Architecture

Eleven layers.
Nine pluggable modules.
Four cross-cutting capabilities.

The operating system behind sovereign, multi-vertical, institutional-grade vaults. ERC-4626 + ERC-7540 native at the vault-shell layer. Layers 4–11 are the mandatory backbone. Layers 1–3 are configurable per institution.

The Operating-System Analogy

A vault is not a contract. It's a system.

Wrapper-builders treat vaults like single contracts. They're not. A real vault is an accounting engine, a risk surface, a policy enforcer, a custody bridge, a reporting pipeline, a governance interface, a compliance gate, and a lifecycle manager — all interacting under conditions where capital cannot be lost and policies cannot be bypassed.

VaultOS factors these into eleven explicit layers so wrapper-builders can configure what's unique to their product (Layers 1–3) and inherit what should never be rebuilt (Layers 4–11).

Reusable backbone. Layers 4–11 are designed, audited, and reused across every wrapper built on VaultOS.

Multi-vertical from day one. Lending, RWA, staking, LP, perps, and prediction live together in a single vault.

Compliance-readable by default. Our Per-Role Policy DSL is versioned, approval-gated, and human-readable.

The Stack

Configurable wrapper. Mandatory backbone.

Layers 1–3 configure per institution. Layers 4–11 are the battle-tested backbone.

VaultOS 11-layer architecture: layers 1-3 (Vault Shell, Product Semantics, Vertical Adapter) are configurable per institution; layers 4-11 (Accounting Engine, Risk Surface, Per-Role Policy DSL, Custody Bridge, Yield Adapter Registry, Reporting Pipeline, Governance Interface, Lifecycle Manager) are the mandatory backbone.
L1

Vault Shell

Configurable

The ERC-4626/ERC-7540 vault contract facade your LPs interact with.

L2

Product Semantics

Configurable

Subscription/redemption model, fee schedule, share-class definitions.

L3

Vertical Adapter

Configurable

Vertical-specific logic (RWA / lending / staking / perps / etc.).

L4

Accounting Engine

Backbone

Deterministic NAV, share accounting, fee accrual, incentive tracking.

L5

Risk Surface

Backbone

Caps, exposure limits, correlation guards, circuit breakers.

L6

Per-Role Policy DSL

Backbone

Human-readable, versioned, approval-gated policy language read by every layer.

L7

Custody Bridge

Backbone

Integrations with institutional custodians (Fireblocks-class) — non-custodial by default.

L8

Yield Adapter Registry

Backbone

Whitelist + versioning of external yield strategies plugged into the vault.

L9

Reporting Pipeline

Backbone

Emit accounting-grade events for LP dashboards, regulators, and internal audit.

L10

Governance Interface

Backbone

Sovereign upgrade authority — your institution holds the keys, not a shared protocol.

L11

Lifecycle Manager

Backbone

Deployment, migration, pause/resume, wind-down runbooks encoded on-chain.

Module Catalog

Nine modules. Add what your wrapper needs.

VaultOS pluggable modules diagram: nine independent modules that attach to the vertical adapter layer, each solving a specific institutional requirement.
M01

ERC-7540 Async Redemption

Async subscription/redemption windows for RWAs and private-credit vaults.

M02

Compliance Evidence Layer

On-chain attestation + off-chain proof pinning for regulator/auditor consumption.

M03

Ingestion Gateway

Structured KYC/KYB, jurisdiction, accreditation checks with signed evidence.

M04

Parametric Trigger Engine

Rule-based on-chain triggers (rate resets, NAV floors, coverage payouts).

M05

Instant Liquidity Facility

Optional discount-priced fast-exit pool for illiquid asset positions.

M06

Redemption Ladder

Multi-window redemption schedules with size caps and priority queues.

M07

ERC-3643 Share Classes

Regulated permissioned tokens with on-chain transfer restrictions.

M08

Exit Engine (S1–S6)

Six exit mechanisms (fast pool, reverse-Dutch, NAV cap, composability wrapper, OTC, coverage overlay).

M09

AI-Augmented Strategies

Policy-bounded strategy execution, anomaly detection, automated reporting. Never autonomous over capital.

Sovereign Upgrade Authority

Who can upgrade what.

The first question any risk committee asks: who holds the keys?

Layers 1–3 · Configurable

Your institution

You own the deployed contracts for Vault Shell, Product Semantics, and Vertical Adapter. You hold the upgrade keys. You choose the multisig/timelock topology, the change-management workflow, and the approval quorum. No shared protocol has authority over your capital surface.

Layers 4–11 · Backbone

Versioned framework

Backbone layers ship as audited framework contracts. Upgrades are opt-in by version — you pin a version and adopt new releases on your own schedule. No forced upgrades. Framework releases follow semantic versioning + a public changelog + security advisories via the disclosure channel.

Modules

Attach / detach at will

Modules are additive. Attaching a new module (say, ERC-3643 share classes) is a scoped deployment reviewed by your compliance function. Detaching is symmetrical — no lock-in at the module boundary.

Across the Stack

Four capabilities, every layer.

1. AI-Augmented Strategies — Optional AI for strategy execution, anomaly detection, automated reporting. Always bounded by the Layer 6 policy DSL. Never autonomous over capital movements.

2. Per-Role Policy DSL — A human-readable, versioned, approval-gated policy language that runs through every layer. Compliance can read it. Engineering doesn't have to translate.

3. Non-Custodial by Default — Capital stays in client-owned custody throughout. VaultOS contracts never take direct custody.

4. Sovereign Upgrade Authority — Your institution holds the upgrade keys for the contracts you deploy. No tenant-on-shared-protocol model.

System Flow

Capital in. Policy gates. Yield out. Reporting back.

Policy is the supervisor. Every operation passes through it.

VaultOS Per-Role Policy DSL Flow
Why This Wins

Five differentiators. All architectural.

VaultOS Five-Property Wedge
Investment

Transparent pricing for the OS underneath.

Three stages, one number. Same math you'll see in Discovery, deployment, and Year 1.

Stage 1

Discovery & Architecture

USD 15K

Fixed. Scoping engagement: wrapper design, integration map, deployment estimate.

2–3 weeks
Stage 2

Production Deployment

USD 60–160K

Range depends on # of yield adapters, compliance modules, chain targets, audit scope.

Weeks, not months
Stage 3

Year 1 Platform Fee

USD 25–75K

Includes framework updates, security patches, module upgrades, on-call support.

12-month term
Total Year 1 TCV — sum of the three stages above:USD 100–250K Year 1 TCV

Want to evaluate VaultOS for your product?

A discovery call maps your requirements to the right configuration of Layers 1–3 and the right module set.

Book an Architecture Review