol configuration process. Users should review the current fee information shown on the relevant Vault page and AQUA interface before depositing.

***

### Risks

Depositing into an AQUA Vault involves risk.

Vault performance may be affected by strategy losses, liquidity constraints, smart contract vulnerabilities, stale or inaccurate valuation data, oracle failures, third-party protocol failures, custody or settlement issues, operational controls, and adverse market conditions.

Withdrawals are subject to available liquidity and may not always be completed immediately. Use of a T+1 withdrawal queue does not guarantee settlement within a fixed period.

{% hint style="warning" %}
AQUA Vaults are not bank deposits. Principal, liquidity, yield, and withdrawal timing are not guaranteed. Users should review the relevant Vault terms, strategy information, fee structure, and risk disclosures before depositing.
{% endhint %}


# USDC Vault

### **Overview**

The AQUA USDC Vault is an ERC-4626-based stablecoin yield vault built on AQUA Market.

Users deposit USDC, receive aqUSDC Vault shares, and gain exposure to market-based yield generated through approved strategies without having to manage individual lending or liquidity positions directly.

The Vault accepts only USDC as its designated deposit asset and operates under configured strategy limits, liquidity parameters, risk controls, and reporting requirements.

***

### Purpose

The USDC Vault is designed for users and institutions seeking USDC-denominated yield within the AQUA ecosystem.

Deposited USDC may be allocated across approved strategies, which may include:

* AQUA lending markets
* Approved external stablecoin lending markets
* Approved fixed-rate or fixed-term strategies
* Other disclosed USDC-denominated yield strategies

The Vault is intended to support liquidity across AQUA Market while providing depositors with a single, transparent Vault position representing their proportional interest in the Vault’s recognized assets.

Strategy availability, allocation limits, and applicable risks may vary over time.

***

### USDC Vault Details

<table><thead><tr><th width="143.54547119140625">Vault</th><th width="158.0908203125">Target Yield</th><th width="170.6363525390625">Withdrawal Period</th><th>Chain</th><th>Deposit Asset</th></tr></thead><tbody><tr><td><sub>AQUA USDC Vault</sub></td><td>Target APY: TBD</td><td>Instant / T+1 Queue</td><td><img src="/files/X7ufaiOfk5GjZWz0CqaO" alt=""></td><td><img src="/files/BdavyKB7q2A1Hmbt5pmI" alt=""></td></tr></tbody></table>

The USDC Vault accepts only USDC through the supported deposit process.

Tokens transferred directly to the Vault contract outside the official deposit flow may not result in Vault shares being issued and may not be recoverable through the standard Vault interface.

Users should deposit only through the official AQUA Market interface and verify the network, asset, and transaction details before confirming a transaction.

***

### Share Token

When users deposit USDC, they receive aqUSDC Vault shares.

Each aqUSDC share represents a proportional claim on the USDC Vault’s recognized assets. The number of shares issued is determined using the Vault’s current accounting exchange rate, subject to applicable fees, rounding rules, and ERC-4626 conversion mechanics.

Base yield accrues through changes in the Vault share price.

When the Vault generates positive net returns, each aqUSDC share may become redeemable for more USDC. Strategy losses, fees, or negative valuation changes may cause the share price to decline.

Vault shares do not rebase, and Base APY is not distributed through a separate reward token.

For instant withdrawals, shares are burned when the withdrawal transaction is completed.

For queued withdrawals, shares are burned when the withdrawal request is submitted. The corresponding USDC is transferred later, after sufficient liquidity has been prepared and the withdrawal becomes claimable.

***

### Yield and Strategy

The USDC Vault may display yield in two separate components.

#### Base APY

Base APY represents the annualized historical or indicative performance generated by the Vault’s approved strategies.

Base yield may include:

* Interest generated through AQUA lending markets
* Supply interest from approved external lending markets
* Returns from approved fixed-rate or fixed-term strategies
* Other disclosed USDC-denominated strategy returns

Base APY accrues through the aqUSDC share price and is displayed net of the applicable performance fee unless otherwise stated.

Base APY is variable and may increase or decrease depending on market conditions, utilization, strategy performance, liquidity, fees, and recognized valuation changes.

#### Boost APY

Boost APY represents additional yield distributed through time-limited incentive programs, protocol rewards, or ecosystem campaigns.

Boost APY is displayed separately from Base APY and does not accrue through the Vault share price unless explicitly stated.

Boost programs may be adjusted, extended, suspended, or discontinued according to their applicable campaign terms.

Displayed APY is not a forecast or guarantee of future performance.

***

### Strategy Allocation

The USDC Vault may allocate deposited assets across multiple approved strategies in accordance with its allocation policy.

Each strategy may be subject to:

* Absolute allocation caps
* Relative allocation limits
* Liquidity requirements
* Strategy-specific risk limits
* Governance or curator approval
* Reporting and valuation requirements

The initial production strategy composition will be disclosed before deposits are enabled.

| Strategy Type | Description |
| ------------- | ----------- |
| TBD           | TBD         |

Actual allocations may change over time due to market conditions, borrowing demand, withdrawal demand, strategy performance, available liquidity, and configured risk limits.

A target allocation is not a guarantee that the Vault will continuously maintain that allocation. Assets may remain undeployed or be reallocated when required for liquidity, risk management, or operational purposes.

Only approved and disclosed strategies may receive Vault assets.

***

### Key Risks

Depositing into the USDC Vault involves risk, including the possible loss of principal.

* **USDC Risk:** USDC may lose its intended value due to issuer, reserve, banking, liquidity, redemption, or regulatory events.
* **Strategy and External Protocol Risk:** Approved strategies or third-party protocols may underperform, experience losses, become illiquid, or fail.
* **Liquidity Risk:** The Vault may not have enough immediately available USDC to satisfy all withdrawals. Users may need to use the T+1 withdrawal queue, and settlement may take longer than expected.
* **Smart Contract and Valuation Risk:** Contract vulnerabilities, stale NAV data, incorrect accounting, or oracle failures may affect share pricing, deposits, or withdrawals.
* **Operational and Regulatory Risk:** Vault operations may be affected by reporting delays, role management, emergency controls, compliance requirements, or regulatory restrictions.

{% hint style="warning" %}

### Important Notice

The USDC Vault is not a bank deposit. Principal, liquidity, withdrawal timing, and yield are not guaranteed. Displayed APY is variable and may differ from future realized performance.
{% endhint %}


# OXAU Vault

### **Overview**

The AQUA OXAU Vault is an ERC-4626-based, gold-denominated yield vault built on AQUA Market.

Users deposit OXAU, receive aqOXAU Vault shares, and gain exposure to yield generated through approved strategies without having to manage individual lending, liquidity, or strategy positions directly.

The Vault is designed to allow users and institutions to maintain OXAU-denominated exposure while making their holdings more productive within the AQUA ecosystem.

The OXAU Vault accepts only OXAU as its designated deposit asset and operates under configured strategy limits, liquidity parameters, risk controls, and reporting requirements.

***

### Purpose

The OXAU Vault is designed for users and institutions seeking to maintain on-chain exposure to gold while participating in approved OXAU-denominated yield strategies.

Deposited OXAU may be allocated across approved strategies, which may include:

* AQUA lending markets
* Approved OXAU liquidity strategies
* Approved gold-linked financing strategies
* Approved gold-linked financing strategies, including approved physical gold leasing arrangements based on the deposited OXAU-equivalent gold weight
* Other disclosed strategies capable of generating OXAU-denominated returns

The Vault is intended to support OXAU liquidity across AQUA Market while providing depositors with a single Vault position representing their proportional interest in the Vault’s recognized assets.

Strategy availability, allocation limits, liquidity terms, and applicable risks may change over time.

***

### OXAU Vault Details

<table><thead><tr><th width="145.63641357421875">Vault</th><th width="176.272705078125">Target Yield</th><th width="173.8182373046875">Withdrawal Period</th><th width="111.6363525390625">Chain</th><th>Deposit Asset</th></tr></thead><tbody><tr><td><sub>AQUA OXAU Vault</sub></td><td>Estimated APY: TBD</td><td>Instant / T+1 Queue</td><td><img src="/files/X7ufaiOfk5GjZWz0CqaO" alt=""></td><td><img src="/files/zq7Le8yYC8RNjDZBB2sb" alt=""></td></tr></tbody></table>

The OXAU Vault accepts only OXAU through the supported deposit process.

Tokens transferred directly to the Vault contract outside the official deposit flow may not result in Vault shares being issued and may not be recoverable through the standard Vault interface.

Users should deposit only through the official [AQUA Market](https://aquafinance.io/) interface and verify the network, asset, and transaction details before confirming a transaction.

***

### Share Token

When users deposit OXAU, they receive aqOXAU Vault shares.

Each aqOXAU share represents a proportional claim on the OXAU Vault’s recognized assets. The number of shares issued is determined using the Vault’s current accounting exchange rate, subject to applicable fees, rounding rules, and ERC-4626 conversion mechanics.

Base yield accrues through changes in the aqOXAU share price.

When the Vault generates positive net returns, each aqOXAU share may become redeemable for more OXAU. Strategy losses, fees, or negative valuation changes may cause the share price to decline.

Vault shares do not rebase, and Base APY is not distributed through a separate reward token.

For instant withdrawals, shares are burned when the withdrawal transaction is completed.

For queued withdrawals, shares are burned when the withdrawal request is submitted. The corresponding OXAU is transferred later, after sufficient liquidity has been prepared and the withdrawal becomes claimable.

***

### Yield and Strategy

The OXAU Vault may display yield in two separate components.

#### Base APY

Base APY represents the annualized historical or indicative performance generated by the Vault’s approved strategies.

Base yield may include:

* Interest generated through AQUA lending markets
* Returns from approved OXAU liquidity strategies
* Returns from approved gold-linked financing strategies
* Returns from approved physical gold leasing arrangements, where applicable, based on the gold weight represented by deposited OXAU
* Other disclosed OXAU-denominated strategy returns

Base APY accrues through the aqOXAU share price and is displayed net of the applicable performance fee unless otherwise stated.

Base APY is calculated in OXAU terms. Changes in the fiat value of gold or OXAU are separate from the Vault’s strategy-generated yield.

For example, an increase in the market price of gold may increase the fiat value of a user’s OXAU position without increasing the Vault’s OXAU-denominated APY. Similarly, a decline in the market price of gold may reduce the fiat value of the position even if the Vault generates positive OXAU-denominated yield.

Base APY is variable and may increase or decrease depending on market conditions, utilization, strategy performance, liquidity, fees, and recognized valuation changes.

#### Boost APY

Boost APY represents additional yield distributed through time-limited incentive programs, protocol rewards, or ecosystem campaigns.

Boost APY is displayed separately from Base APY and does not accrue through the Vault share price unless explicitly stated.

Boost programs may be adjusted, extended, suspended, or discontinued according to their applicable campaign terms.

Displayed APY is not a forecast or guarantee of future performance.

***

### Strategy Allocation

The OXAU Vault may allocate deposited assets across multiple approved strategies in accordance with its allocation policy.

Each strategy may be subject to:

* Absolute allocation caps
* Relative allocation limits
* Liquidity requirements
* Strategy-specific risk limits
* Governance or curator approval
* Reporting and valuation requirements
* Counterparty or venue restrictions

The initial production strategy composition will be disclosed before deposits are enabled.

| Strategy Type | Description |
| ------------- | ----------- |
| TBD           | TBD         |

Actual allocations may change over time due to borrowing demand, withdrawal demand, market conditions, strategy performance, available liquidity, and configured risk limits.

A target allocation is not a guarantee that the Vault will continuously maintain that allocation. Assets may remain undeployed or be reallocated when required for liquidity, risk management, or operational purposes.

Only approved and disclosed strategies may receive Vault assets.

***

### Key Risks

Depositing into the OXAU Vault involves risk, including the possible loss of principal.

* **Gold Price and OXAU Risk:** The fiat value of OXAU may rise or fall with the market price of gold. OXAU also depends on its issuance, reserve, custody, and legal arrangements.
* **Custody and Redemption Risk:** Physical gold redemption may be subject to eligibility requirements, minimum amounts, fees, jurisdictional restrictions, settlement periods, and operational procedures.
* **Strategy and External Protocol Risk:** Approved strategies or third-party protocols may underperform, experience losses, become illiquid, or fail.
* **Liquidity Risk:** The Vault may not have enough immediately available OXAU to satisfy all withdrawals. Users may need to use the T+1 withdrawal queue, and settlement may take longer than expected.
* **Smart Contract, Oracle, and NAV Risk:** Contract vulnerabilities, incorrect price feeds, stale valuations, or reporting errors may affect share pricing, strategy operation, deposits, or withdrawals.
* **Operational and Regulatory Risk:** Vault operations may be affected by reporting delays, counterparties, emergency controls, compliance requirements, or regulatory restrictions.

***

{% hint style="warning" %}

### Important Notice

The OXAU Vault is not a bank deposit or guaranteed gold investment product. Principal, liquidity, withdrawal timing, gold price, and yield are not guaranteed. Displayed APY is variable and may differ from future realized performance.
{% endhint %}


# Deposits & Withdrawals

This page explains how deposits and withdrawals work across AQUA Vaults.

AQUA Vaults are ERC-4626-based tokenized vaults. When users deposit a supported asset, they receive Vault shares representing a proportional claim on the Vault’s recognized assets.

When users withdraw, their Vault shares are burned and the corresponding underlying asset is returned through either an instant withdrawal or the withdrawal queue, depending on available Vault liquidity.

***

### Deposits

Users deposit the supported asset through the official AQUA Market interface.

Each Vault accepts only its designated deposit asset:

* The USDC Vault accepts USDC.
* The OXAU Vault accepts OXAU.

Tokens transferred directly to a Vault contract outside the supported deposit flow may not result in Vault shares being issued and may not be recoverable through the standard Vault interface.

Users should verify the selected Vault, asset, network, and transaction details before submitting a deposit.

***

### Deposit Flow

{% stepper %}
{% step %}

### 1. Select Vault

Users select the Vault into which they want to deposit.

Before depositing, users should review:

* The designated deposit asset
* The supported network
* Current Vault status
* Displayed Base APY and Boost APY, where applicable
* Strategy composition and allocation information
* Withdrawal conditions
* Applicable fees
* Relevant risks
  {% endstep %}

{% step %}

### 2. Approve Asset

Before the first deposit, users may need to authorize the Vault contract to spend the selected deposit asset.

Asset approval is a separate on-chain transaction and may require a network fee.

Users should approve only the required amount unless they intentionally choose a higher allowance.
{% endstep %}

{% step %}

### 3. Deposit Asset

After approval, users can submit a deposit transaction.

The number of Vault shares issued is calculated using the Vault’s current accounting exchange rate.

The final number of shares received may be affected by:

* The current Vault NAV
* Outstanding Vault share supply
* Applicable fees
* Rounding rules
* Virtual-share accounting
* Changes in Vault state before transaction confirmation

Any preview shown by the interface is an estimate until the transaction is executed on-chain.
{% endstep %}

{% step %}

### 4. Receive Vault Shares

Once the deposit transaction is completed, the user receives the applicable Vault share token.

Vault shares represent the user’s proportional claim on the Vault’s recognized assets.

Base yield accrues through changes in the Vault share price. If the Vault generates positive net returns, each share may become redeemable for more of the underlying asset. Strategy losses, fees, or negative valuation changes may cause the share price to decline.

Vault shares do not rebase.
{% endstep %}
{% endstepper %}

***

### Deposit Restrictions

Deposits or share minting may be temporarily restricted under certain conditions, including:

* The Vault’s deposit capacity has been reached
* Deposits or minting have been paused
* Applicable off-chain NAV information is stale
* Required eligibility or compliance checks are not satisfied
* A configured Gate prevents the transaction
* Risk controls or emergency mechanisms are active
* The Vault is undergoing maintenance or configuration changes

When an off-chain valuation becomes stale, new deposits may be restricted to prevent shares from being issued using outdated valuation information.

If deposits are unavailable, users should review the current Vault status shown in the AQUA Market interface.

***

### Withdrawals

Users withdraw from a Vault by redeeming or burning their Vault shares.

The amount of underlying assets returned is determined using the Vault’s current accounting exchange rate and the number of shares being withdrawn, subject to applicable fees and rounding rules.

AQUA Vaults support two withdrawal paths:

```
Instant Withdrawal, T+1 Withdrawal Queue
```

A withdrawal is processed through one path. A single withdrawal transaction is not automatically divided between an instant withdrawal and a queued withdrawal.

If the full requested amount cannot be withdrawn instantly, the user may submit the amount through the withdrawal queue.

***

### Available Liquidity

Instant withdrawal availability is based on liquidity that is immediately available to the Vault.

This may include idle underlying assets held directly by the Vault, after excluding assets that are already reserved or committed to other withdrawals.

Available Vault liquidity is not necessarily the same as liquidity reported by a strategy.

Assets held in a strategy may require:

* Deallocation
* Position unwinding
* Counterparty settlement
* Off-chain transfer
* Network confirmation
* Operational processing

before they become available for withdrawal or claim.

***

### Instant Withdrawal

An instant withdrawal is available when the Vault has sufficient immediately available liquidity for the full requested amount.

When an instant withdrawal is completed:

1. The user submits the withdrawal transaction.
2. The applicable Vault shares are burned.
3. The underlying asset is transferred to the user in the same transaction.

Instant withdrawal availability may depend on:

* Idle Vault liquidity
* Assets reserved for existing withdrawals
* Current withdrawal demand
* Strategy allocation
* Applicable Gate checks
* Vault and network conditions

Availability shown in the interface may change before a transaction is confirmed.

***

### T+1 Withdrawal Queue

When sufficient instant liquidity is not available, users may submit a withdrawal through the T+1 withdrawal queue.

The queue gives the Vault time to recover liquidity from strategies, rebalance assets, and process pending withdrawal obligations.

The standard queue flow is:

```
Submit withdrawal request
        ↓
Vault shares are burned
        ↓
Withdrawal amount is recorded as pending
        ↓
Vault prepares and reserves liquidity
        ↓
All or part of the amount becomes claimable
        ↓
User claims the available underlying asset
```

For a queued withdrawal, the user’s Vault shares are burned when the withdrawal request is submitted, not when the underlying asset is later claimed.

The applicable withdrawal amount and withdrawal fee, if any, are determined at the request stage according to the Vault’s accounting rules.

***

### Meaning of T+1

T+1 represents the Vault’s standard target processing framework for queued withdrawals. It is not a guaranteed settlement deadline.

Actual processing time may vary depending on:

* Strategy settlement periods
* Available Vault liquidity
* Withdrawal demand
* Market conditions
* Counterparty or off-chain settlement
* Network conditions
* Risk controls
* Emergency or operational conditions

A queued withdrawal may therefore become claimable earlier or later than the standard target period.

The applicable time basis, cutoff rules, and any Vault-specific processing schedule should be disclosed on the relevant Vault page or interface.

***

### Partial Fulfillment

A queued withdrawal may be fulfilled in whole or in part.

When only part of the pending amount has been prepared, that amount may become claimable while the remaining balance continues to be processed.

The interface may therefore show separate amounts for:

* Pending withdrawal
* Ready to claim
* Already claimed
* Remaining unfulfilled balance

Multiple queued withdrawal requests from the same wallet may be aggregated into a single pending withdrawal position, depending on the Vault’s accounting design.

***

### Claim

Once all or part of a queued withdrawal becomes claimable, the user may submit a separate claim transaction.

A claim is an on-chain transaction and may require a network fee.

When a claim is completed:

1. The claimable amount is deducted from the user’s recorded withdrawal balance.
2. The underlying asset is transferred to the user’s wallet.
3. Any remaining pending amount continues through the queue.

The underlying asset is not transferred automatically unless the applicable interface or Vault process explicitly supports automatic settlement.

***

### Withdrawal Status

The interface may display the following withdrawal statuses:

| Status          | Description                                                                                        |
| --------------- | -------------------------------------------------------------------------------------------------- |
| Processing      | The withdrawal has been submitted and liquidity is being prepared.                                 |
| Partially Ready | Part of the withdrawal is available to claim while the remaining amount continues to be processed. |
| Ready to Claim  | The currently fulfilled withdrawal amount is available to claim.                                   |
| Claimed         | The available underlying asset has been transferred to the user’s wallet.                          |
| Delayed         | Processing is taking longer than the standard target period or requires additional action.         |

Instant withdrawals are normally completed within a single transaction and may appear directly as completed withdrawal activity rather than as a queued request.

***

### Withdrawal Delays

Withdrawals may be delayed under certain conditions, including:

* Insufficient immediately available liquidity
* High withdrawal demand
* Strategy deallocation or settlement delays
* External protocol restrictions
* Off-chain transfer or settlement delays
* Network congestion
* Smart contract or infrastructure issues
* Counterparty or custodian disruption
* Emergency controls
* Applicable Gate or compliance restrictions

A stale off-chain NAV report does not automatically block an existing withdrawal solely because the report is stale. However, stale or delayed valuation information may indirectly affect settlement if strategy assets cannot be reliably valued, recovered, or processed.

Under the standard Vault pause mechanism, new deposits, minting, and allocations may be disabled while withdrawals, deallocations, and claims remain available subject to liquidity and other applicable controls.

Additional emergency measures may affect withdrawal availability if required to protect the Vault or its users.

Users should review the AQUA Market interface for the current withdrawal status and available claim amount.

***

{% hint style="info" %}

### Important Notice

Deposits and withdrawals are subject to:

* Vault liquidity
* Strategy settlement conditions
* Applicable fees
* Share-price calculations
* Eligibility and Gate requirements
* Risk controls
* Network conditions
* Operational and emergency procedures

AQUA Vaults do not guarantee immediate liquidity, principal protection, fixed returns, or settlement within a specific period.

Users should review the relevant Vault information, strategy disclosures, fees, withdrawal terms, and risk factors before depositing.
{% endhint %}


# Fees

| Fee Type        | USDC Vault Rate | OXAU Vault Rate | Description                                               |
| --------------- | --------------- | --------------- | --------------------------------------------------------- |
| Deposit Fee     | 0%              | 0%              | No fee is charged when depositing into a Vault.           |
| Withdrawal Fee  | 0%              | 0%              | No fee is charged by the Vault when withdrawing.          |
| Management Fee  | 0%              | 0%              | No ongoing management fee is charged on deposited assets. |
| Performance Fee | 10%             | 10%             | Applied only to generated yield.                          |
| Network Fee     | Variable        | Variable        | Users are responsible for blockchain transaction costs.   |

***

### Performance Fee

A performance fee is charged only on positive yield generated by the Vault.

The performance fee is not charged on:

* Deposited principal
* Withdrawals
* Assets that remain idle and do not generate yield
* Negative Vault performance

The fee reduces the portion of generated yield retained by Vault shareholders and is reflected in the Vault’s net share-price performance.

Displayed Base APY is shown after deducting the applicable performance fee unless explicitly stated otherwise.

The applicable performance fee rate, calculation method, and accounting treatment are disclosed on the relevant Vault page and in the AQUA Market interface.

{% hint style="info" %}

### Important Notice

Vault fees may be updated in accordance with applicable governance procedures, protocol policies, or changes in market conditions.

Any material fee change will be disclosed through the relevant Vault documentation or AQUA Market interface.

Users should review the current fee schedule before depositing or submitting a withdrawal. Fees displayed in the interface at the time of a transaction should be treated as the applicable transaction-level reference, subject to the final on-chain execution.
{% endhint %}


# NAV & Share Price

This page explains how the value of an AQUA Vault share is determined.

***

### NAV Definition

Net Asset Value (NAV) represents the total value attributable to the vault, denominated in the vault's underlying deposit asset.

Vault NAV may include:

* Undeployed assets held directly by the vault
* The value of positions allocated to on-chain strategies
* The latest recognized value of approved off-chain strategies
* Accrued or reported strategy yield
* Pending receivables or settlement amounts, where applicable<br>

Assets already committed to queued or claimable withdrawals are excluded from the active vault value attributable to remaining shareholders.\
\
Management and performance fees are generally reflected through the issuance of fee shares, which affects the value of existing vault shares rather than directly reducing totalAssets.

***

### Share Price Formula

```
Share Price = totalAssets / totalSupply
```

* **totalAssets**: the vault's recognized NAV
* **totalSupply**: the total number of vault shares outstanding<br>

Actual share conversion calculations may also include virtual share adjustments, rounding rules, and applicable fees.

Deposits and withdrawals use the vault's current accounting exchange rate. The final number of shares minted or burned, and the assets received by the user, may differ depending on configured deposit or withdrawal fees.\
\
As strategies generate positive returns, totalAssets may increase relative to totalSupply, causing the value of each vault share to rise. Strategy losses or negative valuation changes may cause the share price to decline.\
\
For queued withdrawals, vault shares are burned when the withdrawal request is submitted, not when the assets are later claimed. The withdrawal amount and applicable withdrawal fee are determined at the request stage.

***

### Strategy Valuation

On-chain strategies are valued using strategy-specific accounting derived from on-chain state. For example, the vault may read the value of a supplied position in a lending market, including interest recognized by the underlying protocol.\\

\
Off-chain strategies are valued through periodic NAV reporting. An authorized reporter submits the strategy's updated valuation through the reporting framework described in [Transparency & Reporting.](broken://pages/v7J9iY1JA9Wl2QYuOpaO)

The latest valid report is incorporated into vault accounting. Where configured, positive NAV changes may be recognized gradually under the vault's maximum rate mechanism rather than being reflected immediately in full.

***

### NAV Updates and Stale Risk

Off-chain NAV reports are submitted according to a defined reporting schedule. Each report is subject to a validity window.\\

\
If a new valid report is not submitted within that window, the off-chain valuation is considered stale.\
\
While an off-chain valuation is stale:

* New deposits and share minting may be temporarily restricted
* Existing withdrawals are not automatically blocked solely because of the stale report
* Withdrawal settlement remains subject to available vault liquidity
* A withdrawal may enter the queue if immediate liquidity is insufficient\
  \\

Deposit and mint operations resume when a valid report is submitted.\\

\
This mechanism helps prevent users from entering the vault using outdated valuation information at the expense of existing depositors.

***

### APY and Share Price

Vault APY may be calculated from changes in share price over a defined historical period. Because vault-level management and performance fees are reflected in share accounting, the resulting APY represents strategy performance after applicable vault-level fees.\\

\
Incentive or Boost APY distributed through separate reward programs is not included in the vault share price unless explicitly stated.\\

\
Because share price reflects actual recognized performance, short-term APY may fluctuate and differ from longer-term averages. APY is annualized and backward-looking. It should not be interpreted as a forecast or guaranteed return.


# Transparency & Reporting

AQUA Vaults are designed to make portfolio composition, strategy activity, and valuation updates externally verifiable. This page describes the reporting framework used for on-chain and off-chain vault positions.

### Portfolio Reporting

Each vault may make the following information available through the AQUA interface or linked reports:

* Allocation across approved strategies and venues
* Position-level information for supported on-chain strategies
* Reported valuations for approved off-chain strategies
* Available liquidity and assets reserved for withdrawals
* The timestamp of the latest applicable valuation or report

On-chain positions can be derived from blockchain state. Off-chain positions depend on the latest valid report submitted through the vault's reporting framework.

The reporting schedule may differ by vault and strategy. Applicable schedules will be disclosed on the relevant vault page.

### NAV Reporting

Approved off-chain strategies are valued through reports submitted by an authorized reporter.

A report may include:

* **`reportURI`**: a reference link to an off-chain report containing valuation data, portfolio information, methodology, or supporting evidence
* **`reportHash`**: a cryptographic commitment to the report content, recorded on-chain so that users can verify whether a published document matches the version referenced by the contract
* **Reported assets**: the strategy value submitted for vault accounting
* **Reported available liquidity**: the amount the strategy reports as available for recovery or settlement
* **Report timestamp**: the time at which the report was submitted or became effective

The report document may remain off-chain while its reference and content commitment are recorded on-chain.

A reported available-liquidity figure should not be interpreted as the amount immediately available for a user withdrawal. Instant withdrawal capacity depends on liquidity already available to the vault after accounting for assets reserved or committed to other withdrawals.

How recognized strategy values affect vault accounting and share price is described in NAV & Share Price.

### Proof of Reserve

For the OXAU Vault, vault reporting and OXAU Proof of Reserve serve different purposes:

* **OXAU Proof of Reserve** supports verification that OXAU in circulation is backed by the applicable physical gold reserves.
* **Vault reporting** describes how assets held by the OXAU Vault are allocated, valued, and managed.

Proof of Reserve does not by itself verify the performance, liquidity, or valuation of a vault strategy. Vault-level information and asset-level reserve information should therefore be considered together.

### On-chain Activity

Key vault actions may be recorded through contract state and on-chain events, including:

* Deposits and immediate withdrawals
* Queued withdrawal requests, fulfillment, and claims
* Strategy allocations, deallocations, and rebalancing
* NAV or off-chain report updates
* Fee-related updates or accrual events
* Governance and parameter changes
* Pause and emergency-control actions

These records allow users, indexers, and auditors to reconstruct material vault activity. However, off-chain reports and supporting documents may still be required to evaluate off-chain positions fully.

### Update Schedule

| Item                        | Update Method                                                           |
| --------------------------- | ----------------------------------------------------------------------- |
| On-chain strategy valuation | Derived from current on-chain state when queried                        |
| Off-chain NAV report        | Submitted at a vault-specific interval and subject to a validity window |
| Portfolio information       | Updated through on-chain data and/or linked periodic reports            |
| OXAU Proof of Reserve       | Published under the OXAU reserve-reporting schedule                     |

Final vault-specific schedules and validity windows will be published before the relevant vault is made available.

### Stale Report Handling

Each approved off-chain strategy report is subject to a validity window.

If a new valid report is not submitted within that window, the strategy's off-chain valuation is considered stale.

While an off-chain valuation is stale:

* New deposits and share minting may be temporarily restricted
* Existing withdrawals are not automatically blocked solely because the report is stale
* Withdrawal settlement remains subject to available vault liquidity
* A withdrawal may enter the queue if immediate liquidity is insufficient

Deposit and mint operations resume when a valid report is submitted.

The latest report timestamp and stale status may be made visible through on-chain data and the AQUA interface. The pricing rationale behind this mechanism is explained in NAV & Share Price.


# Smart Contracts

This page provides an architecture overview of the AQUA Vault contract system for developers, auditors, integrators, and advanced users.

### Architecture Overview

```
User
 │  deposit / mint / withdraw / redeem / claim
 ▼
Vault
 │  ERC-4626-based accounting and integrated ERC-20 vault shares
 │  allocation / deallocation / withdrawal queue / fees
 ▼
StrategyManager
 ├── On-chain Strategy A (for example, AQUA Market)
 ├── On-chain Strategy B (for example, an external lending market)
 └── OffchainNAVStrategy (reported off-chain positions)

Access and safety modules:
RoleManager · Gates · Timelock · Strategy Registry
```

The Vault is the primary user-facing contract. The StrategyManager stores approved-strategy configuration, allocation caps, strategy status, and aggregate strategy views. Individual strategy contracts implement the asset-specific accounting and capital-flow logic.

### Vault

The Vault is based on the ERC-4626 tokenized-vault model and also acts as the ERC-20 share token.

It:

* Accepts one underlying deposit asset
* Mints and burns vault shares
* Tracks recognized vault assets and share accounting
* Exposes ERC-4626-style conversion and preview functions
* Applies configured deposit, withdrawal, management, and performance fees
* Allocates and deallocates assets through approved strategies
* Supports immediate withdrawals and queued withdrawals
* Tracks pending, reserved, and claimable withdrawal amounts
* Integrates configurable asset and share Gates

AQUA Vaults extend standard ERC-4626 behavior. Actual share conversions may include virtual-share adjustments, rounding rules, fees, strategy accounting, and withdrawal-queue logic.

Because user eligibility may depend on external Gate contracts, certain ERC-4626 maximum functions may intentionally return zero rather than attempting a potentially reverting eligibility check.

For queued withdrawals, shares are burned when the withdrawal request is submitted. The user receives the underlying asset later, after the request has been fulfilled and claimed. See Withdrawals.

### Vault Shares

Vault shares are issued directly by the Vault contract as ERC-20-compatible tokens.

A share represents a proportional claim on the vault's recognized assets. Its value changes with the vault's NAV, fee-share issuance, and the performance of the underlying strategies.

Share transfers may be restricted by the configured receive-share and send-share Gates.

For additional information, see NAV & Share Price.

### StrategyManager

The StrategyManager stores and validates strategy-related configuration for a specific Vault.

Its responsibilities include:

* Maintaining the list of approved strategies
* Recording whether each strategy is active
* Classifying strategies as on-chain or off-chain NAV strategies
* Maintaining target allocation information
* Enforcing absolute and relative allocation caps
* Recording force-deallocation penalties
* Aggregating reported strategy assets
* Aggregating strategy-reported available liquidity
* Detecting stale off-chain exposure that should block new vault entry

The Vault executes allocation and deallocation operations. The StrategyManager validates and records the resulting allocation changes through Vault-only hooks.

Strategy addition, removal, activation, classification, and cap increases are governance-controlled operations. A strategy must report zero assets before it can be removed.

Strategy-reported available liquidity is an aggregate informational value. It should not be interpreted as the amount immediately available for a user withdrawal. Instant withdrawal capacity depends on assets already available to the Vault after amounts committed to other withdrawals are excluded.

### Strategy Contracts

Each approved strategy implements the common strategy interface used by the Vault and StrategyManager.

Depending on the strategy, the interface may expose:

* `allocate`
* `deallocate`
* `totalAssets`
* `availableLiquidity`
* Strategy-specific identifiers or configuration data

On-chain strategies derive their positions and valuations from blockchain state. For example, a lending strategy may report the current value of supplied assets, including interest recognized by the underlying protocol.

Strategies are implemented as separate modules so that accounting and integration logic can be reviewed independently. This modular structure does not eliminate strategy risk. Losses, illiquidity, integration failures, or external-protocol failures may still affect the Vault.

### OffchainNAVStrategy

The OffchainNAVStrategy represents approved positions whose value or settlement depends on off-chain activity.

It maintains accounting for:

* Assets reported as held off-chain
* Reported available off-chain liquidity
* Assets requested for return but not yet received
* On-chain idle assets held by the strategy
* The latest report hash, report URI, and report timestamp

Two strategy-specific roles are used:

* **Off-chain reporter**: submits NAV and liquidity reports
* **Off-chain manager**: manages approved capital deployment and return flows

These permissions are scoped through the shared RoleManager.

An authorized reporter submits:

* Reported assets
* Reported available liquidity
* Pending receivables
* `reportHash`
* `reportURI`

The last reported NAV remains part of strategy accounting even after the report becomes stale. To prevent outdated valuations from pricing new shares, the Vault may block new deposits and minting while stale off-chain exposure remains.

Withdrawals are not automatically blocked solely because an off-chain report is stale. However, settlement remains subject to available liquidity and may enter the withdrawal queue.

Reported available liquidity is not the same as immediate Vault liquidity. Off-chain liquidity may still require recovery, transfer, or settlement before it can support a claim.

The reporting format is described in Transparency & Reporting.

### RoleManager

The RoleManager is a shared, scope-based access-control registry. Roles are namespaced by Vault or module so that one RoleManager deployment can manage multiple Vault systems independently.

The primary Vault roles are:

| Role              | Purpose                                                                    |
| ----------------- | -------------------------------------------------------------------------- |
| `GOVERNANCE_ROLE` | Governance configuration and privileged parameter changes                  |
| `CURATOR_ROLE`    | Risk configuration and timelock scheduling                                 |
| `SENTINEL_ROLE`   | Emergency actions and cancellation of pending timelock operations          |
| `ALLOCATOR_ROLE`  | Strategy allocation, deallocation, rebalancing, and withdrawal fulfillment |

Off-chain strategies also use strategy-specific scoped roles for reporting and off-chain capital management.

Fee-recipient addresses are configuration recipients, not access-control roles.

Role membership changes are recorded through standard `RoleGranted` and `RoleRevoked` events.

### Gates

The Vault can use four independent Gate contracts:

| Gate                | Check                                                       |
| ------------------- | ----------------------------------------------------------- |
| Receive Shares Gate | Whether an address may receive vault shares                 |
| Send Shares Gate    | Whether an address may send or redeem vault shares          |
| Receive Assets Gate | Whether an address may receive the underlying asset         |
| Send Assets Gate    | Whether an address may deposit or send the underlying asset |

Gate implementations can support controls such as allowlists, wallet eligibility, compliance restrictions, or share-transfer restrictions.

Gates do not define the Vault's emergency pause behavior. Pause controls are handled separately by the Vault.

### Timelock

The Timelock is a delay-based execution wrapper for selected privileged calls.

A typical flow is:

```
Curator schedules a call
→ configured delay passes
→ anyone executes the exact scheduled call
```

A Curator or Sentinel can revoke a pending operation before execution.

Timelock duration is configured by target contract and function selector. Whether a specific governance action is delayed therefore depends on the production configuration. The existence of the Timelock should not be interpreted as meaning that every privileged function automatically has a non-zero delay.

Increasing a timelock can be performed immediately. Reducing an existing timelock must itself wait through the current delay, helping prevent a privileged key from weakening protection instantly.

Emergency actions available directly to the Sentinel are separate from scheduled governance operations.

### Pause and Emergency Controls

The Vault can be paused by an authorized Sentinel and unpaused by Governance.

While paused:

* New deposits and minting are disabled
* New allocations are disabled
* Deallocation remains available
* Withdrawals and claims remain available, subject to liquidity

Additional emergency and risk controls may include:

* Strategy deactivation
* Absolute and relative allocation-cap reductions
* Forced deallocation with a configured penalty
* Timelock-operation revocation
* Stale off-chain entry blocking
* Maximum-rate controls for positive NAV recognition

### Withdrawal Queue Accounting

The withdrawal queue is maintained per user rather than through a separate request ID for each transaction.

Multiple queued withdrawals for the same user may accumulate into one pending position.

The lifecycle is:

```
Withdrawal requested
→ shares burned
→ pending withdrawal recorded
→ allocator fulfills all or part of the request
→ assets become reserved and claimable
→ user claims the ready amount
```

The Vault separately tracks:

* Pending withdrawals
* Assets reserved for fulfilled withdrawals
* Claimable withdrawal assets
* Assets committed to pending or claimable withdrawals

The withdrawal fee applicable to a queued amount is recorded at the request stage. Later fee changes do not retroactively change the fee for that queued amount.

### Events

Material Vault activity is recorded through contract events.

#### User and withdrawal events

* `Deposit`
* `Withdraw`
* `WithdrawalRequested`
* `WithdrawalFulfilled`
* `WithdrawalClaimed`

#### Strategy events

* `Allocate`
* `Deallocate`
* `ForceDeallocate`
* `Rebalance`
* `AfterAllocate`
* `AfterDeallocate`

#### Accounting and reporting events

* `AccrueInterest`
* `NAVReported`
* `CapitalDeployed`
* `ReturnRequested`
* `CapitalReturned`
* `ForceSyncReportedNAV`

#### Governance and configuration events

* `GovernanceSubmit`
* `GovernanceAccept`
* `GovernanceRevoke`
* `Paused`
* `Unpaused`
* Strategy, Gate, fee, cap, role, and timelock configuration events

The final deployed addresses and verified contract interfaces should be used as the authoritative reference for event signatures.

### Security Design

The system includes several accounting and operational safeguards, including:

* Virtual-share accounting to reduce ERC-4626 inflation-attack risk
* Scoped role separation
* Configurable governance delays
* Separate emergency controls
* Absolute and relative strategy caps
* Strategy-registry validation, where configured
* Stale-report entry blocking
* Maximum-rate controls for positive NAV recognition
* Share burning at queued-withdrawal request time
* Reservation of fulfilled withdrawal assets before claim
* Request-time withdrawal-fee recording
* Checks-effects-interactions and reentrancy protections where applicable

These controls reduce specific risks but do not eliminate smart-contract, strategy, liquidity, custody, oracle, or operational risk.

### Contract Addresses

Contract deployments may be specific to each Vault.

| Contract                        | Network  | Address |
| ------------------------------- | -------- | ------- |
| USDC Vault                      | Arbitrum | TBD     |
| USDC StrategyManager            | Arbitrum | TBD     |
| OXAU Vault                      | Arbitrum | TBD     |
| OXAU StrategyManager            | Arbitrum | TBD     |
| OXAU OffchainNAVStrategy        | Arbitrum | TBD     |
| RoleManager                     | Arbitrum | TBD     |
| Timelock                        | Arbitrum | TBD     |
| StrategyRegistry, if configured | Arbitrum | TBD     |
| Gate contracts, if configured   | Arbitrum | TBD     |

Final addresses, source-code verification links, deployment configuration, and audit reports will be published before or at launch.


# Risk Controls

The Financial Layer is designed with a focus on disciplined risk management.

When real-world assets enter programmable financial systems, their underlying trust must be matched by clearly defined market controls. This includes the configuration of collateral parameters, borrowing conditions, liquidation thresholds, and overall market structure appropriate for real-asset-backed environments.

AQUA operates with protocol-level controls that reflect the distinct characteristics of real-world asset collateral. These controls are essential not only for maintaining market stability, but also for ensuring consistent behavior across the Ontorium stack.

In a full-stack architecture, weaknesses in the Financial Layer can directly impact the usability of the Asset Layer and the reliability of the Application Layer. As a result, risk management is treated as a system-wide function rather than an isolated market mechanism.

***

#### Protocol-Level Risk Controls

AQUA incorporates a set of automated risk controls designed to manage market conditions and protect users under adverse scenarios. These mechanisms apply across supported assets and may adjust dynamically based on market conditions.

***

#### Liquidation

Positions that exceed defined collateral thresholds become eligible for liquidation. Liquidators may repay a portion of the outstanding debt in exchange for collateral at a predefined discount. This mechanism helps ensure that undercollateralized positions are resolved before they become insolvent.

***

#### Oracle Deviation

Asset prices are sourced from external price oracles. If price deviations exceed predefined thresholds, the protocol may restrict borrowing activity or pause affected markets to prevent mispricing and potential exploitation.

***

#### Supply and Borrow Caps

Each asset is subject to supply and borrow caps that limit total exposure within the system. These limits help manage concentration risk and reduce the likelihood of systemic imbalances.

***

#### Circuit Breaker

Under extreme market conditions or abnormal system behavior, a circuit breaker may be triggered to temporarily halt selected protocol functions. This mechanism is designed to prevent cascading failures and allow time for system stabilization.

***

#### Market Freeze

Individual markets may be frozen in response to identified risks, smart contract vulnerabilities, or regulatory considerations. During a freeze, new supply and borrow activity is disabled while existing positions remain active.


# Application Layer

The Application Layer is responsible for turning financial infrastructure into usable financial experience.

Where the Asset Layer creates the base asset and the Financial Layer unlocks liquidity and financial functionality, the Application Layer makes the system accessible to end users. It is the point at which on-chain finance becomes practical, navigable, and relevant in everyday financial contexts.

This layer matters because a financial stack is incomplete if it remains accessible only to technically sophisticated users or specialized market participants. Real-asset finance reaches broader utility only when it can be used through simple, familiar, and application-driven interfaces.

Within Ontorium, the current flagship implementation of the Application Layer is **AQUA App**, a stablecoin-powered financial application for payments, transfers, and yield.


# AQUA App Overview

AQUA App is the flagship implementation of the Application Layer. It is designed as a stablecoin-powered financial application that provides user-facing access to payments, transfers, and yield.

The purpose of AQUA App is not merely to expose protocol functionality in interface form. Its purpose is to provide a practical financial experience that connects users to the broader Ontorium Stack.

In this structure, AQUA App sits downstream of the Asset and Financial Layers. It does not replace them. Rather, it serves as the interface through which users can access the value created by those layers.

As Ontorium expands, the Application Layer may include additional interfaces, services, or distribution channels. AQUA App is the current flagship implementation, but the layer is intentionally broader than any single application.


# Payments and Transfers

A core objective of the Application Layer is to support real-world financial activity.

Payments and transfers represent one of the most important bridges between on-chain systems and everyday user behavior. A financial stack designed for real assets must eventually support not only asset holding and market activity, but also usable flows of value between users, applications, and external contexts.

AQUA App is therefore designed to provide application-level rails for movement of value in ways that are simple, accessible, and aligned with stablecoin-based user experience. This brings the stack closer to practical usage and expands its relevance beyond protocol-native users.


# Yield Access

Another key function of the Application Layer is to make yield generated across the **Ontorium Stack** accessible and usable for end users.

Yield within the system originates from financial activity in the Financial Layer, particularly through lending markets on **AQUA and curated vault strategies** built on top of assets such as OXAU.\
These returns are driven by real borrowing demand against gold-backed collateral, as well as liquidity provision and structured capital allocation.

The Application Layer packages these yield sources into unified products, allowing users to access multiple strategies through a single interface without directly interacting with underlying protocols.

Beyond access, the Application Layer also enables utilization.\
Yield is not only accumulated but can be actively used, whether held, redeployed, or integrated into payment and financial flows.

By connecting real-world asset-backed financial activity to user actions, the Application Layer transforms yield from a passive outcome into an active and usable component of the user experience.


# Financial Access and Distribution

The Application Layer serves as the primary access and distribution layer of the **Ontorium Stack**, transforming underlying financial infrastructure into user-facing financial products.

While the Asset Layer and Financial Layer establish the foundation for asset issuance and on-chain financial activity, their impact depends on how effectively these capabilities are delivered to end users. The Application Layer bridges this gap by converting assets such as OXAU and financial primitives from AQUA into accessible forms of financial interaction.

Through this layer, users do not engage directly with individual protocols or strategies. Instead, they access unified products that represent underlying activities such as lending markets, collateralized borrowing, and curated vault allocations.

Financial access is defined not only by the availability of assets, but by the ability to interact with them in practical ways.&#x20;

This includes:

* **accessing yield generated from lending markets and vault strategies**
* **utilizing OXAU as collateral to establish credit lines**
* **interacting with balances that reflect ongoing financial activity**

These balances are not only held or redeployed within the system. They can also extend into spending and payment contexts, allowing financial activity to translate into real-world usage.

In this model, yield and credit are not isolated outcomes. They are directly connected to spending and payment, enabling a continuous flow from asset holding to real-world financial interaction.

In parallel, distribution is achieved by embedding these capabilities into application-level interfaces. This allows financial functions to reach a broader range of users without requiring technical expertise or direct protocol interaction.

As a result, the Application Layer does not simply present information. It operationalizes the stack.\
It is where financial infrastructure becomes accessible, actionable, and continuously utilized by end users.


# Custody & Legal Structure

OXAU tokens are issued by Ontorium Ltd., a company incorporated in the British Virgin Islands. Token issuance is conducted on the Arbitrum network.

The physical gold underlying each OXAU token is held in custody by Uni Precious, operating under UTGL, in secure vaulting facilities located in Hong Kong.

The custody arrangement is designed to ensure that physical assets are held independently from Ontorium's operational activities, maintaining a clear separation between the on-chain token and its underlying reserve.


# Trust at the Asset Layer

OXAU represents physical gold with verifiable backing.

Gold backing follows internationally recognized standards, including LBMA Good Delivery specifications, ensuring consistency in quality, purity, and global acceptability.

Reserve verification is conducted through monthly Proof of Reserves reports, providing regular visibility into asset backing and system integrity. The total supply of OXAU is publicly verifiable on-chain at any time, allowing users to independently cross-reference circulating supply against published reserve data.

Ontorium intends to engage independent third-party auditors to further verify reserve integrity. Details on the audit framework and appointed auditor will be published as the program is established.

This layered approach to verification ensures that OXAU maintains a clear, enforceable link to its underlying physical gold, establishing trust at the foundation of the Asset Layer.


# Transparency as System Design

Transparency within Ontorium is not treated as a communications layer. It is part of the system architecture.

A real-asset stack cannot rely on abstraction alone. Its trust assumptions must be externally legible through reporting, verification, and operational clarity. This principle applies across the stack:

* at the **Asset Layer** through reserve transparency, backing clarity, and redemption visibility,
* at the **Financial Layer** through market design, parameter discipline, and risk controls,
* and at the **Application Layer** through clear user-facing information, understandable flows, and practical financial usability.

Transparency is therefore not merely supportive of trust. It is one of the mechanisms through which trust is produced.


# Risk Management at the Financial Layer

The Financial Layer introduces market activity and therefore requires explicit risk controls.

When trusted real assets become collateral within programmable financial systems, the design of collateral parameters, borrowing conditions, market configuration, liquidity controls, and liquidation logic becomes central to preserving system stability.

Within Ontorium, financial risk management is intended to reflect the characteristics of real-asset collateral rather than assuming only crypto-native behavior. This includes recognizing differences in reserve basis, collateral profile, market structure, and user expectations.

Administrative authority over smart contracts is intended to be governed through multisignature controls rather than unilateral control. This governance approach is designed to reduce single-party operational dependence and strengthen discipline over critical protocol-level actions.

A disciplined Financial Layer is necessary not only for the operation of AQUA, but also for preserving confidence in the stack as a whole. Weakness in financial controls can undermine both the credibility of the Asset Layer and the usability of future Application Layer products.


# User Facing Trust at the Application Layer

Trust must ultimately be experienced by end users.

Even where underlying asset structures and financial controls are robust, users still require interfaces and access layers that make the system understandable and usable in practice. Clear presentation of product logic, transparent communication of user actions, and accessible financial flows are essential to making the stack practical.

For this reason, trust at the Application Layer is partly a matter of user experience. It depends on whether future user-facing products can present the underlying infrastructure in ways that users can navigate with confidence.

This means that user-facing trust is not separate from system trust. It is the form in which system trust becomes visible and actionable to end users.


# A Financial Stack for Real Assets

Ontorium is built on the recognition that real-world assets, while increasingly being tokenized, remain structurally underutilized within on-chain financial systems.

While real-world assets are increasingly being tokenized, most meaningful adoption today is concentrated in U.S. Treasury-backed products. Outside of this category, many tokenized assets remain limited to issuance, without being effectively integrated into on-chain financial systems. As a result, they fail to generate sustained liquidity, utility, or long-term usage.

Ontorium addresses this limitation by designing a full-stack architecture that supports the complete lifecycle of real assets on-chain.

Starting with **OXAU, a verifiably backed gold asset**, Ontorium introduces real-world assets as on-chain primitives with enforceable links to their underlying value. These assets are not intended to remain static. They are designed to move across a unified system where they can be issued, utilized, and accessed within a continuous financial flow.

At the **financial layer**, assets such as OXAU are integrated into markets like AQUA, where they can function as collateral, support liquidity formation, and enable capital-efficient borrowing and lending.

At the **application layer**, this financial utility extends into real-world usage, allowing asset-backed value to be directly accessed through payments, transfers, and yield-generating strategies.

Rather than treating issuance, financial activity, and user access as separate domains, Ontorium unifies them within a single stack. Each layer is designed to reinforce the others, forming a system in which real assets can move seamlessly from representation to financial utility to actual usage.

Through this approach, Ontorium aims to establish a new model for real-asset finance one that is grounded in verifiable backing, structured for capital efficiency, and designed for practical, real-world access.


# Roadmap

Ontorium is designed to expand in phases across its three layers.

This phased approach reflects the logic of the stack itself. The base asset foundation must be established first, financial utility must then be built on top of it, and user-facing applications must ultimately convert that infrastructure into practical access and distribution.

### Phase 1: Asset Layer Foundation

The first phase focuses on establishing the Asset Layer through **OXAU.**

This phase is centered on bringing physical gold on-chain in a form that is trusted, redeemable, and financially usable. The primary objective is to create a credible base asset that can support the rest of the stack.

This includes:

* establishing the structure of the on-chain gold asset,
* defining reserve integrity and backing logic,
* creating the operational basis for issuance and redemption.

While OXAU serves as the initial asset,\
the Asset Layer is designed to support the onboarding of additional real-world assets over time.

This includes assets such as commodities, structured products, and other verifiable off-chain assets,\
which can be introduced under the same framework of custody, verification, and redeemability.

By starting with gold as a universally recognized store of value,\
Ontorium establishes a strong foundation for broader RWA expansion.

### Phase 2: Financial Layer Expansion

The second phase focuses on activating the asset within financial markets through AQUA.

Once the base asset is established, the next objective is to enable financial utility through lending, borrowing, collateralization, and liquidity access. This phase is intended to transform static asset exposure into productive financial participation.

The Financial Layer is critical because it creates the capital efficiency that allows the stack to function as more than a tokenization framework.

### Phase 3: Application Layer Access

The third phase focuses on expanding user access and distribution through AQUA App.

At this stage, the objective is to make the underlying stack more usable through user-facing applications for payments, transfers, and yield-oriented financial activity. This phase is where infrastructure becomes productized into practical financial experience.

The Application Layer plays a decisive role in adoption because it reduces the friction between protocol design and real-world use. is designed to expand in phases across its three layers.

This phased approach reflects the logic of the stack itself. The base asset foundation must be established first, financial utility must then be built on top of it, and user-facing applications must ultimately convert that infrastructure into practical access and distribution.


# FAQ

<details open>

<summary><strong>Q. What is OXAU?</strong></summary>

A. OXAU is an on-chain gold token issued through Ontorium's Asset Layer. Each OXAU token is backed 1:1 by 1 gram of physical gold meeting LBMA Good Delivery standards.

</details>

<details open>

<summary><strong>Q. How do I mint OXAU?</strong></summary>

A. OXAU can be minted directly on the Ontorium platform using USDC or USDT. The minimum minting size is 1,000 OXAU (equivalent to 1 kilogram of gold). Minting requires completion of KYC L1 verification and is available during operating hours: UTC 01:00–10:00.

</details>

<details open>

<summary><strong>Q. What is the difference between minting and buying on a secondary market?</strong></summary>

A. Minting involves the direct issuance of new OXAU tokens backed by physical gold. When you mint, the corresponding physical gold is allocated and held in custody on your behalf. Purchasing OXAU on a secondary market means acquiring existing tokens through available market liquidity, without new tokens being issued or additional gold being allocated.

</details>

<details open>

<summary><strong>Q. How is OXAU different from existing tokenized gold products?</strong></summary>

A. Most tokenized gold products focus primarily on custody and trading. OXAU is designed to go beyond passive holding. It can be actively utilized within on-chain financial systems, including as collateral in AQUA lending markets and for liquidity provision, making it a programmable financial primitive rather than a static store of value.

</details>

<details open>

<summary><strong>Q. Are there any fees?</strong></summary>

A. For a full breakdown of applicable fees, please refer to the [Mint\&Redemption](/ontorium-stack-overview/asset-layer/mint-and-redemption) Parameters section.

</details>

<details open>

<summary><strong>Q.</strong> <strong>Is physical gold redemption available?</strong></summary>

A. For inquiries regarding physical gold redemption, please contact <contact@ontorium.io>.

</details>

<details open>

<summary><strong>Q. How is OXAU backed?</strong></summary>

A. Each OXAU token is backed 1:1 by 1 gram of physical gold meeting LBMA Good Delivery standards. The physical gold is held by an independent third-party custodian in secure vaulting facilities in Hong Kong.

</details>

<details open>

<summary><strong>Q. How is reserve integrity verified?</strong></summary>

A. Ontorium publishes monthly Proof of Reserves reports confirming that the circulating supply of OXAU is fully backed by physical gold on a 1:1 gram basis. The total supply of OXAU is also publicly verifiable on-chain at any time, allowing users to independently cross-reference circulating supply against published reserve data.

</details>

<details open>

<summary><strong>Q. Can I use OXAU as collateral in AQUA Market?</strong></summary>

A. Yes. OXAU is supported as collateral within AQUA. Users can borrow OXAU, USDC, or USDT against their OXAU collateral. Applicable collateral parameters are available on the AQUA Market.

</details>

<details open>

<summary><strong>Q. How does liquidation work in AQUA Market?</strong></summary>

A. If the value of your collateral falls below the required threshold, your position becomes eligible for automatic liquidation. Liquidation may occur without prior notice, and you are solely responsible for monitoring and managing your collateral ratio at all times.

</details>

<details open>

<summary><strong>Q. Why is KYC required?</strong></summary>

A. KYC verification is required to access core platform features including minting and redemption. This is a mandatory requirement for regulatory compliance and platform security.

</details>

<details open>

<summary><strong>Q. What wallets are supported?</strong></summary>

A. Ontorium supports all EVM-compatible wallets

</details>

<details open>

<summary><strong>Q. Are there any restricted jurisdictions?</strong></summary>

A. Yes. Access to the Platform is restricted in certain jurisdictions. For a full list of restricted countries and compliance requirements, please refer to the [KYC Framework](/ontorium-stack-overview/asset-layer/kyc-framework) section.

</details>

<details open>

<summary><strong>Q. How can I contact Ontorium?</strong></summary>

A. For any questions or inquiries, please contact us at <contact@ontorium.io> or join our [Telegram community](https://t.me/Ontorium_Globalchat).

</details>


# Official Links

{% hint style="info" %}
**Only use the official links listed below.**&#x20;

We are not responsible for any loss resulting from interactions with unofficial or fraudulent sources.
{% endhint %}

| Platform         | Link                                         |
| ---------------- | -------------------------------------------- |
| Website          | [​https://Ontorium.io](https://ontorium.io/) |
| Twitter(X)       | ​<https://x.com/Ontorium_io>​                |
| Telegram Channel | ​<https://t.me/Ontorium_io>​                 |
| Telegram Group   | ​<https://t.me/Ontorium_Globalchat>​         |


# Privacy Policy

Last Updated: April 21, 2026

### Introduction

Ontorium (“**we**”, “**our**”, or “**us**”) is committed to protecting user privacy while ensuring compliance with applicable laws and regulations. This Privacy Policy explains how we collect, use, and safeguard information in connection with our platform and services.

By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy and agree to its terms. If you do not agree with our Privacy Policy, do not access or use the Services.

For any questions regarding this Privacy Policy, please contact us at: **<contact@ontorium.io>**

***

### Information We Collect

We collect information necessary to provide our Services, comply with legal obligations, and ensure platform integrity.

**Individual Users**

* Full legal name
* Date of birth
* Nationality and country of residence
* Government-issued identification (e.g., passport, ID card)
* Phone number (for verification and security purposes)
* Proof of address (for L2 Verification)
* Contact information (e.g., email address)
* Source of funds (for compliance and risk assessment, where required)

**Institutional Users**

For institutional users, we may collect additional information as part of Know Your Business (KYB) procedures, including but not limited to:

* Company information, such as legal entity name, registration number, date of incorporation, legal structure, and registered or operating address
* Information relating to directors, representatives, and authorized persons
* Ownership and control structure, including shareholders, members, and their respective ownership interests
* Information relating to ultimate beneficial owners (UBOs), including identity, nationality, and level of ownership or control, which may be subject to separate identity verification procedures
* Information required for compliance screening, including sanctions, politically exposed persons (PEP), and adverse media checks

#### Wallet and On-Chain Data

* Wallet address (used to link verified identity with on-chain activity, where applicable)
* Transaction history (public blockchain data)
* Smart contract interactions

Blockchain data is publicly available and not controlled by Ontorium. Due to the immutable nature of blockchain technology, certain on-chain data cannot be altered or deleted. This is inherent to the technology and not within Ontorium's control.

#### Automatically Collected Information

* IP address
* Device information
* Browser type
* Access logs
* Usage data (interaction with the platform)

#### Information from Third Parties

We may receive information from third-party service providers, including but not limited to:

* Identity verification providers (e.g., Sumsub)
* Compliance and sanctions screening providers
* Custody and settlement partners (e.g., vault operators, gold custodians, logistics partners)

***

### How We Use Your Information

We use your information for the following purposes:

* To provide, operate, and maintain the Services, including managing user accounts and enabling access to platform functionalities
* To verify identity and comply with KYC/AML (Know Your Customer and Anti-Money Laundering) requirements, including transaction monitoring and risk assessment
* To link verified identities with wallet addresses and enable interaction with on-chain services
* To process minting and redemption of assets (e.g., OXAU), including physical redemption where applicable
* To ensure security, prevent fraud, detect abuse, and protect the integrity of the platform
* To comply with legal and regulatory obligations, including responding to lawful requests and supporting internal and external audits
* To improve platform performance, functionality, and user experience

#### Sharing and Disclosure of Information

We may share your information with third parties, including but not limited to:

* **Service Providers**\
  Third-party service providers that support the operation of our Services, including identity verification providers (e.g., Sumsub), blockchain analytics providers, cloud infrastructure providers, and other technical service providers
* **Compliance and KYC/AML Providers**\
  Providers that assist with identity verification, sanctions screening, transaction monitoring, and compliance obligations
* **Custody and Asset-Related Partners**\
  Custody providers, vault operators, and infrastructure partners involved in the issuance, storage, management, and settlement of real-world assets
* **Physical Redemption and Logistics Partners**\
  Authorized partners responsible for handling physical redemption, delivery, or pickup of assets, where applicable
* **Regulatory Authorities**\
  Regulatory bodies, law enforcement agencies, or other authorities where disclosure is required by applicable laws or regulations

We do not sell or share users’ personal information with third parties for marketing or promotional purposes.

***

### Data Storage and Security

We implement appropriate technical and organizational measures to protect your information from unauthorized access, loss, misuse, or alteration. This includes the use of industry standard encryption for data in transit and at rest, access controls that restrict data access to authorized personnel on a need-to-know basis, and secure infrastructure designed to maintain system integrity and availability. We also monitor our systems for potential vulnerabilities, unauthorized access, and other security risks, and work with trusted third-party providers to ensure the secure handling of identity verification, custody, and asset-related processes. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security of your information.

### Data Retention

We retain personal information for as long as necessary to provide our Services, comply with legal and regulatory obligations, and support legitimate business purposes. This includes retaining information required for KYC/AML compliance, transaction monitoring, and record-keeping obligations. In accordance with applicable regulatory requirements, KYC/AML-related records are generally retained for a minimum of five (5) years following the end of a business relationship or the completion of a transaction.Retention periods may vary depending on the nature of the data and applicable legal requirements. When personal information is no longer required, we take reasonable steps to securely delete or anonymize such information.

***

### Age Restrictions

Our Services are not intended for individuals under the age of 18, and we do not knowingly collect or solicit personal information from minors. If you are under 18, you should not access or use the Services. If we become aware that we have collected personal information from a minor without proper authorization, we will take appropriate steps to delete such information and restrict access to the Services.

***

### User Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information, including the right to access, correct, or request deletion of your data, restrict or object to certain processing activities, and withdraw consent where applicable. You may also have the right to request a copy of your personal data. We will respond to such requests in accordance with applicable laws and may require identity verification before processing your request.

***

### Cross-Border Data Transfers

Your personal information may be transferred to, stored, and processed in jurisdictions outside your country of residence, including locations where our service providers and partners operate. These jurisdictions may have data protection laws that differ from those in your country. We take appropriate measures to ensure that such transfers are conducted in accordance with applicable legal requirements and that your personal information remains protected.

***

### Cookies and Tracking Technologies

We may use cookies and similar tracking technologies to enhance user experience, analyze platform usage, and improve the performance of our Services. Users may control or disable cookies through their browser settings; however, doing so may affect certain functionalities of the Services.

***

### Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any updates will be posted on this page with a revised effective date. Continued use of the Services after such changes constitutes acceptance of the updated Privacy Policy.

***

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: **<contact@ontorium.io>**


# Terms of Use

Last Updated: April 21, 2026

### 1. Acceptance of the Terms of Use

These Terms govern your access to and use of the Ontorium platform, including all associated websites, applications, smart contracts, APIs, and services (collectively, the "**Platform**"). These Terms constitute a legally binding agreement between you ("**User**," "**you**," or "**your**") and Ontorium and its affiliates ("**Ontorium**," "**we**," "**us**," or "**our**").

By accessing or using the Platform, including by interacting with any smart contracts, clicking ‘I Agree’ (or any similar button or checkbox), or using any feature or functionality of the Platform, you acknowledge that you have read, understood, and agree to be bound by these Terms. If you do not agree to these Terms, you may not access or use the Platform.

These Terms should be read together with the following additional terms, policies, and notices that may apply to specific features, services, or transactions on the Platform, including but not limited to:

* **Privacy Policy**: governing the collection, processing, and use of your personal data;
* **Know Your Customer (KYC) and Know Your Business (KYB) Requirements**: applicable to individual users and institutional clients respectively; and
* **Product-Specific Terms**: additional terms that apply to particular products or services offered through the Platform.

All such policies, disclosures, and additional terms are incorporated into these Terms by reference. In the event of any inconsistency between these Terms and any product-specific or service-specific terms, the product-specific or service-specific terms shall prevail with respect to that particular product or service.

If you do not agree to these Terms or any applicable additional terms, you must discontinue your use of the Platform. Continued use of the Platform following any amendment to these Terms constitutes your acceptance of the revised Terms.

### 2. Eligibility

By accessing or using the Platform, you represent and warrant that:

2.1 You are at least 18 years of age, or the age of majority in your jurisdiction, whichever is greater;

2.2 You have full legal capacity, power, and authority to enter into and be bound by these Terms, whether acting on your own behalf or as an authorized representative of a legal entity;

2.3 Your access to and use of the Platform is fully compliant with all applicable laws, regulations, and rules in your jurisdiction, including but not limited to financial services law, securities law, commodities law, anti-money laundering ("AML") law, counter-terrorism financing ("CTF") regulations, and applicable tax obligations;

2.4 You are not a person or entity that is prohibited from using the Platform under these Terms, applicable law, or any applicable sanctions regime;

2.5 You are not, and are not acting on behalf of, any person or entity that is (i) designated on any sanctions list maintained by the United Nations, the European Union, the United States (including OFAC), the United Kingdom, or any other applicable governmental authority; (ii) organized or resident in a Restricted Jurisdiction (as defined below); or (iii) owned or controlled by any such person or entity; and

2.6 You do not, and will not, use VPN software or any other privacy or anonymization tools or techniques to circumvent, or attempt to circumvent, any restrictions that apply to the Services.

Ontorium reserves the right to restrict access to the Platform in any jurisdiction at its sole discretion, without prior notice, and without liability to any User.

### 3. Platform Overview and Services

Ontorium is a financial infrastructure platform that enables the issuance, management, and utilization of digital assets backed by real-world assets through an integrated on-chain architecture.

The Platform is structured across multiple layers, including:

(a) Asset Layer, through which real-world assets such as gold-backed tokens (e.g., OXAU) may be issued, minted, redeemed, or otherwise managed;

(b) Financial Layer, through which digital assets may be supplied, borrowed, or utilized as collateral within on-chain liquidity and lending markets (e.g., AQUA); and

(c) Application Layer, which may provide user-facing applications, integrations, or services that enable practical use of digital assets.

The Platform may include functionalities such as minting, redemption, transfers, staking, interaction with smart contracts, and integration with third-party protocols or services. Availability of any feature may vary and is subject to applicable eligibility requirements, including KYC or KYB verification, and jurisdictional restrictions.

Certain features or services may be subject to additional terms, conditions, and risk disclosures. Ontorium reserves the right to introduce, modify, suspend, or discontinue any part of the Platform at any time, without prior notice and without liability.

Access to the Platform may require account registration, identity verification, and connection of a compatible self-custodial wallet. You are solely responsible for maintaining control over your account credentials and wallet.

Ontorium does not guarantee uninterrupted, secure, or error-free operation of the Platform. The Platform may be subject to downtime, delays, or failures due to factors beyond our control, including blockchain network conditions, smart contract risks, third-party dependencies, or regulatory changes.

### 4. User Accounts

To access certain features of the Platform, you may be required to create an account and connect a compatible self-custodial wallet.

You agree to:&#x20;

* Provide accurate, current, and complete information during the registration process
* Maintain and promptly update your account information to keep it accurate and complete
* Maintain the confidentiality and security of your account credentials, private keys, and wallet access
* Notify Ontorium immediately of any unauthorized access to or use of your account
* Accept full responsibility for all activities conducted through your account or wallet

You acknowledge that Ontorium does not store, manage, or have access to your private keys, and does not have custody of your digital assets.

All transactions conducted through the Platform are executed on public blockchain networks and are irreversible. Ontorium has no ability to reverse, cancel, or recover any transaction or lost digital assets.

Ontorium reserves the right to suspend or terminate any account or access to the Platform that violates these Terms, applicable laws, or Ontorium's policies, with or without notice.

### 5. RWA Tokens and Risk Disclosures

5.1 Tokenized real-world assets (“RWA Tokens”) made available through the Platform represent on-chain claims backed by or referenced to underlying real-world assets. The specific rights, obligations, and structure of each RWA Token are defined by the applicable product terms, offering materials, and legal agreements governing that token.

5.2 Nothing on the Platform constitutes investment, financial, legal, or tax advice. You acknowledge that acquiring, holding, or using RWA Tokens involves significant risks, including but not limited to market risk, liquidity risk, smart contract risk, custody risk, and regulatory risk, including the risk of total loss.

5.3 Underlying assets associated with certain RWA Tokens may be held by third-party custodians. While Ontorium may engage established custodial partners to support asset backing and verification, Ontorium does not guarantee the value, liquidity, marketability, or legal status of any underlying asset, nor the performance, solvency, or continued operation of any third-party custodian.

You acknowledge that the use of third-party custodians introduces additional risks, including but not limited to custodian failure, operational errors, and force majeure events.

5.4 RWA Tokens may be subject to regulation in certain jurisdictions, including classification as securities, commodities, or other financial instruments. You are solely responsible for ensuring that your access to and use of any RWA Token complies with applicable laws and regulations in your jurisdiction. Ontorium reserves the right to restrict or deny access to any RWA Token or related functionality at its sole discretion.

### 6. Decentralized Finance and On-Chain Financial Services

The Platform may provide access to decentralized lending protocols, liquidity pools, collateral markets, and other on-chain financial services (collectively, “DeFi Services”).

You acknowledge and agree that your use of DeFi Services involves significant risks, including but not limited to the following:

(a) Smart Contract Risk: DeFi Services are governed by smart contracts deployed on public blockchains, which may contain bugs, vulnerabilities, or errors that could result in loss of funds. Ontorium does not guarantee the security, functionality, or accuracy of any smart contract;

(b) Liquidation Risk: Collateralized positions may be subject to automatic liquidation if collateral values fall below required thresholds. You are solely responsible for monitoring your positions, and Ontorium shall not be liable for any losses arising from liquidation events;

(c) Slippage and Market Risk: Prices and liquidity conditions in on-chain markets are volatile and may change rapidly. Ontorium does not guarantee execution prices, liquidity availability, or market stability; and

(d) Non-Custodial Nature: Ontorium does not take custody of your digital assets in connection with DeFi Services. You retain sole control over your private keys and wallets, and Ontorium is not responsible for any loss of access, keys, or funds.

### 7. Prohibited Conduct

You agree not to, and shall not, directly or indirectly use the Platform to:

(a) Violate any applicable law, regulation, or regulatory requirement;

(b) Engage in money laundering, terrorist financing, fraud, market manipulation, or any other unlawful financial activity;

(c) Circumvent or attempt to circumvent any geographic restrictions, sanctions programs, compliance requirements, or access controls implemented by Ontorium;

(d) Introduce any malware, exploit, virus, or other malicious code into the Platform, including its underlying smart contracts;

(e) Engage in wash trading, front-running, or any other form of abusive or manipulative trading activity;

(f) Impersonate any person or entity, or misrepresent your identity, affiliation, or authorization;

(g) Use any automated means, including bots, scripts, or scraping tools, to access or use the Platform in a manner that may disrupt, degrade, or interfere with the normal operation of the Platform; or

(h) Reproduce, distribute, modify, or create derivative works from any content, data, or materials available on the Platform without prior written consent from Ontorium.

Ontorium reserves the right to investigate any suspected violation of this Section and may, at its sole discretion, take any action it deems appropriate, including restricting, suspending, or terminating your access to the Platform, reporting such activity to regulatory or law enforcement authorities, and pursuing any available legal remedies.

### 8. Intellectual Property

All content, features, technology, trademarks, and materials available on or through the Platform, including but not limited to software, designs, text, data, graphics, and smart contract code developed by Ontorium, are the exclusive property of Ontorium or its licensors and are protected by applicable intellectual property laws.

Subject to your compliance with these Terms, Ontorium grants you a limited, non-exclusive, non-transferable, revocable license to access and use the Platform solely for your personal or internal business purposes.

Except as expressly permitted under these Terms, you shall not, and shall not permit any third party to, copy, modify, distribute, reproduce, republish, reverse engineer, decompile, disassemble, or create derivative works from any part of the Platform or its underlying technology.

All rights not expressly granted herein are reserved by Ontorium.

### 9. Privacy and Data

Your use of the Platform is subject to [Ontorium’s Privacy Policy](/disclaimer/privacy-policy), which is incorporated herein by reference. By accessing or using the Platform, you consent to the collection, processing, and use of your personal data as described in the Privacy Policy.

You acknowledge that transactions and data recorded on public blockchain networks are immutable, publicly accessible, and not controlled by Ontorium. Ontorium is not responsible for any information that is publicly available on such networks.

Ontorium may collect and process personal data in connection with identity verification, KYC/AML compliance, and regulatory obligations. Such data will be processed in accordance with applicable data protection laws and Ontorium’s Privacy Policy.

You acknowledge that certain services may involve third-party service providers, and Ontorium shall not be responsible for the data handling practices of such third parties, except as required by applicable law.

### 10. Disclaimers

10.1 THE PLATFORM AND ALL CONTENT, SERVICES, AND FEATURES, INCLUDING OXAU TOKEN ISSUANCE, THE AQUA LENDING AND LIQUIDITY MARKET, AND ANY FUTURE APPLICATION LAYER SERVICES, ARE PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, ONTORIUM DISCLAIMS IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.

10.2 The availability and performance of the Platform, including minting, redemption, swap, and lending functionalities, may vary depending on network conditions, system performance, and external dependencies. Certain data, including price feeds, collateral valuations, and other information, may be subject to delays or inaccuracies due to third-party sources or technical limitations.

10.3 OXAU tokens are designed to reflect exposure to underlying physical gold assets. However, the value, liquidity, and availability of OXAU may vary depending on market conditions, operational factors, and applicable product terms. Users should be aware that access to minting, redemption, and swap services may be subject to eligibility requirements, processing conditions, and operational constraints. For physical gold redemption inquiries, please contact <contact@ontorium.io>.

10.4 Participation in lending and borrowing activities through the AQUA protocol involves risks associated with collateral management, market volatility, and smart contract execution. Collateralized positions may be subject to liquidation if required thresholds are not maintained. Users are responsible for monitoring and managing their positions.

10.5 The Platform relies on smart contracts and public blockchain networks, which may be subject to technical limitations, vulnerabilities, or network-related disruptions. Blockchain transactions are irreversible and may be affected by congestion, delays, or network events beyond Ontorium’s control.

10.6 Certain underlying assets may be held by third-party custodians. While Ontorium works with established partners to support asset backing and verification, custody arrangements are subject to operational, legal, and market factors that may affect accessibility and processing timelines.

10.7 Nothing on the Platform constitutes investment, financial, legal, or tax advice. All content and services are provided for informational purposes only. Users are responsible for making independent decisions and, where appropriate, seeking professional advice.

You acknowledge that your use of the Platform, including any interaction with digital assets or smart contracts, is at your own risk.

### 11. Limitation of Liability

To the maximum extent permitted by applicable law, Ontorium and its affiliates, officers, directors, employees, agents, licensors, and service providers shall not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, including but not limited to loss of profits, loss of data, loss of digital assets, goodwill, service interruption, computer damage, or system failure, arising out of or in connection with your use of or inability to use the Platform.

In no event shall Ontorium's total liability to you exceed the greater of (i) the fees paid by you to Ontorium in the twelve (12) months preceding the event giving rise to liability, or (ii) one hundred U.S. dollars (USD $100).

Some jurisdictions do not allow the exclusion or limitation of certain warranties or liability. In such jurisdictions, the above limitations shall apply to the maximum extent permitted by law.

### 12. Indemnification

You agree to indemnify, defend, and hold harmless Ontorium and its affiliates, officers, directors, employees, agents, licensors, and service providers from and against any and all claims, liabilities, damages, judgments, awards, losses, costs, expenses, and fees (including reasonable attorneys' fees) arising out of or relating to: (i) your violation of these Terms; (ii) your unauthorized or improper use of the Platform; (iii) your violation of any applicable law or regulation; (iv) your violation of any third-party rights; or (v) any content or data you submit to or transmit through the Platform.

### 13. Fees

In addition to Ontorium’s fees, third-party fees may apply in connection with your use of the Platform, including fees charged by custodians, payment processors, blockchain networks, or other third-party service providers. Such third-party fees are separate from and in addition to any fees charged by Ontorium, and are subject to the terms and conditions of the relevant third party. You acknowledge and agree that you are responsible for all applicable third-party fees.

You are solely responsible for any network transaction fees (including gas fees) incurred in connection with blockchain transactions on the Platform. Such fees are determined by the relevant blockchain network and are outside Ontorium’s control.

All fees paid are non-refundable unless otherwise required by applicable law or expressly stated in applicable product-specific terms.

Fees are subject to change at Ontorium’s discretion. Any changes to the fee structure may be communicated through the Platform. Continued use of the Platform following a fee change constitutes your acceptance of the updated fees.

Ontorium may charge fees in connection with certain Platform services, including but not limited to minting, redemption, swap, and protocol usage fees. Applicable fees will be disclosed to you prior to completing any transaction. By proceeding with a transaction, you agree to pay all associated fees.

### 14. Taxes

You are solely responsible for determining and fulfilling any tax obligations arising from your use of the Platform, including but not limited to obligations related to minting, redemption, swap, lending, borrowing, and any other activities or features made available through the Platform, as well as any gains or income derived from such activities.

Ontorium does not provide tax advice and makes no representations regarding the tax treatment of any Platform activity in any jurisdiction. You should consult a qualified tax adviser regarding your specific circumstances.

To the extent required by applicable law, Ontorium reserves the right to withhold taxes or report transaction information to relevant tax authorities. You agree to provide any information reasonably requested by Ontorium to comply with applicable tax reporting obligations.

### 15. Termination

Ontorium may suspend or terminate your access to the Platform at any time, with or without cause, and with or without notice, to the extent permitted by applicable law. Upon termination, your right to access and use the Platform will immediately cease.

Provisions of these Terms that by their nature should survive termination, including but not limited to provisions relating to intellectual property, disclaimers, limitation of liability, indemnification, fees, taxes, and dispute resolution, shall survive any termination or expiration of these Terms.

### 16. Regulatory Matters and Compliance&#xD;

Ontorium operates in a rapidly evolving regulatory environment. The regulatory treatment of blockchain-based assets, DeFi protocols, and tokenized real-world assets varies significantly across jurisdictions and is subject to change. Ontorium may, at any time and without prior notice, modify, restrict, or terminate access to the Platform or any feature thereof in response to changes in applicable laws, regulations, or regulatory guidance. You are solely responsible for determining whether your use of the Platform complies with applicable laws and regulations in your jurisdiction. Ontorium may be required by law to collect, report, or disclose information about your account activity to governmental authorities, including for AML, KYC, tax reporting, or other compliance purposes. By using the Platform, you consent to such disclosures to the extent required by law.

### 17. Modifications to Terms

Ontorium reserves the right to modify these Terms at any time at its sole discretion. If we make material changes to these Terms, we will provide notice through the Platform or by other reasonable means. Your continued use of the Platform following the effective date of any modification constitutes your acceptance of the updated Terms. If you do not agree to the updated Terms, you must immediately discontinue use of the Platform.

### 18. Governing Law and Dispute Resolution

These Terms shall be governed by and construed in accordance with the laws of the British Virgin Islands, without regard to its conflict of laws principles. Any dispute arising out of or in connection with these Terms or the Platform shall be subject to the exclusive jurisdiction of the courts of the British Virgin Islands.

Notwithstanding the foregoing, Ontorium reserves the right to seek injunctive or other equitable relief in any court of competent jurisdiction to prevent irreparable harm.

### 19. General Provisions

These Terms, together with the Privacy Policy and any additional terms incorporated by reference, constitute the entire agreement between you and Ontorium with respect to the Platform.

If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.

Ontorium’s failure to enforce any right or provision of these Terms shall not constitute a waiver of such right or provision.

These Terms do not confer any rights or remedies on any third party.

You may not assign or transfer any of your rights or obligations under these Terms without Ontorium’s prior written consent. Ontorium may assign its rights and obligations under these Terms without restriction.

Ontorium shall not be liable for any failure or delay in performance resulting from circumstances beyond its reasonable control, including but not limited to blockchain network failures, governmental actions, natural disasters, or cyberattacks.


