The stablecoin financing layer for robotics
and the hardware economy.
DualMint is onchain private equipment and robotics finance: the model Caterpillar Financial and John Deere Financial run offchain, at hundreds of billions, institutional-only and illiquid. We issue no loans. Title sits in a bankruptcy-remote SPV, the operator runs the machine, and DualMint takes a priority return from its operating revenue.
We underwrite usage rather than operator credit. IoT telemetry reports each machine's revenue in near real time, and an Asset Performance Index (0 to 100) gates origination and vault inclusion. Because title never leaves the SPV, underperformance becomes repair, recovery, or redeployment rather than a credit write-off.
Traction & Performance
On-chain track record, distribution history, and portfolio defaults.
What is DualMint's current onchain footprint, TVL, user base, and operational track record to date?
DualMint's current onchain footprint is built around its 1:1 RWA marketplace, which is the live, proven track record for the upcoming Machine Yield Index vault. The vault is not yet live, but the marketplace has produced a real operational track record. More than 1,300 assets have been originated and sold onchain across multiple machine and robotics categories. The established marketplace lines have paid out for 16 consecutive months since May 2025 without delays, restructurings, or defaults.
The marketplace has paid $52,602.60 to investors at a 15.72% net annualized yield and a 100% on-time rate over 8,700 cycles, against $502,107 of capital deployed across 1,310 machine-backed positions, with every distribution onchain-verifiable (see "Onchain distribution receipts"). DualMint has earned $18,580.90 in cumulative minting + yield commissions to date. This was achieved with minimal marketing, largely on organic community demand. Traction and market context are laid out in the pitch deck.
On the operator side, DualMint has developed a sizable sourcing funnel: approximately fifty million dollars in operators are ready for vault deployment once the next phase of the protocol is live. The marketplace has therefore confirmed both sides of the product: investors are willing to purchase tokenized SME yield, and operators are willing to adopt the financing model at scale.
Because the vault has not yet been deployed, TVL is not aggregated in a single ERC-4626 structure. Instead, capital is currently distributed across individual asset NFTs, each representing a direct right to cashflows. DualMint will consolidate this capital into the vault once the structure is complete, allowing it to report unified onchain TVL in a manner consistent with institutional RWA protocols.
The NFT holder base is derivable from onchain ownership records and is provided on request during diligence.
How have the financed assets performed so far, and what does DualMint's payout history, default history, and reliability record indicate?
The record to date is clean, consistent, and fully onchain-verifiable. The numbers:
- Positions originated: 1,310 machine-backed positions originated and sold onchain (1,310 as of July 2026; 1,272 yielding).
- Distributed to investors (onchain-verified): $52,602.60 at a 15.72% net annualized yield and a 100% on-time rate over 8,700 cycles, against $502,107 of capital deployed. See "Onchain distribution receipts."
- DualMint revenue: $18,580.90 in cumulative minting + yield commissions to date (per the DualMint Earnings dashboard); fees were 10% standard, with some early deals at 5%.
- Current throughput: roughly $7,500 per month in operating cash flow processed and distributed (most recent months ~$7,568).
- Distribution history: 16 consecutive months of monthly distributions since May 2025, across the established marketplace lines.
- Missed payments: 0.
- Operator defaults: 0.
- Reassignments / recoveries: 0; the recovery waterfall has never been exercised.
What this proves. Cash flow from the underlying machines has arrived every month for 16 months with no missed payment and no operator default. The IoT telemetry that verifies machine usage against operator revenue reports has functioned as designed, and onchain settlement of distributions has run without interruption. The mechanism (originate, verify, distribute) works, and it has worked through a volatile market because machine usage does not move with crypto. It is demonstrably operating cash flow, not sale-funded: no new primary units have been sold for roughly the past three months, yet monthly distributions have continued on schedule. Yield that persists with zero new sales cannot be funded by sales.
What this record does not yet cover. Two milestones remain, stated plainly:
- A live default. With zero defaults, Layer 1 of the loss waterfall (repossess the machine, reassign the operator) has not run in production, so the 70 to 95% recovery bands are modeled off the amortization schedules rather than observed; the reserve math and honest gaps are walked in full in the liquidation answer (Risk Management). The model is deliberately engineered for the year 2 to 4 window when equipment-finance defaults typically cluster: the operator's exposure is the machine itself (non-cash), IoT telemetry flags underperformance months ahead of a loss, and reassignment restores cash flow without a sale. That machinery is built and contracted, and it proves itself in a live event.
- The vault. This record is the marketplace. The Machine Yield Index vault, which pools these cash flows, is the next milestone; its pooled redemption mechanics and aggregated NAV are designed but not yet live.
Every distribution in the record is onchain and independently verifiable. These two items are execution milestones, disclosed as such.
Onchain distribution receipts: what does the live yield record show?
Every distribution settles onchain and is independently verifiable. Figures are from DualMint's live yield dashboard as of 6 July 2026, across all live product lines.
Cash-flow distribution track record (onchain-verified)
| Metric | Value |
|---|---|
| Distributed to investors | $52,602.60 |
| Net annualized yield | 15.72% |
| On-time distribution rate | 100% (8,700 yield cycles) |
| Months active | 14 (monthly, since May 2025) |
| Capital deployed | $502,107 |
| Positions | 1,310 originated · 1,272 yielding |
| Chains | Live across 3 (Arbitrum, Base, Peaq) |
Distributions have run for 16 consecutive months with zero missed cycles. The monthly run-rate scaled from a few hundred dollars at launch to roughly $7,500 per month, entirely on organic demand.
Verification. Every distribution settles to holder wallets onchain and can be independently reconciled; each cycle is underpinned by machine-level IoT telemetry. Full contract-level and per-asset detail is available under NDA during diligence. A public dashboard will publish at vault launch.
Product & Asset Structure
What the tokenized asset is, and how performance data is verified and updated.
What exactly is the tokenized asset?
The underlying is real, revenue-generating machines and robotics. DualMint is onchain equipment financing, so the token is a claim on a machine's operating cash flow, not a claim on a market-traded security.
There are two token forms across the two products:
- Marketplace, 1:1 machine-backed NFT. Each NFT corresponds to one specific physical machine and represents the right to that machine's operating cash flow, distributed monthly in stablecoins (USDC or USDT depending on the asset). One machine, one NFT.
- Machine Yield Index (vault, upcoming), sUSDm vault share. An ERC-4626 share token representing a pro-rata interest in a diversified pool of the same machine cash flows. Yield accrues as book-value per share rather than as separate distributions.
In both cases the holder owns an economic interest in operating cash flow, and neither token conveys legal title to the machine. What stands behind that cash-flow claim differs by product:
- Marketplace NFT: provenance. The entitlement is created by a direct agreement between the operator and the NFT holder (the provenance agreement). Boring Vault Corp issues the serialized 1:1 NFT and verifies operating performance via IoT telemetry, but is not a party to the ongoing cash-flow obligation, which runs operator-to-holder. There is no SPV title or OSA behind an individual marketplace NFT; on operator default the holder's recourse is under the provenance agreement.
- Vault (Machine Yield Index): SPV-backed. Legal title to the pooled equipment is retained by the bankruptcy-remote BVI SPV (DualMint Ltd.); the operator runs the machine under a revocable licence, with contractual step-in and repossession rights under the Operator Security Agreement (OSA). The SPV structure stands behind the pool for recovery.
How often is performance data updated?
Different data streams update at different cadences:
- IoT telemetry (near-real-time where the vendor API supports it; otherwise polled periodically and on-demand). Equipment logs cycle counts, uptime, and usage events automatically, independent of what the operator reports; DualMint pulls this data at the cadence each integration supports (and on-demand when investigating anomalies) rather than as a continuous real-time stream.
- Revenue reconciliation, monthly. At each monthly epoch, telemetry is cross-checked against bank-transaction data and the operator's revenue report (a 2-of-3 attestation) before cash flow is recognised.
- Distributions, monthly. Marketplace cash flow is paid out monthly in stablecoins; the vault recognises yield monthly into book-value per share.
- Asset Performance Index, monthly. Every asset is re-scored each month on its updated telemetry, utilisation, and payment data; the score can move an asset's standing between epochs.
- NAV (book value), updated on material events and at epoch close. Book value is held constant between material events (purchase, sale, liquidation, impairment) and reconciled at each monthly epoch.
The reader-facing cadence is monthly: a depositor sees a monthly distribution, a monthly reconciliation, a re-scored portfolio, and an updated NAV. The telemetry underneath is captured continuously by the equipment and pulled at the cadence each vendor API supports.
End of packet. 109 answers across 16 sections, 0 appendices.
Underwriting & Operations
Underwriting standards, asset validation, and operator network.
What is the Asset Performance Index, and why is it a moat?
The Asset Performance Index (API) is the underwriting engine. It is a 0-100 score built from IoT telemetry across four pillars: uptime, utilisation, revenue consistency, and operator track record. It is majority machine-generated, scored per asset and per operator, and it re-scores every month as new telemetry arrives. It gates origination eligibility, the pricing band, monitoring intensity, and vault inclusion. No telemetry means no score, and no score means no deal.
Usage risk, not credit risk. Every other credit and RWA protocol underwrites the borrower: will they repay? That is a binary, backward-looking question answered by a credit file that updates once a quarter at best. DualMint underwrites the machine: will it be used? Live machine data answers that question continuously, not once a quarter. It is a different underwriting primitive.
The consequence is structural. The operator is swappable and the machine keeps earning, so a failure is a repair rather than a write-off. And because the signal is behavioral rather than financial, it lands within hours of an event instead of months after a reporting period, early enough to intervene before a default rather than discover one afterward.
Why it is a moat. The scoring methodology is copyable in weeks. The dataset behind it is not. The API is a behavioral credit history assembled from 16 months of live telemetry across 1,310 positions and three chains, and it has three compounding properties.
It is non-transferable. An operator's clean performance record lives with the asset and the DualMint relationship, not with the operator. They cannot carry it to a competitor. Leaving means rebuilding a track record from zero, which is operator lock-in that strengthens every month they perform.
It compounds monthly. Every machine that comes online adds data points on usage by geography, season, and operator type, on recovery timelines, and on category risk. The models get more accurate and harder to replicate with each month of clean data. A new entrant can copy the formula, but matching the record requires originating equivalent assets over equivalent time.
It works on both sides. The same dataset sharpens underwriting, tightening pricing and category assumptions, and sharpens origination, telling DualMint which operators to back. Underwriting improves with scale by design, the opposite of a credit book where rising volume adds risk.
What it gates. The same four gates covered above, funnel entry, price, monitoring intensity, and vault inclusion, run on the score rather than analyst judgment, which is why onboarding another operator does not require another underwriter. The operational thresholds, category playbooks, and rejection rules are detailed in the underwriting standards answer.
The structure is copyable in weeks. The pipeline and the record are not.
What underwriting standards and category-specific playbooks does DualMint use to evaluate assets and operators, and how are risks controlled at origination?
Every asset and operator is scored by the Asset Performance Index (API); see What is the Asset Performance Index, and why is it a moat? for the full scoring mechanics. Today the score is applied through category templates and analyst review; full programmatic scoring is the vault-launch build. What follows is how that score gets used at origination: the playbooks, gates, and rejection rules built around it.
Around the API sit per-category playbooks. Each playbook fixes a standardized lease template, payback period range, expected usage cycles, maintenance assumptions, and intervention protocols. Parameters are validated on the seasoned machine lines and set at design stage for categories still in incubation.
Category gate: only asset types with predictable, measurable, historically stable usage patterns enter the funnel: quantifiable throughput, consistent daily cycles, recognizable seasonality.
Operator gate:
- Verifiable revenue history required
- IoT integration capability mandatory, so the API can be scored
- Demonstrated operational discipline
- Economic exposure via equipment ownership: DualMint holds legal title through the SPV, the operator runs the machine under a revocable licence, and contractual step-in flows through the Operator Security Agreement (OSA). No cash escrow, plus the non-refundable 10% origination fee.
Automatic rejection: no telemetry capability, an API score below the category floor, no reliable asset performance record, or refusal of the origination fee.
Origination control rests on three anchors: the API score sets eligibility and pricing band, the SPV title-retention and OSA step-in structure secures recovery without relying on a borrower balance sheet, and concentration caps (10% single asset, 15% single operator, 50% single sector) bound correlated exposure. Today's book is far more granular than these ceilings require; the caps are set as headroom for the larger robotics and RaaS tickets on the roadmap. There are no LTV caps; leaseback plus SPV step-in is the collateral mechanism.
Post-deployment control: vendor APIs expose usage, uptime, throughput, and location performance, pulled periodically per integration and on-demand for anomalies. Behavioral data lands within hours or days of an event versus months for quarterly financials, early enough to intervene before default, and it feeds the API score directly. The dataset compounds across 3 live chains (Arbitrum, Base, Peaq) as machines come online, tightening category assumptions and sharpening the score. Underwriting improves with scale by design; the evidenced record is 16 months on the seasoned lines. Playbooks: GitBook docs.
How does DualMint validate new asset categories before including them in the pooled vault, and what role does the incubation phase play in risk management?
DualMint does not add new asset categories to the Index Vault based on assumptions or generic underwriting models. Instead, each category enters through a structured incubation phase designed to produce empirical performance data before any pooled capital is exposed.
Incubation Phase Process:
- Initial Funding via 1:1 NFT Tokens (Not Pooled Vault)
- Fund 10-20 assets in a new category through individual bespoke NFT tokens sold directly to retail investors
- Each NFT represents a direct claim to one specific asset's cash flows
- Operators pay origination fees and sign revenue-share agreements
- Capital raised: ~$300K to date through this incubation mechanism (a subset of total marketplace primary sales)
- Data Collection Period (3-6 Months)
- Collect continuous usage data across different operators and locations
- Monitor payment consistency, maintenance patterns, and failure modes
- Track seasonality, geographic variance, and operator behavior
- Build dataset for category-level performance modeling
- Category-Level Performance Analysis
- Build the Asset Performance Index (API) baseline for the category from real telemetry: uptime, utilisation, revenue consistency, operator track record
- Determine category-specific payback periods, volatility bands, and durability
- Identify early warning indicators and performance thresholds
- Create category playbook with standardized underwriting parameters
- Vault Inclusion Criteria
- Performance must be predictable across multiple operators
- API scores hold above the category floor across real cash flow data
- Category playbook documented with clear risk parameters
- Only add to pooled vault once the empirical risk profile is established
Example category thresholds (target parameters, illustrative; validated for the seasoned lines, design-stage for others):
- Seasoned machine categories: Require high daily usage cycles, very high predictability
- Newer machine categories: Require high daily activation counts, high predictability with location dependency
- Transaction-based machine categories: a daily-transaction floor, high predictability with seasonal variance
Under this model the vault only includes assets with measurable, demonstrated performance. It removes the cold-start problem of exposing pooled capital to a new category, and it sets up a clear pipeline where new asset types earn their way in through reliability, scored on the API before a dollar of LP capital is committed. Safety compounds with scale rather than degrades. The incubation criteria are documented in the GitBook docs.
What are the major risks inherent in DualMint's model, and how are operator, asset, and structural risks mitigated through system design?
DualMint starts from the position that SME finance cannot be de-risked through traditional credit methods. It has to be reframed around the behaviour of the underlying asset and the incentives around it. No part of the model eliminates risk; the goal is to manage it continuously and disclose it candidly.
The most material risks an allocator should weigh, stated plainly:
- Untested recovery mechanism. The loss waterfall's first layer (repossession and operator reassignment) has never been exercised in a live default. There have been zero defaults and zero reassignments to date, so the recovery and reassignment targets are design assumptions, not measured outcomes. The first real default is the test.
- Unseasoned track record. Equipment-finance defaults typically peak in years 2 to 4 of an asset's life. The established marketplace lines have 16 months of clean history, which sits before that curve, necessary but not sufficient evidence of through-cycle resilience.
- Vault not live. The current record is the 1:1 marketplace MVP. Pooled vault redemption mechanics and aggregated performance are not yet demonstrated; redemption at scale is unproven.
- Insurance not bound. The Tier 2 performance bond (via YAS, a Hong Kong MGA, licence FA2648, carried by Zurich) is in discussion and no provider is bound yet. DualMint-placed cover (incl. D&O) is being sourced, none bound. Tier 1 asset insurance is operator-carried.
- Smart-contract / technical risk. The vault launches on Concrete's audited ERC-4626 stack; DualMint's own-contract audit is ongoing. Onchain settlement, oracle, and custody integrations carry the usual smart-contract and operational-technology exposure.
- Regulatory / structural risk. The Panama governing-law and VASP/AML regime specifics are being confirmed by Panama counsel and are not yet finalised. Cross-jurisdiction enforceability of security interests is being established per asset location.
- Key-person / lean-team risk. A 9-person team running a multi-category financing protocol concentrates execution risk; capacity to scale to $50M+ without proportional headcount is a design target, not a demonstrated result.
- Operator concentration during ramp. At low TVL, concentration limits (10% per asset, 15% per operator, 50% per sector) bind less effectively; concentration compresses toward target only as the book scales.
Against those risks, the protocol organises its mitigations into three categories:
1.Operator-Level Risk
- Mitigation: Operator economic exposure via equipment ownership: SPV holds legal title, operator runs the machine under a revocable licence, no cash escrow posted, plus the non-refundable origination fee
- Mitigation: Revenue-share/finance lease agreements
- Mitigation: Contractual step-in, repossession, and revenue-redirection rights through the Operator Security Agreement (OSA)
- Outcome: Credit risk is transformed into usage risk; operators have skin in the game through the equipment they stand to lose
2.Asset-Level Risk
- Mitigation: Selection of stable-throughput categories
- Mitigation: IoT telemetry for continuous monitoring
- Mitigation: Quantifiable output units (loads, charges, sales)
- Outcome: Risk is observable, continuous, and correctable
3.Structural Risk
- Mitigation: 3% of asset value ring-fenced as the Origination Reserve (Layer 2 of the loss waterfall; sizing detail: Financial: Reserve & Insurance Mechanisms)
- Mitigation: Vault liquidity buffer (undeployed depositor capital) services redemptions; a liquidity tool, not a loss layer
- Mitigation: Ecosystem partner stop-gap liquidity commitments (bridge timing mismatches, not loss-absorbing; agreement in progress, not executed)
- Outcome: layered protection against variance; funding status per layer at Collateral & Strategy: Loss Waterfall
The system manages risk continuously and empirically and reports the parts not yet stress-tested in production.
Why would an operator choose DualMint over a bank?
For most machine operators in DualMint's primary geographies (SEA/APAC), the bank is not the alternative. DualMint does not compete on price; the revenue-share structure removes the conditions under which banks decline to participate.
Why banks do not originate these relationships:
- Basel III capital cost. SME exposures carry an 85% risk weight (vs 75% retail); all-in capital cost of lending to a small operator is roughly 5x an AA-rated borrower. The disincentive is structural, not operator-specific.
- AML de-risking. Cash-intensive machine operators are classified "higher risk" under the FFIEC BSA/AML Examination Manual, requiring Enhanced Due Diligence; many banks decline the category outright (documented in the World Bank's de-risking studies). The problem is the category, not the operator.
- Cash revenue is unverifiable to a credit desk. Coin-operated and cash-collected businesses produce no bank-statement trail a credit officer can tie back to a specific machine, so the file rests on operator-attested figures and gets discounted or declined on that basis alone. DualMint reads the revenue off the asset instead: IoT telemetry meters cycles, uptime, and collections per machine, which is why a category banks treat as opaque is the category we can verify at source.
- Ticket-size economics. A $5K loan costs a bank nearly as much to underwrite as a $500K one — the fixed cost of credit review, documentation, and servicing doesn't scale down. The business isn't a bad credit risk; the loan is uneconomical for the bank's process, independent of the ADB rejection-rate data below.
- Collateral mismatch. SEA/APAC SME frameworks accept real property; movable equipment with thin resale markets does not qualify. The machines that generate the revenue cannot secure the loan.
- Rejection rates. ADB: 45 to 60% of SME loan applications in the region declined at first credit review. IFC/World Bank: global MSME financing gap $5.7T, up 27% in a decade despite fintech expansion.
- Tightening, not easing. ECB Bank Lending Survey Q1 2026: net 24% tightening in SME rate conditions (from 13% prior quarter). Preqin projects the APAC private credit gap growing $59B to $92B by 2027 (16% CAGR).
Where banks do lend, the rates:
| Market | Bank SME rate | Alternative lending | MCA (practical alternative) |
|---|---|---|---|
| Singapore | 4 to 12% | 8 to 25% | 20 to 120% APR |
| Malaysia | 6.8 to 14% | 12 to 30% | 20 to 200% APR |
| Indonesia | 8.22 to 9.32% floor | 15 to 40% | 30 to 250% APR |
| Thailand | 4 to 12% | 10 to 25% | 20 to 150% APR |
| Philippines | 8 to 15% | 15 to 45% | 25 to 300% APR |
| Vietnam | 7.1 to 9.4% | 12 to 36% | 30 to 200% APR |
| Australia | 7.19 to 7.26% reference + margin | 10 to 18% all-in | 20 to 350% APR |
Merchant cash advances (20 to 350% APR) are the practical capital source for cash-intensive small businesses when banks decline; that is the real competitive set, not the bank's headline rate.
Robotics is harder for a bank, not easier:
The same constraints tighten as the asset class moves from everyday machines to robot fleets, which is why the robotics pipeline reaches us rather than a lender.
- The credit desk does not understand the product. Robot fleets have no comparables, no established depreciation curve, and no residual value index. A lender that cannot price the collateral at exit cannot size the facility, so the file stalls at the asset review rather than the borrower review.
- The book is thin. Robotics operators are young companies, often venture-funded and loss-making at the corporate level while the fleet itself runs against contracted revenue. Credit-based underwriting reads the corporate balance sheet, which is the weakest part of the picture, and never gets to the fleet, which is the part that actually pays.
- They are underwriting the wrong thing. A bank underwrites whether the company repays. We underwrite whether the machine earns. The fleet generates revenue from day one under a service contract, and that revenue is metered by telemetry the manufacturer already ships in the unit.
- No residual exposure on our side. DualMint's assets self-amortize to zero, so there is no terminal value to model and no residual index required to price the deal.
The structural difference:
| Bank loan structure | DualMint SPV structure |
|---|---|
| Operator takes on debt | No debt drawn and no capex; existing credit lines stay open |
| Real property collateral required | The BVI SPV holds title; no operator collateral requirement |
| Credit score and credit file reviewed | Usage-based underwriting: operator track record + machine telemetry |
| Missed payment triggers default | Shortfall triggers operator reassignment; machine keeps earning |
| Interest fixed regardless of revenue | Processing fee (10% of cash flow) scales with performance |
| Legal recovery on default | Step-in rights redeploy the machine without court action |
The BVI SPV holds legal title to the equipment; the operator holds a revocable licence and earns a revenue share (entity structure: Operational: Organizational Structure).
Pipeline evidence: 50+ operators confirmed in pipeline, sourced by the gap itself, not promotion. An operator's clean IoT track record with DualMint is non-transferable, a behavioral dataset that compounds on both sides.
Risk disclosure: this framing assumes continued bank de-risking and stable Basel III application. If banks materially expand SME appetite, the dynamic changes; current data (MSME gap +27% over a decade, Q1 2026 ECB tightening) points the other way at the horizon relevant to the current raise.
Collateral & Strategy
Reserve selection, yield sources, drawdown history, redemption, loss waterfall, and liquidity.
What structures, buffers, and recovery mechanisms protect investor capital, and how does the default waterfall operate in practice?
DualMint's capital protection framework is built on the principle that operator incentives must be aligned with investor capital from the moment a deal is initiated. The operator's economic exposure is equipment ownership, not posted cash: the SPV holds legal title to the financed machine through a leaseback structure, the operator runs it under a revocable licence, and contractual step-in flows through the Operator Security Agreement (OSA). They also pay a 10% origination fee at onboarding. Their skin in the game is that on default they lose the machine and its income stream, which drives accountability long before any intervention is necessary.
Six layers of non-depositor capital sit between an operator failure and investor principal, in strict order. Investor capital is last: it is what the six layers protect, not a layer itself.
The vault liquidity buffer is not one of these layers. It is undeployed depositor capital held liquid: a 15% minimum/target with color-coded zones (green >20%, yellow 15 to 20%, orange 10 to 15%, red <10%), held higher during the early deployment ramp. It funds redemptions and limits deployed exposure, but it cannot protect investor principal from loss because it is the investors' own money. It is kept strictly separate from the loss waterfall.
Loss Waterfall (six layers of non-depositor capital, strict order): (1) asset recovery & reassignment (non-cash; modeled recovery 70 to 95% via reassignment, 50 to 80% via liquidation, modeled off the amortization schedules given zero live defaults to date), (2) the Origination Reserve (3% of asset value, DualMint's own ring-fenced first-loss cash), (3) the Solvency Reserve (3% of monthly cash flow, building with every distribution), (4) two-tier insurance (Tier 1 in force, operator-carried; Tier 2 performance bond via YAS/Zurich, in discussion, no provider bound), (5) an external stop-gap liquidity facility (in negotiation, not executed), (6) RFQ liquidation. Investor principal is last, reached only after Layers 1 to 6 are exhausted. The full layer-by-layer walk with funding status is at Collateral & Strategy: Loss Waterfall.
In practice, operator failure does not equate to asset failure. The finance lease grants step-in, repossession, and revenue redirection rights: the protocol takes control of the machine and redeploys it to a replacement operator, with structured liquidation as the last-resort path inside Layer 1 (recovery mechanics and replacement channels: Collateral & Strategy: Bad Debt Management). Because the system underwrites usage rather than credit, most of these machine assets are inherently productive regardless of who operates them.
To date none of these layers has been triggered; every deployed deal has paid out cleanly across the marketplace track record. The full waterfall is documented in the GitBook docs.
What happens if an operator defaults, the asset cannot be reassigned, and you have to liquidate? Walk the exposure and the reserve math.
This is the correct question to push on, because reassignment (Layer 1) is where most loss events are designed to resolve, and its recovery band is untested. So the honest test of the structure is: assume reassignment fails, assume you are forced into a standalone liquidation, and show what is at risk and what absorbs it. The answer rests on one structural fact and then a set of numbers.
The structural fact: you are never liquidating the ticket. You are liquidating a residual.
The financing self-amortizes. Every month an asset operates, cash flow returns principal, so the un-recovered balance, the exposure at default (EAD), falls every month by design. The loss at default is limited to whatever principal has not yet come back, against which any liquidation proceeds are then credited. It is never the full amount originally financed. This is the same reason equipment finance books behave differently from term-credit books: a term loan carries near-full principal until maturity, while an amortizing asset de-risks itself month over month.
That single fact reframes the liquidation question from "can we resell a used machine into a thin secondary market" (a fight we would lose) to "how small is the residual by the time we would ever need to, and what sits under it."
Worked example: one asset (illustrative, round numbers).
- Amount financed at origination: $1,000
- Term: 24 months, self-amortizing through monthly cash flow
- Operator defaults at month 14
By month 14, roughly 58% of principal has already returned as distributions. The remaining exposure is not $1,000:
| Amount | |
|---|---|
| Original financed value | $1,000 |
| Principal already returned (month 14 of 24) | ~$580 |
| Exposure at default (EAD) | ~$420 |
| Standalone liquidation at 50% of EAD (low end of modeled band) | recover ~$210 |
| Residual shortfall carried into the reserves | ~$210 |
So the worst realistic single-asset outcome, reassignment failed and a fire-sale at the bottom of the modeled recovery band, is a ~$210 residual on a $1,000 ticket, roughly 21% of original value, not a total loss. At the 80% top of the modeled liquidation band the residual is ~$84, roughly 8%.
Portfolio math on the real book (14 months in).
| Metric | Value |
|---|---|
| Capital deployed | ~$302,000 |
| Positions financed | 1,310 |
| Average ticket | ~$234 |
| Single-asset concentration as % of book | ~0.08% |
| Origination Reserve (3% of deployed value, ring-fenced cash) | ~$9,100 |
| Solvency Reserve (accruing from processing share) | ~$1,500 and building monthly |
| Pooled first-loss reserves today | ~$10,600 (~3.5% of deployed), trending toward ~6% as the book seasons |
Two things the reserve percentage hides in your favour:
- The reserve sits against EAD, not against original value. A reserve worth 3.5% of the amount financed is worth roughly 7% of a mid-life EAD, because EAD at mid-life is only about half the ticket. The headline reserve rate understates the real cushion.
- Reserves pool across 1,310 positions, but losses do not arrive all at once. No single asset is more than ~0.08% of the book, so an individual default is a rounding error. The scenario that matters is a correlated one, which is what the concentration caps exist to bound.
The scenario that stresses reserves: a full single-operator failure.
The 15% single-operator concentration cap means the most any one operator can control is ~$45,300 of deployed value. Assume that operator fails entirely, every asset defaults, none is reassignable, and all are forced into standalone liquidation:
| Amount | |
|---|---|
| Deployed value under the operator (15% cap) | ~$45,300 |
| EAD at mid-life (~50% amortized) | ~$22,700 |
| Liquidation recovery at 65% of EAD (mid modeled band) | recover ~$14,800 |
| Residual shortfall into reserves | ~$7,900 |
| Pooled reserves available | ~$10,600 |
| Outcome | Reserves absorb it. Depositor principal untouched. |
At the 50% low end of the modeled recovery band the residual is ~$11,300, marginally above today's reserves, which is the point at which the Tier 2 performance bond is designed to take the gap.
The reserve is DualMint's first-loss alignment capital, not depositor insurance. It is deliberately thin. Depositors bear the tail beyond it, and the 13-15% is priced for that risk. The reserve exists so DualMint's own cash is destroyed before any depositor's, which aligns underwriting and recovery incentives; it is a signal of alignment, not a guarantee of safety. The structural protection is amortization and machine recovery, not a protocol balance-sheet backstop.
Intended reserve-to-insurance structure (not yet live). Once the Tier 2 performance bond is bound, the reserve is designed to fund the sponsor retention (the first-loss the carrier requires DualMint to hold) rather than act as a standalone buffer. On a covered loss the sequence is: asset recovery runs first, the reserve absorbs the retention band, and the carrier pays the residual shortfall above it up to the policy limit. This is standard performance-bond plumbing: carriers will not write non-performance cover without sponsor retention, so the reserve is what makes the cover placeable, and a thin retention unlocks a much larger policy limit. Tier 2 is in discussion through YAS (Hong Kong MGA, licence FA2648), carried by Zurich, with no provider bound yet, so this is the intended structure, not a live arrangement; until it binds, the reserve stands alone as thin first-loss alignment capital.
Who executes a liquidation. A standalone liquidation does not depend on a bespoke buyer hunt. An established industrial-equipment liquidation and remarketing market operates at global scale: auction and disposition firms such as Tiger Group, Heritage Global, and RB Global (Ritchie Bros) run repossessed-equipment sales across jurisdictions, including robotics-specific liquidations, and specialist dealers trade repossessed machinery as standing business. DualMint holds no standing remarketing agreements today; firms in this class are engaged per asset location at the point of need, and vendor remarketing clauses (the equipment supplier takes a repossessed unit back into its own resale channel, standard practice in equipment leasing) are the intended standing arrangement as operator agreements are executed. Beneath any remarketing outcome sits a salvage floor: even a machine with no operating buyer carries component and scrap value, which bounds recovery above zero in the worst case.
What this means.
- A single asset defaulting and being liquidated at the bottom of the band is a ~20% residual on that asset, not a write-off, because most principal has already amortized back.
- At mid-band modeled recovery, today's first-loss reserves absorb a complete single-operator wipeout with depositor principal untouched; at the low end of the recovery band a thin residual passes to the depositor tail that the 13-15% prices, and Tier 2 caps it once bound.
- The concentration caps (10% single asset, 15% single operator, 50% single sector) exist so that no correlated event scales past what the layers below can carry.
- Depositor principal is impaired only if reassignment fails and liquidation recovers below roughly half of EAD and the failure is large or correlated enough to exhaust reserves and the Tier 2 insurance and stop-gap layers behind them. Each condition is independent; the structure is built so they have to fail together.
The honest gap. Every number above is modeled: off the amortization schedules for EAD, and off a design-target 50-80% liquidation band for recovery. There have been zero defaults, zero reassignments, and zero liquidations across 14 months and 1,310 positions, so no observed recovery data exists yet. The Tier 2 performance bond that backstops the reserves is in discussion through YAS (Hong Kong MGA, licence FA2648), carried by Zurich, and no provider is bound yet. We would rather show the arithmetic and mark it as modeled than present a recovery guarantee we cannot yet evidence. DualMint will publish measured actuals, response time, liquidation proceeds, and residual against reserves, within 30 days of the first live default event. The full waterfall is documented in the GitBook docs.
How does liquidity work in the marketplace and the Index Vault, and what mechanisms support redemption, secondary market exits, and vault stability?
Real-world yield cannot be redeemed instantaneously without compromising safety or forcing the protocol to hold idle capital. In the marketplace phase, yield-bearing NFTs are transferable on the secondary marketplace, giving early users an exit channel through the market rather than redemption obligations. The upcoming Machine Yield Index vault carries that principle forward through three complementary channels plus a defined redemption process.
1. Redemption via the vault
- No mandatory lockup. Redemption requests are serviced on a published SLA: 30-day standard, 90-day stressed, 120-day maximum. Optional 3 / 6 / 12-month boost locks earn a higher yield weight; only the locked portion is non-redeemable until its tenor matures.
- Vault yield accrues as sUSDm price-per-share appreciation rather than separate cash distributions, so redemption converts shares back to USDC at the prevailing NAV.
2. Liquidity buffer (undeployed depositor capital)
- The vault targets a 15% minimum liquidity buffer with color-coded zones (green >20%, yellow 15-20%, orange 10-15%, red <10%), held higher during the early deployment ramp, with the balance deployed into operators.
- This buffer, together with amortisation throw-off, services the redemption SLA and smooths timing mismatches in global SME cash flows. It is a liquidity tool, not a loss-absorption layer.
3. Secondary market for sUSDm
- DualMint is exploring immediate-exit options to let LPs exit in-lock without forcing vault redemption. The current lean is a batch auction with tranching via a third-party AMM, targeted for activation around the $30M TVL mark when depth supports it. This is a designed, supplemental channel under evaluation, not yet live, and not active before the TVL threshold. Redemption (above) remains the primary exit path.
- An external floor-bid backstop (agreement in progress) is intended to underpin the bid side of the secondary venue.
4. Ecosystem partner liquidity support
- A temporary stop-gap facility (agreement in progress) bridges early vault cycles while TVL accumulates, transitioning to organic market depth over time.
DualMint does not offer instant redemption in the manner of stablecoins or money-market wrappers. The vault behaves more like a real-world credit fund (defined redemption mechanics, predictable cycles, and diversified inflows), which avoids the liquidity mismatches that have destabilised other RWA protocols. Vault mechanics are documented in the GitBook docs.
Can the asset be legally transferred or bought by a liquidity facility?
Yes, for the vault. Legal title to each machine in the vault pool is retained by the bankruptcy-remote BVI SPV (DualMint Ltd.), with the operator running it under a revocable licence and DualMint holding contractual step-in and repossession rights under the Operator Security Agreement (OSA). That title-retention arrangement is precisely what lets a vault asset change hands without a court order: on a confirmed event of default the SPV exercises step-in, repossesses the machine, and can reassign or sell it.
The marketplace works differently: a 1:1 marketplace NFT is a direct operator-to-holder provenance claim, not an SPV-held asset. What transfers there is the NFT (the cash-flow claim) itself on the secondary market, not an SPV interest in the machine.
A liquidity facility can take exposure at two levels:
- The economic interest: buying the vault share (sUSDm) or the marketplace NFT, i.e. the cash-flow claim, on the secondary market.
- The underlying equipment (vault): in a liquidation of a vault asset, acquiring the machine itself (or the SPV's interest in it) through the recovery process.
The exit rails are the bottom waterfall layers: the Stop-Gap Liquidity Facility can stand as floor bid for secondary exits, and RFQ Liquidation sells the asset book to funds, LPs, or OTC desks via request-for-quote.
What stablecoin liquidity depth is required to support instant secondary exit?
Depth is sized, not guessed. The secondary pool only needs to absorb the instant-exit demand that exceeds what the vault's standing mechanisms already cover: the 15% liquidity buffer (minimum/target, held higher during the early deployment ramp), amortization throw-off, and the 30-day redemption queue. Required depth is the larger of two estimates:
- Stress-exit coverage. Size the pool to absorb a one-shot exit on top of the buffer: on current assumptions, roughly a 10 to 15% instant-exit stress beyond the 15% buffer. This is the same logic as a liquidity-coverage ratio: hold enough liquid stablecoin to meet plausible outflows over a stress window.
- Price-impact (microstructure). Set depth so a target trade size stays within a tolerable price move. For a constant-product venue, price impact ≈ trade size ÷ pool size, so a pool is sized to keep a given exit's slippage under the chosen threshold.
The binding number falls out once the vault has a TVL and real redemption behaviour to observe. We finalise depth with live redemption data and the secondary-venue counterparty at the secondary market's activation point (~$30M TVL). What is stated here is the method and the implied range, not a committed figure, because committing a precise number before there is a book to stress would be a guess dressed as precision.
Reserve Selection: What is the process for selecting and underwriting various forms of collateral utilized?
The underwriting process is a three-stage funnel, documented in the Operator Management Playbook and the Underwriting Data Requirements (both available on request under NDA), with the Asset Performance Index (API) methodology in the GitBook docs.
- Category gate. Only categories with predictable, measurable, IoT-instrumentable usage cycles enter the funnel. Multiple machine categories are live today; adjacent categories are incubating on the marketplace or incoming, not yet in the live origination roster.
- Operator gate. Verifiable revenue history (12+ months of operator-system records and tax filings), IoT integration capability, GAAP-clean books, and an executed Operator Security Agreement (OSA) with step-in rights to the BVI SPV.
- Asset gate. An Asset Performance Index (API) score of ≥70 / 100 across four pillars (uptime, utilisation, revenue consistency, operator track record) sets origination eligibility; ≥80 is required for vault deployment.
APR is negotiated within scoring bands (15 to 20%), not formula-driven. Concentration limits are enforced at the portfolio level: 10% single asset, 15% single operator, 50% single sector. Origination passes through an underwriting committee, today the CFO and Smart Contract Lead; an external risk consultant is added by Phase 2.
Over 1,300 assets have been originated under this process, with zero operator defaults to date. The 16-month proof record spans the established marketplace lines, distributing for 16 consecutive months since May 2025.
Bridging & Aggregator Dependencies: Are there any collateral dependencies on cross-chain bridges or aggregator platforms? How are bridging failures or liquidity fragmentation managed?
None at launch. The Machine Yield Index deploys on a single chain (chain to be confirmed): the vault contracts, the M0-extension USDm token, and sUSDm all live on one chain, so there is no cross-chain bridge or collateral-bridging dependency. Capital flows are USDC native to that chain, not bridged, and Chainlink CCIP is not used at launch. There are no aggregator dependencies. DualMint is not aggregating across DEXes. Liquidity fragmentation is addressed by the single-pool design: one vault, one chain.
Bad Debt Management: In the event of a capital shortfall, what enforceable mechanisms exist to isolate the losses and restore the protocol capital?
When an asset underperforms or an operator fails, loss is absorbed by six layers of non-depositor capital in strict order, with depositor capital last. The vault liquidity buffer is not in this waterfall: it is undeployed depositor capital that funds redemptions, not loss absorption.
- Asset recovery & reassignment (non-cash). Drawn first. The operator's economic exposure is equipment ownership, not posted cash. The BVI SPV holds legal title to the financed machine and step-in rights under the Operator Security Agreement (OSA); the operator runs it under a revocable licence. On default, the SPV exercises those step-in rights, repossesses the machine, and reassigns it to an existing or newly-onboarded operator, or runs a structured liquidation. Recovery bands run 70 to 95% via reassignment and 50 to 80% via liquidation, within a 14 to 45 day SLA (modeled; recovery is not yet live-tested, see qa-offchain-risk-04). Reassignment draws on the existing operator base and onboards replacements through the vendor-financing / Operator Distributor framework rather than a static standby roster. The asset itself is the moat, so going-concern value is preserved through the handover. Recovers most loss scenarios with no cash drawn. 2-6. The cash and external layers. Behind recovery sit the Origination Reserve (3% of asset value, DualMint's own ring-fenced cash), the Solvency Reserve (3% of monthly cash flow, building with every distribution), two-tier insurance (Tier 1 in force, operator-carried; Tier 2 performance bond via YAS/Zurich, in discussion, no provider bound), the external stop-gap liquidity facility (in negotiation, not executed), and RFQ liquidation, in that strict order. Layer-by-layer sizing and funding status: Collateral & Strategy: Loss Waterfall and Financial: Reserve & Insurance Mechanisms.
Depositor principal is last. Reached only after Layers 1 to 6 are exhausted.
Legal mechanisms that make the above enforceable:
- Operator Security Agreement (OSA) is the contractual basis. Template drafted (12 sections, in counsel-redline with Horizons); first execution targeted pre-launch with Vertriqe. Section 7 defines events of default and per-event cure periods; Section 8 defines remedies (first-loss draw, revenue redirect, repossession, replacement-operator appointment, insurance claim, equity disposition).
- SPV title and step-in. The BVI SPV (DualMint Ltd.) holds legal title to each financed machine and is the secured party of record, with first-priority step-in rights over the physical asset perfected through the OSA in each operator's jurisdiction.
Status today: OSA execution and security-interest perfection run in operator-jurisdiction sequence pre-launch, and no live default has yet exercised recovery (see qa-offchain-risk-04).
Loss isolation across the book: each asset runs through the waterfall independently. Concentration limits cap correlated exposure: 10% per asset, 15% per operator, 50% per sector. One asset's impairment doesn't drag the rest.
Reassignment timing: 14 to 45 day SLA target from default declaration to revenue resumption with the replacement operator. Replacements are sourced from the existing operator base and onboarded through the vendor-financing / Operator Distributor framework rather than a static standby roster. See qa-objections-04 for the operator-default walk-through.
Loss Waterfall: Please outline which parties, and to which amount, bear any losses (such as the result of accrued bad debt) in which order.
Depositor capital is the last loss. Six layers of non-depositor capital absorb a default before it, in strict order.
Distance to loss. For depositor principal to take any loss, a sequence of independent failures must all land on the same exposure: an operator fails; the machine is then unrecoverable and cannot be reassigned (Layer 1, the primary defence, which draws no cash and resolves most scenarios by putting the machine back to work under a new operator); the residual shortfall exceeds DualMint's two committed, ring-fenced cash reserves (Layers 2 to 3, ≈6% of the affected exposure, funded and in place today); insurance and the stop-gap facility (Layers 4 to 5) fail to cover it; and RFQ liquidation (Layer 6) still falls short. Because the model recovers the asset rather than chasing a borrower, principal sits structurally far from loss. Concentration limits (10% single asset / 15% single operator / 50% single sector) cap how much of the book any single failure can reach.
The vault liquidity buffer is depositor TVL and is not a loss layer; it funds redemptions, not loss absorption (see the liquidity note below). Concentration limits, monthly Asset Performance Index re-scoring, and cure-period engagement (7 / 14 / 30 days by event type) operate as pre-loss defences before any layer is drawn. The full waterfall mechanics are documented in the GitBook docs.
Loss-absorbing layers (strict order, all non-depositor capital):
- Layer 1: Asset recovery & reassignment. The operator's economic exposure is equipment ownership, not posted cash. The BVI SPV holds legal title to the financed machine and step-in rights under the Operator Security Agreement (OSA), and the operator runs it under a revocable licence. On default, the SPV exercises those step-in rights, repossesses the machine, and reassigns it to an existing or newly-onboarded operator or runs a structured liquidation. Recovery bands run 70 to 95% via reassignment and 50 to 80% via liquidation, within a 14 to 45 day SLA (modeled; recovery is not yet live-tested, see qa-offchain-risk-04). Reassignment draws on the existing operator base and onboards replacements through the vendor-financing / Operator Distributor framework rather than a static standby roster. Recovers most loss scenarios with no cash drawn.
- Layer 2: Origination Reserve. 30% of the 10% origination fee (= 3% of asset value) is carved into a segregated, ring-fenced reserve at onboarding; the remaining 7% is protocol income. This is DualMint's own committed first-loss cash, drawn after recovery for any residual shortfall.
- Layer 3: Solvency Reserve. 30% of the 10% processing fee (= 3% of cash flow) is carved into a segregated, ring-fenced reserve; the remaining 7% is protocol income. Builds with every monthly distribution and is held in stablecoins. Funded from DualMint's processing share, so LP yield is unaffected. Committed non-depositor cash, drawn after the Origination Reserve.
- Layer 4: Insurance (2-tier). Tier 1, asset insurance: commercial policies covering the physical machines (theft, fire, physical damage, loss), carried by the operator and in force at onboarding as an OSA covenant; loss-payee is written into operator agreements. Tier 2, performance bond: covers operator non-performance, priced on non-performance rather than asset residual value. Placed through YAS (Hong Kong MGA, licence FA2648), carried by Zurich; in discussion, not yet bound. Once bound, Tier 2 attaches above the reserves: the Origination and Solvency Reserves serve as the carrier-required sponsor retention and the carrier pays the shortfall above it, so the reserve and the retention are the same capital, not additive cushions. Tier 2 is not a guaranteed protection layer until cover is bound.
- Layer 5: Stop-gap liquidity facility. External cash and liquidity facility; bridges redemption timing mismatches and serves as the floor bid for LP secondary exit. Agreement in progress; not yet executed.
- Layer 6: RFQ liquidation. The final layer before depositor principal. Last-line liquidity sourced from funds, LPs, and OTC desks via request-for-quote; activated only after Layers 1 to 5.
Depositor principal is last. Reached only after Layers 1 to 6 are exhausted.
What is in place today: of the six layers, three are funded and in place now (recovery rights, the Origination Reserve, and the Solvency Reserve) plus operator-carried Tier-1 asset insurance. The Tier-2 performance bond and the stop-gap facility are being arranged and are not yet binding.
Liquidity (not loss absorption): the vault liquidity buffer (15% minimum/target, color-coded zones of green >20%, yellow 15 to 20%, orange 10 to 15%, red <10%; held higher during the early deployment ramp) is undeployed depositor capital; together with amortisation throw-off and the secondary market it services the 30-day standard / 90-day stressed / 120-day maximum redemption SLA. The stop-gap liquidity facility (Layer 5, agreement in progress) also bridges redemption timing mismatches on the liquidity side, distinct from its loss-absorbing role.
Legal priority on liquidation: (1) reasonable wind-down costs, (2) LPs pro-rata, (3) DualMint operational claims, (4) DualMint equity.
Reserve Audits: Are the reserves regularly audited by a recognized auditing firm (by whom?) or are cryptographic proofs of reserves published? If so, which and in what frequency?
Independently verifiable artifacts available today:
Marketplace asset registry covering 1,310 positions: serial number, location, operator, IoT telemetry record, payment history per Underwriting Data Requirements. (2) On-chain distribution receipts: Arbitrum products in USDC, Peaq products in USDT. Every payment verifiable via tx hash on the relevant block explorer. The 16-month record spans the established marketplace lines. (3) Vertriqe full on-chain reconciliation case study (Appendix A, Vertriqe reconciliation): 9 transactions July 2025 to January 2026, every tx hash verifiable on Arbitrum, dispute resolution documented end-to-end. Payouts accrue and increase every month as monthly yields are processed; the live aggregate is $52,602.60 distributed to date and growing. (4) The vault's book-value ledger smart contract (per Vault Smart Contract Spec) aggregates per-asset book value with cryptographic proof at every NAV update post-launch. (5) Merkle proof of asset registry published quarterly post-launch as supplementary cryptographic verification.
Attestation roadmap: we intend to engage an institutional-tier proof-of-reserves attestation provider ahead of launch (selection in progress; no engagement letter signed and no provider named today). The first quarterly attestation is targeted once a provider is engaged, covering combined marketplace + vault assets; the provider will be named once selected. Independent BVI fund administrator engagement is a planned Phase 2 milestone tied to TVL scaling (same firm targeted for reporting and reconciliation in a single integrated workflow); threshold under finalisation. An independent NAV calculation agent is targeted for $50M+ TVL.
PnL/Yield Accounting Methodology: When do you recognize yield (e.g., for yield received at once at the end of a three-month allocation)? Do you ever recognize yield before it is actually received in the vault? Do you mark the portfolio to market?
Yield recognition: cash basis at receipt. Yield is recognised only when cash flow is received and cross-referenced under 2-source oracle consensus (IoT telemetry + operator-system API per the Vault Smart Contract Spec). The self-amortising rule: cash flow received is first allocated to principal recovery, up to that period's amount due, which reduces the unrecovered principal balance; only the residual becomes recognised yield. We do not recognise yield before receipt.
No mark-to-market. Physical assets are carried at book value (acquisition cost less cumulative principal recovery), not market price. NAV is the aggregated book value plus the liquidity buffer plus reserves, recalculated at the monthly epoch boundary (last day of month, 23:59 UTC).
How yield reaches depositors. Vault yield accrues to depositors as sUSDm price-per-share appreciation; there is no separate cash distribution at the vault level. Recognised yield is retained in the vault and raises NAV per share; a depositor realises it on redemption or secondary sale. (This is distinct from the 1:1 marketplace NFTs, which pay monthly cash distributions in USDC or USDT.)
Allocation periods. Recognition follows the monthly cash-flow cycle. Lumpy cash flows (for example a quarterly farm harvest) are recognised at receipt and smoothed across the following months in the per-share accrual to avoid step changes in NAV. Smoothing only re-distributes cash already received across periods; it never recognises future or unreceived yield.
A standalone PnL & Yield Accounting Policy v1.0 (revenue recognition, principal-recovery method, mark-to-market posture, accrual treatment, smoothing, NAV recalculation timing, and audit trail) is targeted for publication ahead of vault launch.
Redemption Policy: How do you plan to handle redemptions if all assets inside the vaults are depleted? Do you plan to throttle/temporarily close vault redemption or facilitate redemptions via some other mechanism? If so, which?
If all vault assets are depleted (extreme tail scenario): redemptions are throttled and the vault enters structured wind-down. The BVI SPV holds legal title plus a first-priority security interest over the physical assets and proceeds to orderly liquidation of the remaining equipment over a 3 to 6 month period. Legal priority on liquidation: (1) reasonable wind-down costs, (2) LPs pro-rata, (3) DualMint operational claims, (4) DualMint equity. LPs recover ahead of DualMint corporate claims.
Alternative exit routes (designed / under evaluation, not yet live):
- Secondary-exit venue. We are exploring immediate-exit options; the current lean is a batch auction plus tranching via a third-party AMM. Designed and under evaluation, not deployed; expected to activate around the ~$30M TVL threshold. Redemption (30-day standard / 120-day max SLA; no mandatory lockup) remains the primary exit path.
- Morpho borrow against sUSDm. Leveraged-exit substitute without principal sale (post curator listing, under DD).
Throttle / pause logic before depletion (multi-tier gates, most-restrictive governs):
- Liquidity gate. Green ≥20% buffer = normal; Yellow 15 to 20% = pause boosted-early redemptions; Orange 10 to 15% = 60-day notice; Red <10% = 90 to 120 day max SLA.
- Asset-impairment gate. ≥10% vault in Stage 2+ → +30 days SLA; >20% → pause all redemptions pending Council review.
- NAV-impairment gate. >5% NAV drop → +14 days; >15% → Council convened, redemption gate review, potential structured wind-down (entering the depletion path above).
These gates are policy design; on-chain enforcement is codified at v1 launch (currently backend-tracked; see sh-4.16a). Standard SLA at full buffer is 30 days; 120 days max under stress. The vault does not promise instant redemption; the underlying assets are illiquid by design.
Redemption Priority: If redemptions are gated or delayed, how are they prioritized (FIFO, pro-rata, by tranche/class)? Are any investor classes or roles prioritized over others?
Priority structure (per the Vault Liquidity Risk Framework):
- Tier 1, base (flexible) depositors. No lockup. FIFO by request timestamp.
- Tier 2, boosted depositors at lockup maturity. FIFO by request timestamp within this tier.
- Within each tier: pro-rata fill if available liquidity is insufficient to satisfy all queued requests.
Tier 1 fills ahead of Tier 2. This rewards flexible depositors with first access to liquidity at the cost of forgoing the boost multiplier; boosted depositors trade redemption priority for higher yield weight.
Early redemption during lockup: boosted depositors may exit before maturity at lower FIFO priority and subject to an early-redemption penalty per Depositor Terms (in flight with Horizons; final penalty schedule will be codified pre-launch).
Class-of-shares prioritisation: none. Single-pool vault: all depositors hold the same sUSDm share class, all are last-loss across the loss waterfall. The only differentiation between depositors is base vs boosted lockup tier.
Operational mechanics: Council Operator wallet processes the redemption queue per the Vault Security Council Charter (bounded, cannot override automatic triggers). FIFO queue position will be visible on-chain via the queue contract at v1 launch; currently tracked in the backend redemption ledger.
Yield Conversion Policy: Are any rewards accrued converted to the base asset of the vaults?
Yes. The vault's base asset is USDC. Operator cash flow arrives in the distribution currency of each product (Arbitrum products in USDC, Peaq products in USDT) and is converted to the vault base asset (USDC) before recognition, so there is no non-base-asset accrual at the vault level.
Any cost of the USDT→USDC conversion is borne before recognition, so only net USDC reaches NAV (the conversion venue and slippage policy are specified in the vault's conversion path (Vault Smart Contract Spec)).
Depositor yield is not paid out as a separate reward stream; it accrues to sUSDm as price-per-share appreciation, denominated in the USDC base asset. There is no native non-USD asset accruing to depositors.
Rewards/Yield Management: Where are rewards held? How are they distributed to the vault? Are rewards distributed on an ongoing basis or in specific frequencies?
Today (marketplace level): distributions flow through the operator's marketplace contract directly to the NFT holder, monthly, in the product's distribution currency (USDC on Arbitrum, USDT on Peaq).
Designed for the vault (Machine Yield Index, upcoming): cash flow is received by the vault's asset ledger; the routing logic applies the waterfall (principal recovery, then processing fee, then yield). Recognised yield is retained in the vault and accrues to depositors as sUSDm price-per-share appreciation at the monthly epoch boundary (last day of month, 23:59 UTC); there is no separate cash distribution to vault depositors. The boost multiplier is applied through the index-based BoostRewardManager, so boosted positions accrue a higher per-share weight on the same monthly cadence. During accrual, USDC sits in the routing contract until epoch settle, then is recognised into NAV.
Reserve Models: Please provide any models, assumption documentation and supporting detail pertinent to how you evaluate potential risk, return, probability of default, or other relevant analytic metrics as they may apply.
What exists today (live inputs):
- Operator-level default scoring: operator-history weighting, telemetry anomaly scoring, and category baselines feeding the Asset Performance Index.
- Loss-given-default framework: recovery via SPV step-in and reassignment to a replacement operator under a 14 to 45 day SLA target.
- Cash flow projection: epoch-level NAV, principal recovery curve, processing fee accrual.
- Buffer adequacy: buffer-zone gate per the Vault Liquidity Risk Framework: Green ≥20% / Yellow 15-20% / Orange 10-15% / Red <10% of TVL.
A calibrated probability-of-default × loss-given-default model is a build-plan item, not yet deployed: there is no live operator default to anchor recovery rates against (see qa-offchain-risk-04).
Build plan: as default data accumulates, the models migrate from assumption-based to empirical. Phase 2 (vault live, 50+ assets): empirical recovery curves from first real default events; Phase 3 (200+ assets): pre-default telemetry signals; Phase 4 (500+ assets): a full survival model.
Stress test math exists in the Operator Default Playbook (waterfall scenarios) and the Senior Capital Investment Framework (yield + recovery scenarios). A curator-format stress test deliverable (PD × LGD × exposure across severity scenarios) is in development and available on request.
Reserve Monitoring: What tools and processes exist to monitor ongoing risks and the sufficiency of reserve requirements? Do any committee or external experts contribute?
Marketplace monitoring (operational today across 1,310 live assets): IoT telemetry ingest from peaq Machine ID, payment timeliness scoring, operator-level revenue-vs-forecast variance, equipment GPS, IoT connectivity heartbeat, and insurance certificate validity tracking. Operator Watchdog escalation per Operator Default Playbook: yellow flag → automated alert within 1 hour to Operations + CFO; red flag → CFO + Operations Lead within 15 minutes; Stage 3+ severity → 72-hour LP communication. Risk register maintained quarterly.
Vault Guardian System (designed; deploys with vault contracts at launch, targeted at vault launch): the architecture specified in the Vault Guardian System Blueprint (available on request under NDA) is an autonomous monitoring and response layer for the Machine Yield Index: six agents (Liquidity Guardian, Operator Watchdog, Telemetry Verifier, Exit Queue Manager, Risk Aggregator, Alert Dispatcher), 20 metrics, 24/7 automated zone-gate enforcement (Green / Yellow / Orange / Red per the Vault Liquidity Risk Framework). The Blueprint is documented today; deployment is concurrent with vault smart contracts.
Committee and external oversight: today, risk monitoring is run internally by Operations and the CFO. There is no external or independent oversight engaged yet. The following independent checks are chartered but not yet engaged:
- Council Seat 5: independent auditor / depositor representative; external view on Council decisions.
- LP Advisory Committee: chartered at $50M TVL per the Legal Structuring Memo.
- Independent risk consultancy: quarterly review engaged from Phase 2 (vault live + 50+ assets).
Escalation SLAs above (1 hour / 15 min / 72 hour) are process targets per the Operator Default Playbook.
Reserve Transparency / Reporting: How are reserves aggregated and reported on? What frequency? By whom?
Reporting framework documented per the Operator Default Playbook; layers (1) and (2) below are operational at vault launch (the vault is not live yet). Marketplace distribution receipts are verifiable on-chain today (see "Today (marketplace level)" below).
(1) Monthly LP report (institutional-grade), operational at vault launch. Full impact disclosure, yield-gap explanation, asset-count in cure / reassignment status, NAV reconciliation, buffer level by zone. (An insurance adequacy ratio will be added once the Tier 2 performance bond is bound; none bound today.) Format designed to fund-administrator standards. Frequency: monthly at epoch close.
(2) Public dashboard, in build (6-week target), live at vault launch. Aggregate metrics: live asset count, total deployed capital, distribution history, current buffer zone, NAV trend. No operator identification (operator privacy per Operator Default Playbook).
(3) Stage-driven escalation reporting. Weekly during Stage 2+ events; same-day public disclosure within 72 hours of Stage 4 (Critical) events per Operator Default Playbook.
Today (marketplace level): the asset registry is maintained internally (serial number, location, operator, payment history, IoT data per Underwriting Data Requirements). Distribution receipts are published on-chain per asset. Arbitrum-based products pay in USDC, Peaq-based products in USDT, each independently verifiable on the relevant block explorer. The 16-month distribution record spans the established marketplace lines.
By whom: DualMint Operations + CFO author; Council review is a launch-gated control (Council not yet seated). Independent BVI fund administrator engagement is a planned Phase 2 milestone tied to TVL scaling; TVL trigger and provider selection under finalisation per the Legal Structuring Memo.
Reserve Reconciliation Process: Who is responsible for reconciling reserves with reported balances, and what tooling or oversight exists?
Proven methodology (live today). The reconciliation method is published as the Vertriqe (AirUp operator) full on-chain reconciliation case study, Appendix A (Vertriqe reconciliation):
- 9 transactions, July 2025 to January 2026, every hash independently verifiable on Arbitrum.
- Payouts accrue and increase every month as monthly yields are processed; the case study is a point-in-time snapshot of a relationship that keeps distributing.
- Full dispute resolution documented (Tx 4 + Tx 6 disputed; Tx 8 settled).
Aggregate proof sits above the single case: $52,602.60 distributed to date and growing monthly, every payment verifiable per transaction on-chain. This is the operational template now being standardised across marketplace operators (rollout ongoing; Vertriqe is the first operator on the template, with the remaining established lines being migrated).
The ±10 to 15% tolerance band. Revenue is not recognised in NAV unless the two sources (IoT telemetry and operator-system API) agree within ±10 to 15%. The band absorbs timing and rounding differences between telemetry cycle counts and POS/payment-rail settlement (e.g. a cycle logged at machine close vs. its payment clearing in a later batch); a tighter band would reject legitimate revenue on timing alone. Anything outside the band is flagged and not recognised until reconciled.
Vault-level reconciliation (post-launch). NAV is recalculated at each monthly epoch boundary; the vault's book-value ledger aggregates per-asset book value from the asset ledger; the routing contract logs every receipt and reconciles it against the same 2-source cross-reference (per Vault Smart Contract Spec).
Ownership and tooling. Owner: CFO (operational reconciliation). Council Seat 5 (independent auditor) review is a launch-gated control at quarterly cadence (Council not yet seated). Tooling: internal asset ledger + the vault's on-chain book-value ledger + Vertriqe-style transaction-level on-chain reconciliation. Independent third-party attestation by a BVI fund administrator is a planned Phase 2 milestone tied to TVL scaling. Provider selection and threshold under finalisation; the same firm is targeted for reporting attestation in a single integrated workflow.
Historical Drawdowns: What is the historical drawdown profile of the underlying collateral or reserves? What conditions contributed to these drawdowns and could cause them again?
Live track record (marketplace; established lines, 16 consecutive months since May 2025; 1,310 positions originated):
- Zero operator defaults.
- Zero principal losses.
- Zero restructurings.
- Realised drawdown: 0%.
- Operator-level disruption in two cases (Vertriqe payment dispute Tx 4/6, settled via Tx 8; see Appendix A, Vertriqe reconciliation). No LP impact.
Stress test scenarios (qualitative, per Operator Default Playbook): the Layer 1 recovery/reassignment outcomes below are modeled (recovery is not yet live-tested, see qa-offchain-risk-04).
| Scenario | LP impact |
|---|---|
| Single asset 100% loss | Layer 1 asset recovery & reassignment absorbs entirely (repossession + reassignment, no cash drawn). No LP impact. |
| Modest portfolio default | Layer 1 recovery + Layer 2 Origination Reserve absorb. No LP impact. |
| Elevated portfolio default | Origination and Solvency Reserves drawn; yield reduced for a small number of cycles before principal is exposed. |
| Severe portfolio default | Once the non-depositor layers are exhausted, structured wind-down begins and depositor principal is exposed. |
What is funded and in place today: of the six loss-waterfall layers, three are in place now: recovery rights (Layer 1), the Origination Reserve (Layer 2), and the Solvency Reserve (Layer 3), plus operator-carried Tier-1 asset insurance. The Tier-2 performance bond, the Stop-Gap Liquidity Facility, and RFQ liquidation are being arranged and are not yet binding.
We have not yet built a calibrated probability-of-default × loss-given-default model that would quantify the LP-impairment threshold, because there is no live default to anchor recovery rates, so we do not state a specific portfolio-default percentage at which principal is impaired. A curator-format quantitative stress deliverable will be produced as Phase 2 empirical recovery data emerges.
On concentration: most onchain yield products are single-source by construction (one instrument class, one borrower-risk type, or one machine type), so their diversification is across instances of a single failure mode. DualMint finances multiple categories with operationally independent revenue drivers, so early concentration is a ramp artifact compressing monthly toward the target framework, not a structural ceiling.
Conditions that could trigger losses:
- Macro recession driving multiple operator defaults concurrently.
- Category-wide regulatory event (e.g., machine licensing change in core markets).
- Insurance carrier failure (Tier 1 asset cover is operator-carried and in force; Tier 2 performance bond via YAS/Zurich is in discussion, no provider bound).
- Smart-contract exploit (mitigated by launching on Concrete's independently audited ERC-4626 stack; a separate smart-contract / custody / crime insurance program is being explored, distinct from the loss-waterfall layers).
Duration & Volatility: Please describe the duration and volatility characteristics of the underlying reserves / assets.
Asset duration:
- Underlying assets are physical equipment with 3 to 7 year economic life.
- Self-amortising principal recovery: modeled at 40 to 50% by Month 12, full recovery 24 to 36 months by category (per the Senior Capital Investment Framework; modeled curve, not yet validated against a full vault cycle).
- Weighted-average asset duration at portfolio level: 18 to 24 months.
- Asset-level depreciation schedules documented per category in the Underwriting Data Requirements.
- Vault distribution cadence: monthly epoch (last day of month, 23:59 UTC).
Volatility characteristics (utilisation volatility, not market volatility):
The cash flow drivers (machine usage cycles, transaction counts, contract revenue, robotics output) are physical operational metrics. They do not correlate to crypto markets, equities, or rate moves. The relevant volatility is whether machines are used, not how markets are pricing risk.
Empirical evidence (marketplace; seasoned machine lines, 16 consecutive months):
- Gross asset yields have run in the 15 to 25% historical range across categories (per Senior Capital Investment Framework). This is gross asset yield before vault buffer drag; the vault's net effective yield to depositors targets 13 to 15%.
- Machine usage counts hold across recession and expansion. The primary machine category shows a ~95% 5-year survival rate vs 51% for small businesses overall (BLS).
Currency:
- Cash flow denomination: USD (USDC at the vault level).
- Operator pricing in local currency where applicable; FX-hedging at the SPV level is designed, not yet operational.
Forward volatility model (not yet published; targeted pre-launch):
There is no published volatility profile yet. We intend to produce a formal institutional-grade profile per asset category: 12-month trailing coefficient of variation of monthly cash flows, drawdown distribution, and autocorrelation structure. The planned method: pull the 12-month per-asset cash flow ledger from the vault's asset ledger and Vertriqe reconciliation data; compute CV per category and per operator; Monte Carlo overlay for forward 12-month NAV volatility under historical-bootstrap and stressed scenarios. The empirical CV by category will be available once published.
Liquidity: Please describe the secondary liquidity of the underlying reserves / assets.
Underlying physical equipment is illiquid, and we state that plainly; it is the structural reason for the 30-day standard / 90-day stressed / 120-day maximum redemption SLA. Secondary liquidity for the equipment itself exists in established resale channels: each financed machine category has working equipment-market and small-business sale markets. On operator default, the recovery path is reassignment to a replacement operator (14 to 45 day SLA target; channels and mechanics: Collateral & Strategy: Bad Debt Management); recovery rates are not yet measured, as there has been no live operator default to date.
Vault-level secondary liquidity (the Machine Yield Index is upcoming, not yet live): redemption is the primary exit path (30-day standard / 90-day stressed / 120-day maximum SLA; no mandatory lockup). A secondary venue is designed and under evaluation. We are exploring immediate-exit options, with the current lean toward a batch auction plus tranching via a third-party AMM; it is not yet live, and is expected to activate around the ~$30M TVL threshold. Morpho borrowing against sUSDm (post curator listing, under DD) is an additional route under evaluation. The honest framing in the Vault Liquidity Risk Framework holds: the underlying assets are illiquid and the vault does not promise instant redemption. Architecture and mechanics are in the GitBook docs.
Oracles / Price Feeds: What price feeds/oracles are utilized? Are there any policies or standards for oracle utilization?
Oracle layer: DualMint is a member of the Chainlink BUILD program, and the Chainlink oracle integration is live. Revenue verification runs on the 2-source IoT + operator-API cross-reference described below.
Revenue verification (2-source cross-reference per Vault Smart Contract Spec):
- IoT telemetry: machine-generated cycle counts via Peaq Network.
- Operator-system API access: POS and payment-rail data pulled directly from operator infrastructure.
- Consensus rule: both sources must agree within ±10 to 15% tolerance. Revenue that cannot be cross-referenced is not recognised in NAV.
- Single-source revenue is rejected.
Attestation cadence: soft (weekly), hard (monthly), full audit (quarterly). Asset Performance Index (API) re-scoring runs monthly from the same data sources.
Reserve drawdown gating: drawdown from the ring-fenced Origination Reserve (Layer 2 of the loss waterfall) to absorb operator-level losses requires 2-source oracle consensus (per Operator Default Playbook). No single-party authority can drain the reserve.
Forward additions: the Layer 4 insurance tier pairs operator-carried asset cover (Tier 1, in force) with a performance bond (Tier 2, via YAS/Zurich, in discussion, no provider bound); once Tier 2 is active, claim-driven reserve replenishment will run on the same 2-source consensus model.
Offchain Risk
How offchain risk decomposes, how it is observed onchain, and what remains unproven.
What happens when an operator defaults, and how should I understand offchain risk?
Offchain risk is the part of the picture an allocator cannot self-audit onchain. The way to underwrite it is to decompose it, because a named risk is priceable and a black box is not. It breaks into four questions: will the machine get used, will the operator run it and remit, if an operator fails can the asset be recovered, and does regional revenue hold up.
The whole model turns on the first one. DualMint underwrites usage risk, not credit risk. It is not a bet that a borrower repays a loan. DualMint owns the machine, and the machine earns whether or not any single operator stays. That changes what a default is: when an operator fails, DualMint does not chase a debt, it repossesses the machine and reassigns it to a new operator, and the cash flow resumes. Elsewhere a default is a write-down. Here it is a repair.
For a vault depositor this is sharper still. In the pooled vault a depositor does not hold one machine, they hold a slice of the whole book. An operator failure shows up as a smaller distribution for that period while the machine is reassigned, and diversification absorbs the rest. Concentration limits cap any single operator at 15% and any single asset at 10% of the book, so no one failure can dominate the pool. Yield flexes down gracefully under stress long before principal is ever in question.
For depositor principal to be touched, two independent buffers both have to be overwhelmed. First, the diversification: losses would have to be broad and correlated across the entire book, a large fraction of operators failing at once rather than one or two. Second, the loss waterfall: six layers of non-depositor capital, beginning with machine recovery and reassignment at no cash cost, then two committed cash reserves, then insurance and liquidity facilities, all stand in front of depositor principal. And because each asset amortizes as it runs, the amount at risk shrinks every month on its own.
The result is a clean separation. Operator failures cost yield. Principal is untouched unless the whole diversified book fails through six layers of non-depositor capital first.
What is the offchain risk in DualMint, and how should an allocator think about what they are underwriting?
Short answer: "Offchain risk" is not a single black box. It decomposes into four named, separately-priceable components: usage, operator, recovery, and macro/geography. Naming them is the point: a decomposed risk is underwritable, a monolithic "offchain" label is not. Each component carries a named mitigant, with the residual gaps on recovery and macro consolidated in the dedicated gaps answer (qa-offchain-risk-04).
Most questions about offchain risk are really a legibility question, not a magnitude question. Onchain risk is self-auditable: an allocator can inspect the contract, the TVL, the oracle, and the redemption logic without asking us anything. The physical asset base cannot be inspected that way, so it can feel like a bet placed on trust. It is not. The offchain layer is instrumented and decomposable, and this section walks each component in the terms an IC already uses.
The four components of offchain risk
| Component | The question being underwritten | Mitigant / status |
|---|---|---|
| Usage risk | Will the machine generate cash flow? | The primary thing underwritten. Observed monthly via IoT telemetry (cycle counts, uptime, revenue). Diversified across categories with concentration limits (10% single asset / 15% single operator / 50% single sector). |
| Operator risk | Will the operator run the asset and remit? | The bankruptcy-remote SPV holds legal title to the equipment; the operator holds a revocable licence, posts no cash, and is swapped rather than written off on failure. DualMint holds contractual step-in and repossession rights via the Operator Security Agreement (OSA). Origination Reserve (3% of asset value) and Solvency Reserve (3% of cash flow) are committed first-loss cash. |
| Recovery risk | If an operator fails, can the machine be repossessed and reassigned at or above book? | Recovery runs 70 to 95% via reassignment and 50 to 80% via liquidation, with financing sized below replacement value; the SPV holds title and repossesses and reassigns under the OSA. Live-default recovery economics are consolidated in the gaps answer (qa-offchain-risk-04). The Tier-2 performance bond is in discussion through YAS/Zurich. |
| Macro / geography risk | Does regional SME revenue hold up? | The asset base is concentrated in SEA / APAC operating markets. This is the one exposure most institutional books do not currently measure. It does not correlate with credit spreads or equity markets, but it is a real exposure and is disclosed, not buried. |
Why decomposition is the honest frame
Every other yield product an allocator holds carries offchain or off-model risk somewhere: a trading strategy's execution and counterparty layer, a private-credit book's borrower behaviour, a trade-finance facility's shipment performance. The difference is not that DualMint has offchain risk and they do not. The difference is that we name ours at the component level and attach a mitigant or an honest gap to each.
Usage and operator carry working, funded mitigants; recovery and macro carry disclosed gaps, consolidated in the dedicated gaps answer (qa-offchain-risk-04). An allocator who can see the seams underwrites faster than one handed a single confident number.
The related answers cover how each component is observed (telemetry-as-oracle), how the overall profile compares to onchain products already in an allocator's book, and the residual gaps consolidated in qa-offchain-risk-04.
How is offchain risk observed and made legible: what is the offchain equivalent of an oracle?
Short answer: IoT telemetry is the offchain oracle. The reason onchain risk feels safe is observability: an allocator can watch it in real time. DualMint points the same observability at the physical asset: machine-level cycle counts, uptime, and revenue, reconciled monthly. The asset base is not blind; it is instrumented. And it degrades gradually and visibly, which a market position does not.
Telemetry as the oracle layer
An onchain oracle exists to make an off-model fact legible to a contract. DualMint's telemetry layer does the same job for the physical asset: it makes the machine's operation legible to the underwriting and to the depositor.
- What is measured: cycle counts, transaction counts, uptime, and revenue per asset, captured via API access and the Peaq Machine ID layer, not self-reported operator statements.
- Cadence: reconciled monthly, on the same monthly epoch the vault settles on. This is materially more frequent than the quarterly, lagging, self-reported financials that a private-credit book underwrites against.
- Cross-check: telemetry cycle counts are reconciled against operator revenue reports, so reported income has an independent physical counterpart. This feeds the Asset Performance Index (0 to 100), which gates origination, monitoring intensity, and vault eligibility.
The failure-axis: gradual and observable, not sudden and correlated
The load-bearing distinction for a risk framework is not yield correlation. It is failure mode.
- Market collateral fails through sentiment. It reprices fast, with no warning, and it reprices together across a book. A tokenized bond, an equity position, or a trading strategy can gap overnight on an exogenous event.
- Operational collateral fails through utilisation. A machine's usage declines gradually, and that decline is visible in telemetry months before it becomes a cash-flow shortfall. Utilisation dropping below benchmark triggers a review window under the operator playbook before any default occurs.
That observability window is a risk-management tool, not a liability. It is the offchain analogue of watching a health factor drift toward liquidation, except the drift is measured in months of machine data, not seconds of price action.
What this means for the allocator
The instinct that "offchain = I can't see it" is the gap this closes. The allocator does not get a market price on the asset, because the asset does not have one and is not supposed to. That is the source of the non-correlation. What the allocator gets instead is monthly machine-level operating data on the exact thing being underwritten. Legibility comes from instrumentation, not from a ticker.
How does offchain risk compare to the onchain products I already hold: trading strategies, tokenized stocks and bonds, private credit, trade finance?
Short answer: Same risk family, different failure mode, more real-time data than the comparable. An allocator holding private credit or trade finance already underwrites offchain operator and geography risk on quarterly, self-reported statements. DualMint carries the same family of risk with monthly machine-level telemetry. The point is not that DualMint is lower-risk; it is that "offchain is a black box" is inconsistent with what is already in most institutional books.
Where each product's risk actually lives
| Product | Core risk being underwritten | Failure mode | Data cadence | Correlation to markets |
|---|---|---|---|---|
| Trading strategies (basis, delta-neutral) | Strategy, execution, counterparty | Fast, opaque, can gap overnight | Real-time price, limited fundamentals | Funding-rate and market dependent |
| Tokenized stocks / bonds | Market price risk | Immediate repricing | Market price | Fully correlated |
| Private credit | Borrower creditworthiness | Binary default, backward-looking | Quarterly, self-reported | Compresses with credit spreads |
| Trade finance | Counterparty + performance + geography | Lumpy, document-dependent | Per shipment / milestone | Partially correlated, geography-exposed |
| DualMint | Usage + operator + geography | Gradual, observable, recoverable via reassignment | Monthly machine-level telemetry | Uncorrelated to rates, spreads, equities |
The two honest reads of this table
1. The risk family is not new to the allocator. Trade finance and private credit are the closest analogues: both underwrite an offchain counterparty operating in a specific geography, and both do it with less frequent, less independent data than DualMint provides. An allocator who is comfortable holding those is already comfortable with the category of risk. What is genuinely new is the observability (monthly telemetry versus quarterly statements) and the recovery mechanism (reassign the machine versus pursue the borrower).
2. The failure mode is the diversification argument, not the yield. The strongest reason to hold DualMint next to the rest of a book is not that it yields more. It is that it fails through a different axis. When market collateral reprices together on sentiment, an operational asset's utilisation does not move with it. A rate cut does not reduce machine utilisation. For portfolio construction, the relevant question is not "does this yield move with my book?" but "does this blow up when everything else in my book blows up?" The answer is structurally no.
What DualMint does not claim in this comparison
- It is not claiming to be lower-risk than a tokenized treasury. It sits above treasuries on the risk/return curve: different product, higher operating margin, higher operational risk.
- It does carry a regional operator-macro exposure (SEA / APAC) that most books do not currently measure. That is a real line item, disclosed in the gaps answer (qa-offchain-risk-04), not netted away here.
- The recovery advantage (swap the operator, keep the machine) is a structural feature of title-retention; its live-default economics are covered in the gaps answer (qa-offchain-risk-04).
What offchain risk is unproven or unmeasured: where are the honest gaps?
Short answer: Four things. The recovery mechanism is untested in a live default. The Tier-2 performance bond is not yet bound. The regional operator-macro exposure is real and mostly unmeasured by institutional books. And the vault itself is not live, so the aggregated redemption mechanics are unproven. A gap that is disclosed before it is discovered is easier to underwrite than one that surfaces later.
The four honest gaps
1. Recovery is untested. The model's central claim is that a failed operator is swapped and the machine keeps earning, with 70 to 95% recovery via reassignment. That is a design target. There have been zero defaults and zero reassignments across the track record to date, which means the repossession-and-reassignment path has never been exercised in production. The mechanism is contractually enabled (step-in rights, the SPV's retained legal title, sub-replacement-value financing) but not demonstrated. This is the single most important thing to underwrite honestly: the track record proves the assets pay, not that recovery works.
2. The Tier-2 performance bond is not bound. Layer 4 of the loss waterfall has two tiers. Tier 1 (commercial asset insurance on the physical machines: theft, fire, damage) is operator-carried and in force. Tier 2 (a performance bond covering operator non-performance, priced on non-performance rather than asset residual value) is in discussion through YAS (Hong Kong MGA, licence FA2648), carried by Zurich; no provider is bound. Until it binds, treat Tier 2 as planned, not guaranteed. The Stop-Gap Liquidity Facility (Layer 5) is similarly an agreement in progress, not yet executed.
One market fact belongs next to this gap: true payment-default insurance (an insurer covering "the operator stopped paying") does not exist as a live product from a traditional carrier, and none of the established tokenized-credit protocols (Maple, Centrifuge, Clearpool) carries third-party non-payment cover either; the toolset used market-wide is first-loss capital plus legal recourse through an SPV, which is the structure DualMint runs. DualMint's Tier 2 takes a different route to the same exposure: a performance bond, a surety-market instrument rather than an insurance policy, that pays out on the operator's non-performance rather than on the resale value of the repossessed asset. It is in discussion through YAS (Hong Kong MGA, licence FA2648), carried by Zurich, and is not yet bound. This gap is market-wide rather than DualMint-specific, and the load-bearing protection is sizing the first-loss layers, a capital-structure discipline the category's own default history confirms (see the comparable-protocol precedent answer in this section).
3. Regional macro exposure is real and mostly unmeasured. The operating asset base is concentrated in SEA / APAC markets. Regional SME revenue correlates to regional macro conditions. The yield is genuinely uncorrelated to credit spreads and equity markets, but it is not uncorrelated to a downturn in its operating geographies, and most institutional risk books do not currently carry a factor that measures this. It is a real exposure. We disclose it rather than fold it into a blanket "zero correlation" claim, which would be an overstatement.
4. The vault is not live. The 16-month track record and the $52,602.60 distributed to investors are from the 1:1 marketplace, where individual machine-backed positions distribute monthly. The Machine Yield Index vault is upcoming, not live. That means the aggregated redemption mechanics (the 30-day standard / 90-day stressed / 120-day maximum SLA, the liquidity buffer behaviour under redemption pressure, and vault-level NAV reconciliation) are designed but unproven at scale. Present-tense claims about live vault performance are not available yet.
Why we lead with the gaps
The offchain layer is where an allocator's instinct is to assume the worst, because it cannot self-audit it. Surfacing the four gaps early does two things: it lets the IC price the real residual risk instead of a feared one, and it makes the mitigated components (usage observability, operator swappability, funded reserves) more credible by contrast. A book that discloses its unproven layers is easier to hold than one that presents every layer as proven.
The mitigated components and the comparison to onchain products already in an allocator's book are covered in the related answers.
How have comparable protocols absorbed real defaults, and what does that precedent imply for the structure?
Tokenized credit has now produced enough live defaults to show which protections actually work. Two events carry the lesson:
| Protocol | Default event | How the loss landed |
|---|---|---|
| Maple Finance | Dec 2022: Orthogonal Trading, $36M across 8 loans (~30% of active loans) | First-loss "Cover" was thin (0 to 3% of pool) and was exhausted immediately. LPs took direct haircuts; recovery ranged roughly 17 to 80% by pool, with final Orthogonal recovery near 20%. |
| Centrifuge | Codex Finance default | The junior (TIN) tranche absorbed the loss as designed; the senior (DROP) tranche was largely protected. |
The pattern across both is the same: the fix is sizing, not insurance. Where properly sized first-loss capital existed before the loan was written (Centrifuge), it did exactly its job. Where it was thin (Maple), depositors ate the loss and any protection arrived after the fact, at the protocol's discretion. Neither protocol carried third-party non-payment insurance, because no carrier sells it (see the honest-gaps answer in this section); first-loss capital and legal recourse were the entire defence, so their adequacy decided the outcome.
How DualMint's structure maps against that precedent:
- First-loss capital sits in place before vault launch, funded ahead of any loss. The Origination Reserve and Solvency Reserve are funded, ring-fenced DualMint cash, in position ahead of depositor capital (sizing: Financial: Reserve & Insurance Mechanisms; drawdown order: Collateral & Strategy: Loss Waterfall).
- Exposure shrinks by design. The financing self-amortizes, so exposure-at-default falls every month, and a mid-life default lands as a residual balance, not the full ticket. Reserves therefore sit against a smaller number than the headline book (the worked arithmetic, including a full single-operator failure scenario, is in the liquidation answer in Risk Management).
- Concentration caps bound the correlated case. 10% single asset, 15% single operator, 50% single sector cap how much of the book any one failure can reach, the same variable that decided the Maple outcome.
The honest limit of the comparison. DualMint has made the structural choices that held elsewhere: pre-funded first-loss in position before launch, amortizing exposure, concentration caps. Those choices are the ones the precedent above proves out. But the precedent is borrowed. Maple's and Centrifuge's numbers come from their own live defaults; DualMint has not yet had one. The structure is sized the way the surviving structures were sized. Whether it holds the same way stays unproven until DualMint has a live default of its own (full disclosure in qa-offchain-risk-04).
Legal & Investor Protections
Legal entity, regulatory regime, investor rights, recourse, and compliance.
How is DualMint's legal architecture structured, including the use of SPVs, contracts, and investor protections across jurisdictions?
DualMint's legal architecture is designed so that investors hold enforceable rights to cash flow, not physical property, and so those rights are insulated from operational and jurisdictional risk. The structure differs between the marketplace phase (live) and the vault phase (upcoming).
Marketplace phase (1:1 NFT, live)
The marketplace does not fractionalize assets. Each asset is represented by a single NFT that carries machine-specific legal provenance (serial number, location, and category), anchoring the claim to one specific physical machine. The NFT itself is the legal instrument: it binds the operator and the token holder under attached terms and conditions covering revenue share, payment cadence, default events, step-in rights, and reassignment. Performance is validated by IoT telemetry; payouts settle in USDC for Arbitrum products or USDT for Peaq products on the relevant chain.
This avoids both fractionalization (each NFT represents one whole asset) and off-chain wrappers (the agreement is on-chain, attached to the NFT, with the serial number making the claim verifiable against the underlying machine).
Vault phase (Machine Yield Index, upcoming)
The vault uses a different legal setup: a bankruptcy-remote SPV owns the assets and leases them to the operator for the term of the deal, structured as a lease-to-own (finance lease). At the end of the term, equipment ownership transfers to the operator. The lease-to-own structure (rather than direct lending) is what makes step-in enforceable on telemetry-triggered underperformance during the term.
Four entities carry this: DualMint Holdings, Inc. (Delaware parent), Boring Vault Corp (Panama, operating entity), DualMint Ltd. (BVI, the asset-holding SPV), and DualMint Foundation (Panama PIF, the vault counterparty and sUSDm issuer). Capital flow is one-directional: LPs → PIF → loan → Boring Vault Corp → SPV → operators → cash flows back up the same path. Because the SPV owns the asset rather than lending against it, telemetry-triggered underperformance gives it authority to suspend the operator and repossess or reassign the machine without judicial process, under the Operator Security Agreement (OSA). Full entity roles, governing documents, and counsel are detailed in Legal Structure & Documentation.
Cross-cutting protections
DualMint avoids fractionalizing physical assets or issuing off-chain securities through opaque wrappers. Investors hold enforceable claims validated by machine telemetry. The legal design is reinforced by operator KYB at onboarding (Blockpass); title retention by the bankruptcy-remote BVI SPV, which owns each machine and holds contractual step-in and repossession rights under the OSA (title retention plus step-in, rather than filed liens, since the asset-holding SPV sits outside the US filing system); and micro-insurance partners (in development) underwriting operator-specific risks such as theft, equipment downtime, and environmental damage.
Depositor terms and DualMint-side agreements are governed by Panama law, with the asset-holding SPV's constitutional documents under BVI law. The applicable AML/CFT and data-protection regime is being confirmed by Panama counsel.
This structure gives investors the economic benefit of operational control without holding physical assets directly. The full legal architecture and entity diagram are in the GitBook docs.
Legal Structure & Documentation: Please describe the full legal structure of the project (e.g. OpCo, DevCo, Foundation, DAO, SPVs). What are the key governing documents (e.g. Articles, bylaws, operating agreements, token terms, protocol terms of use, subscription documents, side letters) and how do they interact?
Four entities, each with a defined role (canonical detail in the GitBook docs):
DualMint Holdings, Inc. (Delaware): parent holding company. Holds equity / cap table, IP, the US team, and partnerships. It receives equity raises and has no direct role facing depositors. Governing documents: Certificate of Incorporation, bylaws, stockholders agreement, employee equity plan.
Boring Vault Corp (Panama): operating entity. Runs operations and treasury, borrows from the Panama PIF, and deploys capital into operators (asset title held in the BVI SPV). Governing documents: Articles of Incorporation, board resolutions, Operator Security Agreements with each operator (OSA template drafted; first execution with Vertriqe targeted pre-launch).
DualMint Ltd. (BVI): asset-holding SPV. Holds legal title to the equipment on a title-retention basis; the operator holds a revocable licence to operate, and DualMint holds contractual step-in and repossession rights under the Operator Security Agreement (OSA). The SPV is bankruptcy-remote from the operating entity and is the enforcement vehicle on operator default. Single SPV now; segregates into one SPV per asset class as the portfolio scales. Governing documents: M&A, board resolutions, Asset Holding Agreements with Boring Vault Corp.
DualMint Foundation (Panama PIF): ownerless Private Interest Foundation, the vault counterparty, and sUSDm issuer. Receives LP liquidity and lends it to Boring Vault Corp. Capital flow: LPs → PIF → (loan) → Boring Vault Corp → operators → cash flows back up. An independent director on the Foundation Council provides external oversight. Governing documents: PIF Charter, Foundation Council instrument, Loan Agreement with Boring Vault Corp. (The HK entity was wound down in May 2026 and is not part of the structure.)
Council multisig (Gnosis Safe 3-of-5) is designed to operate at the Boring Vault Corp layer and hold admin authority over the vault smart contracts once deployed, with all 5 signers using air-gapped signing. It is not yet deployed and does not currently govern or hold any depositor funds; see Key Management for status. The Vault Security Council Charter is available on request under NDA.
A stop-gap liquidity facility is in discussion (no signed agreement); targeted mid-July 2026.
Counsel (scope split confirmed 2026-06-23):
- Pacifica Legal (Panama; Edgar Young, edgaryoung@pacifica.legal), lead counsel for the issuer + operating entity (Boring Vault Corp) and the PIF: PIF setup, Boring Vault Corp governance, and ongoing Panama regulatory matters.
- Horizons Law (general + US; Haroldo Granados, haroldo@horizonslaw.io): engagement letter signed for US matters and cross-entity intercompany agreements.
- BVI counsel: scoped to the asset-holding SPV and its collateral perfection only.
Key documents in flight (drafted pre-launch, executed ahead of vault launch):
- Delaware ↔ Boring Vault Corp Services Agreement (Horizons)
- Boring Vault Corp ↔ BVI SPV Asset Holding Agreements (Horizons)
- Panama PIF ↔ Boring Vault Corp Loan Agreement (Pacifica Legal + Horizons)
- Depositor Terms (vault subscription document): Horizons; first draft circulated for counsel review
Dispute Resolution, Governing Law & Jurisdiction: What is the governing law for your core agreements and protocol terms? What is the venue and mechanism for dispute resolution (e.g. courts of a specified jurisdiction, arbitration institution and rules, on-chain dispute mechanisms)? Are there any mandatory arbitration or class action waiver provisions?
Governing law and dispute resolution defined in Depositor Terms 10 (drafted, in counsel review with Horizons, targeted mid-July 2026) + Operator Security Agreement 15: Depositor Terms (LP-facing):
- Governing law: laws of the Republic of Panama (Panama specifics to be confirmed by Pacifica Legal).
- Dispute resolution: binding arbitration administered by the Singapore International Arbitration Centre (SIAC) under SIAC Arbitration Rules, seated in Singapore. Arbitral panel: 1 arbitrator for disputes <$5M, 3 arbitrators for ≥$5M.
- Emergency arbitrator option (SIAC Rule 30): for disputes requiring urgent interim relief (e.g., asset preservation, status quo orders during wind-down).
- Costs-to-prevailing-party clause: discourages frivolous claims.
- Consolidation clause: allows multiple LP claims arising from same underlying event to be consolidated into single proceeding.
- Small-claims fast-track for disputes <$50K: expedited single-arbitrator procedure, 60-day target resolution.
- Class action waiver: LPs waive class action rights; consolidated arbitration is the substitute mechanism.
- Carve-out: claims for injunctive / equitable relief to preserve assets pending arbitration may be brought in Panama courts (forum of the operating entity and PIF vault counterparty). Where enforcement reaches the asset-holding SPV's own collateral, BVI courts remain available for SPV-level relief. Note: governing law/forum resolved to Panama (operating entity Boring Vault Corp + PIF are Panama; arbitration seat unchanged). Panama specifics to be confirmed by Pacifica Legal.
Operator Security Agreement (operator-facing):
- Governing law: laws of the operator's home jurisdiction (US states, AU, UK, SG, etc. as applicable).
- Dispute resolution: courts of the operator's home jurisdiction OR arbitration administered by AAA/JAMS (USA), ACICA (AU), LCIA (UK), SIAC (SG), at DualMint's election.
- BVI counsel of record on standing basis (Horizons referral): ensures consistent BVI-side enforcement coordination.
Class action waiver + mandatory arbitration: yes (Depositor Terms 10.4). LPs waive right to class action; consolidation clause provides substitute mechanism for related claims. Subject to applicable jurisdictional limits (e.g., enforceability against US-domiciled LPs not relevant since US persons excluded per Depositor Terms 3.2).
On-chain dispute mechanisms: not used at launch. Considered future enhancement (e.g., Kleros, UMA optimistic oracle for low-value disputes), not in scope for vault v1.
Compliance, AML & Sanctions: What policies and controls exist for sanctions screening, AML/CTF compliance and monitoring of illicit activity (if any) in relation to user onboarding, counterparties, and treasury operations? Are any third-party compliance providers engaged?
Known readiness blocker (state it plainly): the only live AML/sanctions control today is Blockpass KYC/KYB screening at onboarding. There is no appointed MLRO and no transaction-monitoring program in production. For an institutional allocator this is a material compliance-readiness gap, not just a wording matter; the build-out items below are all targeted pre-vault-launch.
Live today:
- KYC / KYB on all depositors and operators: Blockpass (engaged, in production for marketplace onboarding). Institutional-grade identity verification, document authentication, liveness check.
- Sanctions screening at depositor onboarding: Blockpass-bundled OFAC / UN / EU / UK consolidated sanctions list check, PEP screening, adverse media review. Re-screening cadence at Blockpass: continuous monitoring with alert on list changes.
Pre-launch compliance build (not yet live):
- Wallet-address sanctions screening: pending engagement of Chainalysis Sanctions API or equivalent (under evaluation; Blockpass coverage of wallet-side OFAC exposure being verified; clarification targeted pre-launch). Closure targeted pre-launch: either Blockpass bundled coverage confirmed in writing, or a separate Chainalysis Sanctions API engagement.
- Geographic exclusions per Depositor Terms 3.2: US persons excluded; OFAC-sanctioned jurisdictions (Iran, North Korea, Syria, Cuba, Crimea, Donetsk, Luhansk) excluded; ongoing review of HRIF (high-risk and other monitored jurisdictions) per FATF.
- AML / CTF policy: under counsel-led drafting with Horizons. Closure targeted pre-launch. Will cover customer due diligence (CDD) tiers by risk, enhanced due diligence (EDD) triggers, suspicious activity report (SAR) procedures, recordkeeping requirements (5-year retention), and training cadence for all personnel.
- Money Laundering Reporting Officer (MLRO): designated person to be appointed alongside AML/CTF policy publication. Candidate identified internally; appointment targeted pre-launch.
- Treasury operations sanctions screening: not yet live. The designed control is per-transaction screening of DualMint treasury wallet addresses against sanctions APIs, plus pre-screening of counterparty wallets before any disbursement; this is under deployment and not in production today.
- On-chain analytics and ongoing monitoring: pending Chainalysis Reactor or TRM Labs engagement for transaction monitoring, suspicious activity detection, and investigation tooling. Decision targeted pre-launch.
Insurance, Indemnities & Limitations of Liability: Does any entity in the structure maintain D&O insurance, E&O insurance, cyber insurance or protocol-specific coverage (e.g. DeFi hack insurance)? What indemnities (if any) are granted to directors, officers, contributors or service providers, and how are these funded? What limitations of liability apply to users, LPs and institutional partners?
In force today: operator-carried Tier-1 asset insurance only. Every layer of cover that protects LP principal (the Tier-2 performance bond, D&O, E&O, cyber, and smart-contract/exploit cover) is being sourced or under evaluation, and none is bound. Tier-1 protects the operator's physical asset, not the LP's principal directly. State this plainly: the LP-protecting insurance layers are not yet in place.
Insurance posture:
D&O insurance: directors and officers cover for Delaware Holdings + Boring Vault Corp (Panama). Being sourced; not bound. Coverage scope sought: ordinary fiduciary duty claims; gross negligence / wilful misconduct excluded (consistent with indemnification clauses below).
E&O insurance (errors and omissions): for professional services exposure. Under evaluation; not standard for vault-protocol structure but considered for Operations + CFO functions.
Cyber insurance: under evaluation. Coverage for breach response + notification + business interruption.
DeFi-protocol-specific cover (smart contract hack insurance): under evaluation. This is a separate program, not a numbered layer of the canonical six-layer waterfall.
Asset Insurance (Tier 1 of the Layer 4 insurance tier of the canonical six-layer waterfall) per Operator Default Playbook: commercial cover on the physical machines (theft, fire, physical damage, loss), carried by the operator and in force at onboarding. The cover ratios, continuous-validity requirement, 30-day lapse cure, and loss-payee endorsement are drafted as OSA covenants in the unexecuted OSA template:
- Machine and robotics operators: 75 to 80% commercial cover required, set per category playbook. Operator must maintain insurance certificate validity continuously; lapse triggers an OSA cure period (30 days). Loss-payee is to be written into operator agreements on execution.
Performance Bond (Tier 2 of the Layer 4 insurance tier): covers operator non-performance, priced on non-performance rather than asset residual value. Placed through YAS (Hong Kong MGA, licence FA2648), carried by Zurich. In discussion; no provider bound. Not a guaranteed protection layer until bound.
Cash reserves backing the waterfall (Layers 2 to 3): the Origination Reserve (30% of the 10% origination fee = 3% of asset value) and the Solvency Reserve (30% of the 10% processing fee = 3% of monthly cash flow, building with every distribution, held in stablecoins). Drawdown is gated by 2-source oracle consensus (IoT telemetry + operator-system API per Operator Default Playbook); no single-party authority to drain.
Indemnities:
(a) Indemnity from operators to BVI SPV (OSA 10): operator indemnifies BVI SPV against losses arising from operator gross negligence, wilful misconduct, fraud, or breach of representations. Funded by enforcement against the equipment (the SPV's retained legal title plus OSA step-in and repossession rights; no cash escrow is posted) + operator's own balance sheet.
(b) Indemnity from Boring Vault Corp (Panama) to directors / officers / Council members: standard D&O indemnification per Operating Entity bylaws; ordinary fiduciary acts indemnified, gross negligence / wilful misconduct excluded. Funded by D&O insurance (being sourced) + the operating treasury as backstop.
Limitations of liability (Depositor Terms, in flight):
(a) LP-facing: direct damages capped at LP's deposit principal minus distributions received. Punitive / exemplary / consequential damages excluded.
(b) Smart contract risk: not excluded (separate smart-contract / exploit cover program, under evaluation); LP retains action against DualMint for gross negligence / wilful misconduct in code review or deployment.
(c) Force majeure: market risk on USDC depegging excluded; oracle outage compensated by 2-source cross-reference discipline (revenue not recognised in NAV unless both IoT telemetry and operator-system API agree).
(d) Third-party failures (Chainlink, M0, Vercel, AWS): excluded if DualMint exercised commercially reasonable diligence in vendor selection (documented in Infrastructure Inventory 15 credential rotation + vendor review cadence).
Change Management for Legal Terms: How can your legal terms (e.g. protocol terms of use, token terms, DAO governance docs) be amended? Who has the authority to approve changes (e.g. tokenholder vote, board resolution, foundation council)? What notice is given to stakeholders, and do investors have any opt-out or exit rights upon material amendments?
The change-management framework below is as drafted in the Vault Security Council Charter 4 + Depositor Terms 12 (in counsel review with Horizons; targeted mid-July 2026). The Depositor Terms are unexecuted, and the on-chain amendment-event emission described below is not yet implemented (target pre-launch), so the on-chain notification path is aspirational today. As drafted:
Categories of legal terms + change authority:
Vault Depositor Terms (LP-facing subscription contract):
- Material change (fee structure, redemption SLA, governing law, dispute resolution, loss waterfall) requires 30-day prior notice to all LPs + opt-out exit right (LPs may redeem at NAV during the 30-day window without penalty even if subject to lockup).
- Non-material change (clarifications, typo corrections, technical updates) requires 14-day notice; no opt-out trigger.
- Authority to approve: Council unanimous (3-of-5 multisig + Operating Entity board resolution).
- Notification mechanism: on-chain event emission + email to depositor of record + dashboard notification (codified in Depositor Terms 12.3).
Operator Security Agreement (operator-facing):
- Material amendment (events of default, remedies, fee structure, security interest scope) requires written agreement of both parties.
- Authority: Boring Vault Corp (Panama) board resolution + operator counter-signature.
- DualMint-side authority: the Council-bounded operator wallet (per Vault Security Council Charter 3.3) executes amendments within concentration limits; changes that cross those limits require full Council approval.
DAO governance (protocol governance token):
- At present this is framework only; there is no live on-chain governance.
- When governance goes live, tokenholder voting will follow the governance token terms (under counsel review). Quorum, voting threshold, and proposal process are documented in the tokenomics + DAO governance memo (drafting target 2026-Q3).
Side Letters (LP-specific):
- Bilateral amendment between DualMint and individual LP. Most-favoured-LP clause in standard Side Letter Template ensures parity downstream.
Smart contract upgrade:
- Logic upgrade requires Council 3-of-5 + 24-hour timelock per Vault Security Council Charter 3 (Admin role).
- Emergency pause/unpause via Guardian role (Vault Security Council Charter 3.2; immediate, 7-day expiry, Council vote to extend).
- Audited upgrade migration path documented in Vault Smart Contract Spec.
Notice mechanism per Depositor Terms 12.3:
- Primary: on-chain event emission (DepositorTermsAmended event) on the vault contract, verifiable, timestamped, immutable.
- Secondary: email to depositor of record (collected at KYC).
- Tertiary: dashboard banner notification on dualmint.com vault portal.
Opt-out / exit rights:
- Material amendments to Depositor Terms: 30-day opt-out window during which LPs may redeem at NAV without penalty regardless of lockup tier. Rollback: if >25% of LPs opt out within window, Council reviews amendment for withdrawal or modification.
- Non-material amendments: continued participation deemed acceptance after 14-day notice period.
Catch-all "material change" definition: any change that (i) alters fee structure, (ii) extends redemption SLA, (iii) modifies governing law or dispute resolution, (iv) alters loss waterfall priority, (v) changes counterparty entity, (vi) imposes new restrictions on LPs, or (vii) is reasonably expected to materially affect the LP's return profile or risk exposure. Determination by Council majority; LP may petition arbitrator for material-change ruling under Depositor Terms 10.
Counsel & Ongoing Legal Oversight: Which external legal counsel(s) do you work with on a recurring basis and in which jurisdictions? Is there an internal legal function or responsible person overseeing legal, regulatory and compliance matters on an ongoing basis?
External counsel engaged on a recurring basis as of 2026-05-03:
Counsel scope split (confirmed 2026-06-23): Pacifica Legal (Panama) is lead counsel for the issuer + operating entity (Boring Vault Corp) and the PIF; BVI counsel is scoped to the asset-holding SPV only; Horizons covers US matters + intercompany structuring.
Horizons Law (general + US counsel; lead counsel Haroldo Granados, haroldo@horizonslaw.io): engagement letter signed. Recurring scope: cross-entity corporate structuring (Delaware Holdings + intercompany agreements across the Panama and BVI entities), Depositor Terms drafting, US securities analysis, AML/CTF policy drafting, Privacy Policy drafting, ongoing legal advisory on protocol changes. Horizons has reviewed the curator DD document directly and is producing the Section 6 deliverables (intercompany agreements, regulatory memos, Depositor Terms, AML/CTF policy, Privacy Policy, indemnification clauses).
Pacifica.legal (Panama counsel; lead counsel Edgar Young, edgaryoung@pacifica.legal): engagement letter signed. Lead counsel for the issuer + operating entity and the PIF. Scope: Panama PIF setup and compliance review, Boring Vault Corp (Panama) corporate governance, Loan Agreement (PIF ↔ Boring Vault Corp (Panama)), the Panama regulatory framework analysis for the issuer/operating entity (specific statutes/registrations to be confirmed; AML/CFT anchor Panama Law 23 of 2019, to be confirmed), and the Panama Law 81 of 2019 data protection memo.
BVI counsel, scoped to the asset-holding SPV (DualMint Ltd. (BVI)) only: SPV constitutional documents, collateral perfection, and any BVI VASP/SIBA/Data Protection Act obligations that genuinely attach to the SPV.
US securities-law coverage, provided by Horizons Law (engaged; see (1)). Scope: Howey / investment-contract analysis, Reg D / Reg S analysis if US persons are admitted in future, and advisory on the US securities-law ramifications of protocol changes. Per counsel (2026-06-23), no separate token legal opinion is required for the current offering posture (see Token Legal Characterization in this section); the engagement is in place to provide US securities advisory on a standing basis.
BVI fund administrator (recurring administrative + light legal oversight): planned Phase 2 milestone tied to TVL scaling; engagement target 2026-Q3, threshold under finalisation.
Operator-jurisdiction counsel (case-by-case, non-recurring): local counsel engaged at OSA execution for equipment title documentation and any local-law charge registration where the OSA program adds one. Coordinated through Horizons.
Internal legal function: no full-time General Counsel as of 2026-05-03 (9-person team). Ongoing legal coordination is owned by:
- CEO + acting CTO (Bill Lee) for Delaware-side, engineering, and high-level structuring.
- CFO (Hung-Chou Tai) for risk, compliance, MLRO functions, regulatory monitoring.
- CRO Chief Revenue (David Sakai) for operator origination, partnerships, revenue.
Known limitation, key-person concentration: there is no full-time GC, and the CFO (Hung-Chou Tai) currently concentrates the compliance, MLRO, and DPO functions. Independent NAV / fund-administration is also pending (target 2026-Q3). These are disclosed as concentration risks for a 9-person team, to be relieved as the team and counsel cadence scale.
Internal legal calendar + monitoring:
- Quarterly counsel-review meeting with Horizons covering open legal matters, pending counsel deliverables, regulatory developments.
- Material contract calendar (renewals, expiries, automatic-renewal triggers) maintained by CFO.
- Regulatory monitoring: Panama issuer/operating regulatory developments with Pacifica Legal; MiCA developments and US SEC / CFTC enforcement trends with Horizons; BVI VASP/SPV-level guidance with BVI counsel. Reviewed quarterly.
- Continuing-disclosure obligations (per Depositor Terms 11.3 + 6.11) monitored on rolling basis; controlling-person events trigger 14-day disclosure to LPs.
Contractual Counterparty: Who is the legal counterparty (or counterparties) to which the curator and LPs will be directly exposed (e.g. specific entity, DAO, trust structure)? Are you able to enter into written agreements (e.g. ISDA-type docs, subscription agreements, credit agreements) with the curator or its vehicles?
Direct legal counterparty to LPs (including curator vehicles): DualMint Foundation, the ownerless Panama Private Interest Foundation (PIF) that receives LP liquidity directly. LPs subscribe to vault shares (sUSDm) issued through the PIF; the PIF lends to Boring Vault Corp (Panama), which deploys capital into the BVI SPV (single SPV now; one per asset class as the portfolio scales) that holds the physical assets. The separation keeps LPs facing a bankruptcy-remote vehicle rather than the operating entity that carries operator counterparty risk.
Curators and LPs can enter into the following written agreements with the structure:
- Vault Depositor Terms (subscription document): base agreement for all LPs, applies to retail and institutional depositors. Counsel-led draft in flight with Horizons; execution in progress.
- Side Letter Template: supplementary terms for LPs ≥$5M ticket. Includes information rights, monthly NAV disclosure, fee carve-outs, redemption priority discussion, governing law alignment. Counsel-led draft in progress.
- Curator Agreement: for a curator engaged to manage allocation and risk oversight (the vault is a single senior pool; there is no junior tranche and the curator is not a loss-absorbing layer). Defines curator allocation parameters, fee share, reporting cadence, termination rights. Template draft in progress.
- ISDA-style Master Agreement: under evaluation by Horizons; current view is that ISDA is not the right form (no derivatives in flow), bespoke loan-style documentation is more fit-for-purpose. Decision in progress.
Counterparty risk transparency: Panama PIF is ownerless and bankruptcy-remote; in the event of Boring Vault Corp (Panama) insolvency, the loan asset on PIF balance sheet is the LP claim against Boring Vault Corp's portfolio, with the underlying equipment held on a title-retention basis in the bankruptcy-remote BVI SPV. LPs are not exposed to Delaware Holdings or to DualMint employee/founder personal liability beyond fiduciary duty.
Hierarchy of On-Chain vs Off-Chain Terms: In the event of a conflict between smart contract logic, your public documentation (whitepaper, docs, website) and any executed legal agreements, which governs? Is this hierarchy explicitly disclosed to users and investors?
This hierarchy is drafted into the Vault Depositor Terms 1.4 (in counsel review with Horizons). It is not yet in force or disclosed to users; it takes effect on execution and publication at dualmint.com/legal (target ahead of vault launch). As drafted:
In order of precedence: (1) Executed legal agreements (Depositor Terms, Side Letters, Operator Security Agreements, Inter-Entity Agreements) govern. (2) Public documentation (whitepaper, GitBook docs, dualmint.com pages) is descriptive only and does not modify executed agreements. (3) Smart contract logic implements the legal terms but does not override them; if a smart contract bug or behaviour deviates from documented design, Council emergency powers (per Vault Security Council Charter 5) and the legal documentation control. (4) Marketing materials are explicitly disclaimed.
Disclosure to users (on execution). The 1.4 hierarchy clause will be acknowledged at the depositor onboarding flow before any subscription is accepted, and surfaced in the public docs at dualmint.com/legal. Neither is live today.
Discrepancy resolution protocol. Any divergence between deployed smart contract behaviour and documented legal terms triggers a Stage 3 incident (per Operator Default Playbook severity tiers). CFO and Smart Contract Lead are notified immediately, and Council convenes within 48 hours. If the divergence favours the LP, deployment continues with disclosure. If it doesn't, Council uses emergency pause powers (Vault Security Council Charter 5) and remediates per the Malware-Endpoint and Smart Contract Spec runbooks.
Terms-to-code mapping appendix. Required artifact, not yet produced. It will be appended to Depositor Terms as Appendix A, mapping each material term (NAV calculation, redemption SLA, fee structure, loss waterfall layers, gate triggers) to the specific smart contract function or state. Closure targeted pre-launch, validated as part of the independent smart contract review scope.
Investor / Creditor Rights: What specific, enforceable rights do the curator and LPs benefit from (e.g. information rights, reporting covenants, negative covenants, veto rights, step-in rights, security interests)? How are these rights documented? Are there any classes of stakeholders with superior or pari passu claims over the same assets?
The rights below are as drafted in the Vault Depositor Terms (in counsel review with Horizons; targeted mid-July 2026), the Side Letter Template for $5M+ LPs (draft targeted pre-launch), and the Operator Security Agreement (operator-facing template). These agreements are not yet executed, so these are drafted rights, not rights currently in force. A stop-gap liquidity facility is in discussion with no signed agreement.
LP rights at base subscription level (as drafted in Depositor Terms):
- Information rights: monthly LP report with NAV, distribution detail, utilisation, insurance adequacy ratio, and yield-gap explanation; weekly during Stage 2+ events; same-day disclosure within 72 hours of Stage 4 events.
- Redemption rights: 30-day standard SLA, 120-day max under stress; FIFO with priority tiers (base depositors → boosted depositors at maturity → pro-rata); penalty interest of 1%/month on redemptions delayed past Day 31 where not justified by a gate trigger.
- Reporting covenants: quarterly proof-of-reserves attestation by a recognised firm post-engagement (target 2026-Q3).
- Step-in / asset access: the BVI SPV holds legal title to the physical assets on a title-retention basis, bankruptcy-remote from the operating entity. The operator holds a revocable licence to operate, and DualMint holds contractual step-in and repossession rights under the OSA. This title-based security position is structured to survive DualMint corporate failure. Step-in / repossession via the BVI SPV is the asset-level remedy; it has not been exercised (0 operator defaults to date). Recovery mechanics detailed in qa-offchain-risk-04.
- Governing law and dispute resolution as set out in the Depositor Terms.
Enhanced rights for LPs ≥$5M (as drafted in the Side Letter Template, draft targeted pre-launch):
- Direct quarterly call with CFO (Hung-Chou Tai).
- Asset-level performance data (subject to operator privacy redaction).
- Most-favoured-LP clause on fee terms.
- Veto right on operator concentration breach (>15% single operator without explicit Side Letter LP consent).
- Information rights extending to 30 days post-redemption for forensic review.
Negative covenants on the protocol (in Depositor Terms):
- No new senior debt above LP claim without LP majority consent.
- No material change to fee structure or waterfall without 30-day notice plus opt-out exit.
- No transfer of BVI SPV asset holdings without Council unanimous approval.
- No related-party transactions that impair the committed first-loss position (operator equipment exposure at Layer 1 plus the 3% Origination Reserve at Layer 2; full waterfall: Collateral & Strategy: Loss Waterfall).
Class structure: single senior-only pool at vault launch. There is no junior tranche; loss absorption sits in the six non-depositor waterfall layers, not in a subordinated LP class. No LP class holds a superior or pari-passu claim over another.
Pari-passu / superior claims over the same assets: reasonable wind-down costs rank ahead of LP recovery in any liquidation. DualMint's operational and equity claims rank below LPs.
Security Interests & Perfection: Are any real-world or off-chain assets pledged as collateral in favor of token holders or LPs? If so, what form of security interest is granted (e.g. pledge, charge, lien), how is it perfected, and in which jurisdiction(s)? Who acts as secured party or security agent?
The security that exists today is legal title. The BVI SPV (DualMint Ltd.) holds legal title to the equipment on a title-retention basis: the SPV owns the machine, the operator holds a revocable licence to operate it, and DualMint holds contractual step-in and repossession rights. This is title retention plus step-in, not a filed or perfected lien. Because DualMint (via the SPV) already owns the asset, LP recovery does not depend on registering a security interest against a borrower.
Layered on top of title, an Operator Security Agreement (OSA) lien program is drafted (12 sections, in counsel-redline with Horizons) but not yet executed. No OSA is signed today, so the OSA's contractual covenants (step-in, repossession, and any local-law charge over the equipment) are prospective. First execution is targeted for pre-launch with Vertriqe, with roll-out across remaining marketplace operators thereafter. The OSA program activates per operator as OSAs sign.
Diligence gap to surface: historic operator liens on the existing 1,310 marketplace assets have not yet been diligenced for pre-vault-deployment subordination. Lien searches on existing operators are part of OSA onboarding; until completed, existing assets may carry undiligenced operator liens.
Form of security: title retention is the primary mechanism. The BVI SPV holds legal title to each physical asset; the operator's interest is a revocable operating licence, not ownership. Governing instruments:
- BVI SPV Asset Holding Agreement: establishes the BVI SPV as legal title holder of the equipment.
- Operator Security Agreement (OSA), granting clause (drafted, not executed): operator acknowledges the SPV's title, grants continuing step-in and repossession rights, and, where local law supports it, grants a charge over the equipment as additional security for all obligations.
- Subordination / inter-creditor agreement with operator's existing lenders (where any): operator must disclose existing liens at OSA execution; existing senior liens are subordinated or the vault declines the asset.
Where the OSA program adds a registrable charge, any registration follows the operator's local law at OSA execution; those registrations are prospective and not filed today. The primary title-retention position does not depend on such filings.
Secured party / enforcement vehicle: DualMint Ltd. (the BVI SPV). It holds legal title to the equipment today; under the OSA (drafted, not executed) it is also the counterparty holding step-in and repossession rights. Because the SPV is bankruptcy-remote from the operating entity, the title-based security position is structured to survive DualMint corporate failure. There is no separate third-party collateral agent in the structure; title and the contractual step-in rights sit directly in the asset-holding SPV.
Loss Allocation & Legal Recourse: In the event of a shortfall or loss (e.g. bad debt, exploit, operational failure), beyond the economic waterfall in Section 4, what legal recourse do the curator and LPs have against the protocol operators, entities, or affiliates? Are there contractual limitations of liability, caps, or exclusions (e.g. exclusions for smart contract risk, market risk, or third-party failures)?
Loss allocation is governed by the canonical six-layer loss waterfall, all non-depositor capital, with depositor principal last (see the loss-waterfall answer for layer-by-layer detail, and the GitBook docs for the mechanics). Beyond the economic waterfall, legal recourse for the curator and LPs is documented in the Depositor Terms (in counsel review with Horizons; targeted mid-July 2026) and the Operator Security Agreement (operator-facing template, first signing targeted pre-launch). None of these agreements is executed to date. A stop-gap liquidity facility is in discussion with no signed agreement.
By design, LP recourse runs to the Foundation (the vault counterparty) and its loan claim on Boring Vault Corp, plus the BVI SPV's secured position over the equipment. LPs have limited direct recourse to operators until OSAs execute, and limited recourse to Delaware Holdings (veil-piercing only). This limited direct recourse is intentional: it is the bankruptcy-remote structure working as intended, not a gap.
Legal recourse against protocol operators / entities / affiliates:
Against operators (Layer 1 of the waterfall, asset recovery & reassignment):
- Direct contractual claim against operator for breach of OSA representations and warranties (activates per operator as OSAs sign).
- Enforcement against the equipment: the asset-holding BVI SPV (DualMint Ltd.) holds legal title on a title-retention basis, plus OSA step-in/repossession rights; Boring Vault Corp (Panama) is the capital-deploying counterparty, not the title holder. Enforcement is run by the SPV directly.
- Personal guarantee from controlling operator principals where ticket size >$500K: this is an optional clause in the OSA template, negotiated case-by-case, not a standard or guaranteed LP protection.
- Cross-default with related operator entities (OSA 7.1, discretionary).
Against Boring Vault Corp (Panama) / PIF:
- Bankruptcy-remote structure means LP claims are direct against the Panama PIF (vault counterparty), which holds the loan against Boring Vault Corp (Panama). In Boring Vault Corp insolvency, LPs recover via the loan asset, with the underlying equipment held in the bankruptcy-remote BVI SPV.
- Legal priority order on enforcement: 1st reasonable wind-down costs, 2nd LPs pro-rata, 3rd DualMint operational, 4th DualMint equity. LPs rank ahead of DualMint operational and equity claims.
Against Delaware Holdings:
- Limited: Delaware Holdings is parent for team and IP; not a direct counterparty to LPs or operators.
- Indirect recourse via piercing-the-veil claims requires fraud / undercapitalisation showing; a high bar, treated as backstop only.
Against directors, officers, contributors:
- Standard fiduciary duty claims for gross negligence / wilful misconduct (not for ordinary business judgement).
- D&O insurance (being sourced, not bound) would cover ordinary fiduciary claims.
- Indemnification clauses (in Depositor Terms + Operating Entity bylaws) limit liability to ordinary cases; gross negligence / wilful misconduct exclusion.
Smart contract risk:
- Vault launches on Concrete's independently audited ERC-4626 stack; no unaudited core vault code at launch.
- Bug bounty post-launch (Immunefi).
- Separate smart-contract / exploit cover program (under evaluation) compensates within scope per Operator Default Playbook.
- Limitation of liability clause in Depositor Terms excludes consequential damages and caps direct damages at LP's deposit amount minus distributions received, pending counsel review with Horizons.
Limitations of liability / caps / exclusions (Depositor Terms, in flight):
- Smart contract risk: not excluded; separate smart-contract / exploit cover program (under evaluation) compensates; LP retains right of action against DualMint for gross negligence / wilful misconduct in code review or deployment.
- Market risk on USDC depegging: excluded (force-majeure-style provision).
- Third-party failures (Chainlink, M0): excluded if DualMint exercised commercially reasonable diligence in vendor selection.
- Operator default: not excluded; full recourse via OSA layered remedies + insurance.
- Caps: LP direct damages capped at deposit amount. Punitive / exemplary damages excluded.
Operational
Team, governance, motivation, minting, legal structure, composability, and scaling.
What is DualMint's current operational capacity, and how does the protocol scale underwriting, sourcing, and asset management without linear headcount growth?
Capacity is not bound to headcount: a lean internal team, external partners for sourcing and legal, the Asset Performance Index (API) as the underwriting engine, and category templates that cut the marginal cost of each new operator. The API turns each asset's live telemetry into a score that drives eligibility and pricing automatically, so onboarding another operator does not add underwriting headcount (full mechanics in the API moat answer, qa-underwriting-and-operations-00).
Current metrics:
- Team: 9 employees
- Assets: 1,310 originated and sold onchain
- Throughput: ~$7,500/month operating cash flow processed and distributed
- Track record: 16 consecutive months of distributions on the established lines, zero defaults
- Pipeline: $50M+ identified operators; first vendor-financing MOUs at signing stage
Partner leverage: Peaq (operator sourcing + IoT data), external PE advisor (valuation, structuring, cash-flow modeling), standardized contract templates, three live chains (Arbitrum, Base, Peaq) for distribution and ecosystem liquidity.
Origination channels: vendor financing embedded with machine manufacturers and distributors, plus territory distributors posting first-loss bonds; in draft and early appointment, not fully operational (full mechanics: the pipeline-scaling answer in Common Investor Objections).
At vault launch the protocol moves from one-off NFT minting to pooled programmatic structure: unified underwriting schema, full programmatic API scoring, single ERC-4626 architecture, continuous rather than deal-specific data ingestion. Capacity then expands through system maturity (more deals, more data, tighter scores), not staffing. The full-scale build proves out at vault launch; the honest gaps are catalogued in the honest-gaps answer (Off-chain Risk).
Why: Our job is to create the best risk adjusted rates for our investors. Please explain why adding your token as collateral creates real value for our investors vs other collaterals.
The collateral is sUSDm, the vault share: a direct claim on self-amortizing equipment cash flow whose yield ceiling is the operating margin of the underlying businesses, uncorrelated to rates or crypto market conditions. The structure carries no separate token, so this answer addresses why sUSDm-backed exposure is a high-quality, differentiated collateral relative to other onchain collaterals.
Yield premium and source. The Machine Yield Index (upcoming) targets 13 to 15% net effective yield to depositors, accruing as sUSDm share-price appreciation rather than separate distributions. The yield ceiling is the operating margin of the underlying businesses, not the risk-free rate and not borrower creditworthiness. The premium over tokenised treasuries (~4 to 5%) and tokenised credit (~6 to 12%) does not compress as rates fall or credit spreads tighten; it compresses only if physical asset utilisation declines materially across the portfolio.
Physical machine revenue is independent of crypto market conditions and macro rate cycles. Everyday machine and robotics usage does not move with token prices or rate cycles; the revenue driver is people using the machines, not market sentiment. Allocation to sUSDm reduces portfolio-level correlation without sacrificing yield, a genuine diversification benefit rather than a yield/risk tradeoff.
Demonstrated track record. 1,310 positions originated and sold onchain. 16 consecutive months of stablecoin distributions across the established marketplace lines since May 2025. Zero operator defaults across the full portfolio history. The marketplace is live and the cashflow mechanics are proven; the vault aggregates the same cashflows into an institutional-grade ERC-4626 wrapper. Mechanics are documented in the GitBook docs.
First-loss structure. Depositor capital is the last loss, sitting behind six layers of non-depositor capital: (1) asset recovery & reassignment via SPV step-in rights, (2) the Origination Reserve (3% of asset value, ring-fenced cash), (3) the Solvency Reserve (3% of monthly cash flow, building with every distribution), (4) two-tier insurance, (5) an external stop-gap liquidity facility (in negotiation), and (6) RFQ liquidation. Layer mechanics, funding status, and what remains unbound are walked in full at Collateral & Strategy: Loss Waterfall; recovery mechanics at Collateral & Strategy: Bad Debt Management.
Curators and their LPs are last-loss across the full structure. The vault liquidity buffer (15% minimum/target, held higher during the early deployment ramp) is undeployed depositor capital that services redemptions, a liquidity tool, not a loss layer.
Team Identity & Experience: Please list the founding team and key team members and their experience. How big is the team and how is it composed between engineers vs. sales vs. others? (Note: if we move forward, issuers will be expected to complete reasonable KYC/KYB for all controlling personnel).
Founding team: Bill Lee (CEO/CTO); Hung-Chou Tai (CFO); David Sakai (CRO, Chief Revenue). Detailed bios available on request under NDA. Key team: Ed Steward (Head of Marketing), Kyle Huang (Financial Analyst). Engineering: a full-stack engineering bench in-house; smart-contract development contracted to specialists. Marketing runs in-house under Ed Steward, with Lunar Strategy as the external marketing agency partner. The team is 9 employees, product/finance/operations weighted with a dedicated full-stack engineering bench (Lunar Strategy is an external agency, not part of the headcount). Controlling personnel are confirmed at KYC/KYB. KYC/KYB on all controlling personnel: willing. Blockpass is engaged as KYB/KYC vendor for the protocol; Synaps is acceptable for personal KYC. Not yet executed; will be completed at allocation stage on a curator-by-curator basis.
Minting & Withdrawing: Under what circumstances can minting and redeeming occur? Are there any gates to withdrawing? (e.g. lock or cooldown period for staked tokens). Are there any escape hatches for LPs to remove funds from a protocol.
Designed but not deployed. Minting (deposit): permissionless within KYC/KYB perimeter (Blockpass-screened wallets, restricted-jurisdiction screening). Async deposit request via ERC-4626: capital is escrowed, settled at the next monthly epoch boundary, then sUSDm is minted at epoch PPS. There is no mandatory lockup; deposits enter at base weight and stay redeemable through the standard queue. Depositors may optionally lock sUSDm (3 / 6 / 12-month tenors) for a higher boost weight; only the locked portion is non-redeemable until its tenor matures. Redemption: async redemption request at ERC-4626 standard, from the base tier or after an elected boost lock matures. Standard SLA 30 days from buffer. Gates by buffer zone (per the Vault Liquidity Risk Framework and Operator Default Playbook): Green (>20%) normal; Yellow (15 to 20%) boosted-early redemptions paused; Orange (10 to 15%) new deposits paused, 60-day notice; Red (<10%) emergency gate, 90 to 120 day max. Asset-impairment gate: if ≥10% of vault is in Stage 2 (active reassignment, cashflow suspended), additional SLA extension applies regardless of buffer. NAV-impairment gate: >5% NAV drop triggers extended SLA. Secondary exit options are designed, not live (batch auction via third-party AMM is the current lean, plus a DEX pool and a Morpho borrow market once curator-listed; detail: Secondary Liquidity in this section). There is no instant escape hatch: the structural exit is the 30-day async queue, gated up to 90 to 120 days in the Red zone, inherent to financing illiquid physical assets and disclosed as such.
Mint & Redeem Flow: Please detail the full subscription and redemption process from a user's perspective, including smart contract calls, discretionary team actions, pricing calculation and timing of execution.
Designed; vault not deployed. Contract names below refer to the Vault Smart Contract Spec; implementation runs on Concrete's audited ERC-4626 stack and is not yet deployed.
Subscription
- Depositor passes Blockpass KYC/KYB and restricted-jurisdiction screening.
- Depositor calls
requestDeposit(USDC amount)on the vault contract (ERC-4626 vault with epoch-based async settlement); capital is escrowed in the BIVOnOffRamp contract. - At the next monthly epoch (last day of month, 23:59 UTC), the epoch-settlement logic settles all queued requests at epoch PPS.
- sUSDm ShareToken is minted to the depositor wallet.
- Optional: depositor calls
BoostVault.lock(sUSDm, tenor)to lock sUSDm until maturity at an elected boost multiplier. Locking is not required; the base tier remains redeemable.
Redemption
- Depositor calls
requestRedeem(sUSDm amount)(after any elected boost lock has matured). - The request enters the redemption queue (FIFO by tier).
- At the next epoch, the queue is processed against available buffer; pro-rata partial fill if the buffer is insufficient.
- USDC is settled to the depositor wallet and sUSDm is burned.
Pricing. Epoch PPS = vault NAV ÷ sUSDm outstanding. NAV reconciled monthly (not yet deployed).
Discretionary actions. The Operator wallet may pause new RWA deployments in the Yellow zone; the Council may activate an emergency gate in the Red zone or on an asset-impairment trigger.
Timing. Standard 30-day settlement; up to 120-day maximum under stress.
Notice Period / Queue: Do you use a minting or redemption queue or notice period, and under what conditions? Or are all minting and redemption atomic?
Yes, both minting and redemption are queued via ERC-4626 vault with epoch-based async settlement, not atomic. Monthly epoch cadence (last day of month, 23:59 UTC). Mint queue: deposits between epochs are escrowed and settled in batch at epoch boundary; PPS calculated against epoch-end NAV. Redeem queue: redemption requests enter a FIFO queue per tier (base-tier depositors any epoch; boosted depositors once their elected lock matures; pro-rata within tier if the buffer is insufficient). The 30-day standard redemption SLA reflects the monthly cashflow cycle of underlying assets, not a discretionary gate. Notice periods extend automatically by buffer zone (per the Operator Default Playbook). Lockup: none is mandatory; the base tier stays redeemable through the queue, and depositors may optionally lock for 3 / 6 / 12 months to earn a higher boost weight, during which only the locked portion is non-redeemable. Early exit from an optional boost lock is permitted with a penalty per the Depositor Terms (in flight). All minting and redemption operations are non-atomic by design, a deliberate choice driven by the illiquidity of underlying physical assets.
Secondary Liquidity: What is the current state of on-chain and off-chain liquidity? Which venues? Can liquidators access atomic liquidity to facilitate liquidations? How will liquidity be scaled with the protocol? Please address the same for the governance token post-TGE.
Vault and protocol-token liquidity addressed separately:
Vault tokens (sUSDm): at launch there is no live secondary market for sUSDm; the redemption queue is the exit. Single-chain (chain to be confirmed). Primary exit is async redemption against the liquidity buffer (30-day standard SLA; no mandatory lockup, optional boost locks aside). Secondary-exit mechanisms are designed and under evaluation, not live: (1) the current lean is a batch-auction mechanism with tranching via a third-party AMM, providing periodic price discovery and exit without forcing a redemption against the buffer; (2) a Uniswap v3 sUSDm / USDC pool (concentrated range around NAV), to be provisioned from protocol treasury; (3) a Morpho curator-listed sUSDm borrow market that supports leveraged positions and exit without principal sale; under diligence (curator track active). Initial liquidity sizing for the secondary venues is under finalisation. Liquidator access: the batch auction and DEX pools provide programmatic liquidation paths once live; Operator Default Playbook redemption gate logic gates emergency exits.
Underlying assets: illiquid by design (physical equipment), and disclosed as such. The 30-day standard / 120-day max redemption SLA exists precisely because of that underlying illiquidity. Equipment-market secondary liquidity exists for the machine and robotics categories DualMint finances via established business-sale channels. Asset reassignment via SPV step-in rights replaces forced liquidation in default scenarios; recovery rates and reassignment timing vary by category.
Governance token: not applicable — DualMint has no governance token. Nothing in the current offering depends on a governance token.
Scaling plan: liquidity scales with TVL, and secondary venues are seeded from protocol revenue (10% processing fee accrues to protocol treasury); the DEX pool deepens with curator co-allocation; the Morpho borrow market opens once curator endorsement is secured. Liquidity adequacy reviewed quarterly by Council per the Vault Security Council Charter.
Inter-Entity Legal Agreements: Detail any legal or contractual arrangements between the corporate entity, development company, DAO and/or Foundation, if any exist.
Counsel engaged:
- Horizons Law (general + US counsel; lead counsel Haroldo Granados, haroldo@horizonslaw.io). Engagement letter signed. Scope covers corporate structuring and intercompany agreements across the DualMint entity stack.
- Pacifica Legal (Panama counsel; lead counsel Edgar Young, edgaryoung@pacifica.legal). Engagement letter signed. Scope covers the PIF setup, the Loan Agreement (PIF ↔ Boring Vault Corp), and ongoing Panama corporate governance.
Entity structure (four entities, registered): DualMint Holdings, Inc. (Delaware: parent, team, IP) · DualMint Foundation (Panama PIF: ownerless vault counterparty and sUSDm issuer; receives LP liquidity and lends to the operating entity) · Boring Vault Corp (Panama: operating entity; borrows from the PIF, deploys into operators) · DualMint Ltd. (BVI: asset-holding SPV; single SPV now, one per asset class as the portfolio scales). Capital flow: LPs → DualMint Foundation (PIF) → intercompany loan → Boring Vault Corp → operators → cash flows return up the chain.
Required intercompany agreements (in drafting): (a) Delaware ↔ Boring Vault Corp Services Agreement (operations + IP licence delegation; Horizons); (b) Boring Vault Corp ↔ BVI SPV Asset Holding Agreement (codifies title custody, step-in rights, revenue routing, operator-default remedies; one per SPV as the portfolio segregates; Horizons); (c) DualMint Foundation (PIF) ↔ Boring Vault Corp Loan Agreement (vault liquidity into the operating entity, loan terms aligned to the LP redemption SLA; Pacifica Legal + Horizons); (d) Boring Vault Corp ↔ Operators Operator Security Agreements (OSA template; first OSA execution with Vertriqe targeted pre-launch).
DAO / backstop arrangements: an external Stop-Gap Liquidity Facility (the last-resort backstop in the loss waterfall) is in negotiation; the provider is not disclosed while terms are being finalised, and no agreement is signed yet.
Collateral security: the BVI SPV (DualMint Ltd.) holds legal title to the financed machines, with the operator holding a revocable licence and DualMint holding contractual step-in and repossession rights under the Operator Security Agreement (OSA). The mechanism is title retention plus step-in, bankruptcy-remote from the operating entity, rather than filed statutory liens (the SPV sits outside the US filing system). Enforcement on a confirmed event of default runs through the SPV's ownership and step-in rights per the Operator Default Playbook; there is no separate third-party collateral agent.
Closure: the agreements above are drafted and targeted for execution pre-vault-launch. Together with the Stop-Gap Liquidity Facility, they are blocking items for vault launch.
Regulatory Regime: Does the company fall under any regulatory regime or are there any licenses it requires to operate?
Counsel engaged:
- Pacifica.legal (Panama counsel; lead counsel Edgar Young, edgaryoung@pacifica.legal). Engagement letter signed. Lead counsel for the issuer + operating entity (Boring Vault Corp) and the PIF, covering Panama PIF setup, ongoing Panama corporate governance, and the Panama regulatory analysis.
- Horizons Law (general + US counsel; engagement letter signed). Scope covers US matters + intercompany agreements.
- BVI counsel scoped to the asset-holding SPV (DualMint Ltd. (BVI)) and its title-retention and step-in collateral structure only.
No licenses held today; no enforcement actions. Position per jurisdiction (under counsel review):
(a) Panama (operating entity Boring Vault Corp; token issuer DualMint Foundation): the issuer/operating analysis is governed by the Panama regulatory framework. Applicable Panama statutes/registrations to be confirmed by Panama counsel (Pacifica Legal); known AML/CFT anchor is Panama Law 23 of 2019 (to be confirmed).
(b) BVI (asset-holding SPV only): the BVI VASP Act 2022 / SIBA analysis attaches only to the asset-holding SPV (DualMint Ltd. (BVI)) where it genuinely scopes that entity's collateral custody; BVI counsel to confirm. The question of whether the Machine Yield Index constitutes a "collective investment scheme" is mitigated by the qualified-investor restriction in the Depositor Terms; counsel memo targeted mid-July 2026.
(c) Panama PIF (vault entity, ownerless): operates under Panamanian Private Interest Foundation regime, not regulated as an investment fund under Panama law. An independent director on the Council provides external oversight. Panama counsel comfort letter target 2026-08-15 from Pacifica.legal.
(d) Delaware Holdings: not registered as investment adviser, broker-dealer, or money transmitter; serves as parent entity for team and IP only; does not directly interact with depositors.
(e) MiCA (EU): full assessment pending if EU-resident depositors are permitted; the current Depositor Terms carry a geofence option.
(f) US: US persons excluded under the Depositor Terms pending regulatory clarity; no Reg D / Reg S structuring at vault launch.
Counsel scope still to close: the Panama regulatory analysis (Pacifica Legal) and the PIF comfort letter. Per counsel, no separate token legal opinion is required for the issuer structure. MiCA counsel is engaged only if EU depositors are permitted at launch.
Strong status requires the written Panama analysis and comfort letters in hand. The current answer reflects engaged counsel and drafting in flight, not delivered comfort letters.
Strategy Format: Is the protocol's economic activity driven primarily by on-chain interactions, or off-chain trading logic? Please describe the format of the strategy (e.g. delta-neutral, basis trade, market-making, LP provision) and how it is implemented technically.
Not a trading strategy. DualMint is not delta-neutral, not a basis trade, not market-making, and not LP provision. There is no order routing, no hedging, and no position management. The protocol finances physical machines and robotics: two seasoned lines with 16 months of distributions, newer live lines, and further categories incoming/not yet live. It routes the operating cash flow on-chain. Activity is primarily off-chain (machines running) with on-chain settlement and verification.
Operational flow:
- DualMint underwrites the asset via the Asset Performance Index (0 to 100 score, 4 pillars, 65% machine-generated, monthly re-score).
- Operator pays a 10% origination fee and posts the equipment as collateral.
- Capital is deployed against the asset, phased per the deployment ramp.
- Operator runs the business; revenue is collected via IoT-instrumented payment systems.
- Revenue is cross-referenced through 2 sources (IoT telemetry + operator-system API); sources must agree within ±10 to 15% per Vault Smart Contract Spec.
- Cash flow routes through the vault's routing contract, split between principal recovery and yield.
- Yield accrues to sUSDm as price-per-share appreciation (no separate distribution event), weighted at the epoch by boost multiplier.
- Self-amortising: cumulative principal recovery reduces vault exposure over time (a modeled/projected 40 to 50% by Month 12 per the Senior Capital Investment Framework, a projection, not observed; the vault is not live and 0 recovery events have occurred to date).
Implementation stack: Concrete's audited ERC-4626 vault standard, custom single-chain vault contracts, the M0 USDm stablecoin layer, and the Peaq IoT layer. See the GitBook docs for the full architecture.
Competitors: Who are your direct competitors and how does your product differentiate from them?
Closest direct comparable: Daylight / DayFi (a16z + Framework Ventures-led, $75M raised, same structural argument, same M0 stablecoin partner), single-category (solar) against DualMint's multi-category book.
| Category | Players | Their yield source | Structural difference |
|---|---|---|---|
| Operational yield, single category | Daylight / DayFi | Solar electricity revenue | Same argument, one category |
| Tokenized credit | Maple, Centrifuge | Borrower repayment (credit risk) | DualMint underwrites usage risk; the operator is swappable and the machine keeps earning |
| Tokenized treasuries | BlackRock BUIDL, Ondo | Government rates | Compresses with rate cuts; DualMint's ceiling is operating margin, rate-decoupled |
| DePIN | Helium, DIMO, Render, Hivemapper | Token emissions | DualMint pays monthly cash receipts (USDC on Arbitrum, USDT on Peaq) |
Not competitors: Peaq (DualMint builds on it) and USD.ai (GPU-collateralized lending, different collateral and yield source).
Track-record precision: the 16 months of distributions sit with the two seasoned machine lines, not the full roster; additional live lines are newer, further categories incoming and not yet live.
Owned territory:
- Usage-risk underwriting as a primitive
- The Asset Performance Index dataset as a compounding moat
- The $10K to $1M equipment cash-flow segment: TradFi finances it offline, and tokenized credit abandoned it onchain when it moved upmarket to $1M+ institutional pools
- Robotics fleets: term lenders need a residual-value curve for fixed amortisation, and robot residual value is an unsolved modelling problem, so they structurally cannot finance RaaS fleets. A revenue-share model priced off live telemetry with machine-level reassignment underwrites the category directly.
External validation, August 2026: NVIDIA's $500B compute-financing coalition (Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs, KKR — announced 2026-08-10) underwrites AI infrastructure the same way DualMint underwrites machines: on utilization and cash flow, not borrower credit. One structural difference favors DualMint — NVIDIA still guarantees up to 25% of residual value per deal, because GPU value three years out is unpriced; DualMint carries no residual-value risk, since its assets are designed to amortize to zero. Kalanick's Atoms ($1.7B, a16z-led, industrial robotics, closed 2026-07-22, 19 days ahead of the NVIDIA coalition) is the same capital thesis from the demand side.
Reference class: GE Capital, Caterpillar Financial, and John Deere Financial built the $1.1T equipment-finance category offline. DualMint is that category onchain, one ticket-size rung down. Landscape detail: pitch deck.
Organizational Structure: Where is the project's corporate entity based? Please confirm the ownership structure of the entity. What is the controlling structure of the team and how are decisions made? Does an Org Chart exist? Would you be willing to KYC via a tool like Synaps?
Four-entity institutional structure (Horizons Law as general + US counsel and Pacifica Legal as Panama counsel; both engagement letters signed). Detailed structure documented in the GitBook docs.
DualMint Holdings, Inc. (Delaware C-Corp): parent entity for team, IP, equity cap table. Not registered as investment adviser, broker-dealer, or money transmitter. Does not directly interact with depositors.
DualMint Foundation (Panama Private Interest Foundation): ownerless vault counterparty and sUSDm issuer. Receives LP liquidity and lends to the operating entity. An independent director on the Council provides external oversight. Registered (Folio Nº 25067005).
Boring Vault Corp (Panama corporation): operating entity. Borrows from the PIF, deploys capital into operators, and manages the portfolio. Registered (Folio Nº 155786295).
DualMint Ltd. (BVI): asset-holding SPV. Holds legal title to the financed equipment via leaseback; the operator holds a revocable licence, with contractual step-in and repossession rights to DualMint under the Operator Security Agreement (OSA). Bankruptcy-remote from the operating entity. Single SPV now, segregating into one SPV per asset class as the portfolio scales.
Capital flow: LPs → DualMint Foundation (PIF) → intercompany loan → Boring Vault Corp → operators → cash flows return up the chain to LP yield (sUSDm price-per-share). The Hong Kong entity was wound down in May 2026 and is not in the structure.
KYC/KYB on all controlling personnel: willing. Blockpass is engaged as the KYB/KYC vendor; Synaps is acceptable for personal KYC. The packet is compiled at allocation stage on a curator-by-curator basis.
Decision-making: founder-led at corporate level (DualMint Holdings + Boring Vault Corp); a multi-signature Security Council governs vault-level material actions per the Vault Security Council Charter. DualMint holds a minority of the Council seats and cannot act unilaterally; the remaining independent seats (including auditor / depositor representative) are designated for appointment at vault launch. The exact seat count and signing threshold are being finalised ahead of vault launch.
A dedicated org chart is available on request.
Asset Custody: Does the project rely on a non-custodial smart contract framework or a legally recognized custodian for safeguarding user assets?
Two custody surfaces.
Onchain depositor capital. USDC sits in the ERC-4626 vault smart contract: non-custodial, with no centralized custodian holding depositor funds. The vault contract is upgradable under a multi-signature Security Council (DualMint holds a minority of seats) plus 24-hour timelock controls, and launches on Concrete's audited ERC-4626 stack.
Physical assets. The BVI SPV (DualMint Ltd.) holds legal title to the equipment; assets sit at operator locations. The operator holds a revocable licence, and DualMint holds contractual step-in and repossession rights under the Operator Security Agreement (OSA). Title retention plus step-in is the collateral mechanism, not filed liens. DualMint Ltd. (BVI) sits outside the US filing system, so enforcement runs through the SPV's ownership and step-in rights rather than statutory lien filings.
The OSA framework is prospective: the first OSA (Vertriqe) is targeted pre-launch, and live marketplace assets to date are not yet under signed OSAs. That is the core collateral consideration of the model, disclosed as such. Institutional custody integration is planned post-$10M TVL and is not yet in place. The custody model is set out in the GitBook docs.
Key Management Setup: Describe the admin role set up - who holds the cryptographic keys that affect critical operations (e.g. upgrades, fund movements)? If there are multi-sigs, what are the thresholds and the associated wallets infrastructure and addresses behind the multi-sig? Are hardware wallets / devices utilized, exposed to other devices or regularly cycled?
Live today vs. at vault launch. A multi-signature Safe (Gnosis Safe) is deployed; address available to a serious counterparty on request. Because the vault is not yet deployed, this Safe does not currently govern or hold any material depositor funds; it is the control surface that will administer the vault at launch. The full Security Council described below is designed for launch, not yet fully appointed.
Designed Council (per the Vault Security Council Charter): DualMint holds a minority of seats and cannot act unilaterally. Composition: DualMint executive seats (CEO Bill Lee; CTO / Operations Lead); an independent-oversight seat tied to the external Stop-Gap Liquidity Facility (in negotiation; the facility is not executed, so this seat is designated, to be appointed at launch); plus independent seats, including an auditor / depositor representative, designated for appointment at vault launch. The exact seat count and signing threshold are being finalised ahead of vault launch; the target is a supermajority of seats for any Council action, with DualMint unable to reach threshold alone. Offline key storage; hardware wallets mandatory per the Vault Security Council Charter (Ledger or Trezor only). No hot wallet signing for Council transactions. No proxy voting. Lost-key replacement procedure documented in the Vault Security Council Charter. Three roles defined: Admin (24h timelock: parameter changes, upgrades), Guardian (immediate: pause, gate, freeze), Operator (bounded: daily operations within concentration limits).
Composability & External Dependencies: Does the protocol interface with external DeFi platforms, aggregators, bridging solutions and oracles? If so, what are the dependencies?
Designed but not all live. Active integrations and dependencies, in priority order:
- Concrete. ERC-4626 vault standard, audited; vault contracts are built on its async-vault framework.
- M0. Stablecoin issuance infrastructure; USDm is an M0 extension token on the M0 ledger.
- Chainlink. Live oracle integration (Chainlink BUILD program), supplying the IoT-derived API score and the 2-source revenue cross-reference (IoT telemetry plus operator-system API).
- Peaq. IoT telemetry layer for machine-generated revenue verification.
- Single-chain deployment at launch (chain to be confirmed). All vault contracts sit on one chain, so there is no cross-chain bridge dependency and no Chainlink CCIP at launch.
DualMint's marketplace today runs across three live chains (Arbitrum, Base, Peaq); the vault itself launches on a single chain. Dependencies are documented in the Vault Smart Contract Spec and the GitBook docs.
User Use Case: What is the primary use case of the protocol from a user's perspective?
From a depositor's perspective: deposit USDC into the Machine Yield Index (upcoming), receive sUSDm vault shares, and earn a target effective net yield of 13 to 15% sourced from the operating cash flow of physical machines. Vault yield accrues as sUSDm price-per-share appreciation rather than separate distributions; the share value grows as the underlying cash flows settle. Principal is recovered first per asset before yield accrues to depositors (self-amortizing structure). There is no mandatory lockup: the base tier stays redeemable through the standard queue, and depositors may optionally lock for 3 / 6 / 12 months to earn a higher boost weight. Redemptions run on a 30-day standard SLA from the buffer, extending up to 120 days under stress. The use case is non-correlated, USDC-denominated yield from real-economy operating margins for three buyers: curators allocating in their vaults; DAO treasuries seeking diversification away from crypto-native yield; and institutional family offices seeking productive deployment of stablecoin treasury at rates above tokenized treasuries. See the GitBook docs for vault mechanics.
Infrastructure & OpSec
Cloud infrastructure, DNS, deployment, and security.
Infra Inventory: Has the team documented all infrastructure and third-party systems (cloud, CI/CD, deploy agents)?
Infrastructure Inventory v1.0 published 2026-05-01 (available on request under NDA). Documents every system in scope across 16 categories:
- Cloud: AWS (ap-southeast-1)
- Source control + CI/CD: GitHub DualMint org with Dependabot
- Database: AWS RDS
- Smart contract infrastructure: EVM-compatible chains: 3 live (Arbitrum, Base, peaq); Alchemy RPC; Vault Security Council Safe to be deployed at vault launch (3-of-5 target; final seat count being confirmed), not yet live
- Oracles: Chainlink (live) + peaq Machine ID + operator-system API; 2-source cross-reference per Operator Default Playbook
- KYC / KYB: Blockpass
- Telemetry: peaq Machine ID
- Payment reconciliation: API access into operator POS systems
- Monitoring: AWS CloudWatch + Vercel + Vault Guardian System (per Vault Guardian System Blueprint, available on request under NDA)
- Domain / DNS: Namecheap registrar + Route 53
- Runtime secrets: Infisical
- Corporate services: standard accounting / banking / payroll providers
- Vault contract stack: Concrete ERC-4626 (independently audited)
Each entry names vendor, account purpose, and owner. The inventory also sets a credential rotation policy and a quarterly review cadence, held jointly by the CEO / acting CTO and the CFO.
IAM & Access Controls: Are RBAC, MFA, VPC segmentation, and cloud security standards implemented? Is access monitored?
IAM & Access Control Policy v1.0 published 2026-05-01, with a companion Off-boarding Checklist v1.0 (both available on request under NDA).
Controls operational today:
- 5 engineering/infrastructure personnel (CTO + 4 engineers) out of 9 total staff hold infrastructure access.
- MFA enforced on all AWS IAM users, the GitHub org, the Vercel team, and Infisical.
- Multi-VPC topology with prod / staging / dev separation; no cross-VPC peering between prod and non-prod.
- No engineer has direct write access to production RDS or production AWS resources; all changes flow through PR + CI gates.
- CloudTrail enabled multi-region, 90-day hot retention + 1-year archive.
Artifacts introduced by the policy:
- A five-role matrix mapping every individual to AWS / GitHub / Vercel scope.
- A quarterly access review cadence (first review 2026-08-01) with a sample CloudTrail audit.
- A 14-step off-boarding checklist: 24-hour SLA for IAM revocation and secret rotation, 7-day SLA for sign-off.
- A break-glass procedure for CTO unavailability, with CFO-held offline root recovery.
DNS Security: Are domain names protected via DNSSEC, domain locking, and registrar 2FA? Are DNS changes monitored?
DNS Security Runbook v1.0 published 2026-05-01, updated to v1.0.2 on 2026-05-02 reflecting DNSSEC and CAA operational state. Available on request under NDA.
Posture:
- Domain at Namecheap registrar with registrar lock active (WHOIS status: clientTransferProhibited).
- DNS authority on AWS Route 53.
- DNSSEC signing enabled at Route 53; customer-managed CMK in us-east-1; DS record (algorithm 13 ECDSAP256SHA256, digest type 2 SHA-256) published at the .com registry via Namecheap.
- Chain of trust validates end-to-end (validating resolvers 1.1.1.1 and 8.8.8.8 return ad flag confirming root → .com → dualmint.com chain validation, externally verifiable at https://dnssec-analyzer.verisignlabs.com/dualmint.com).
- CAA records published in Route 53 restricting TLS issuance to Let's Encrypt (Vercel default path) and AWS Certificate Manager (amazon.com, amazontrust.com, awstrust.com) only; all wildcard cert issuance blocked via issuewild ";"; misissuance attempts route to a security alias via iodef.
Residual hardening items: Namecheap 2FA hardware-token confirmation, CloudWatch SNS monitoring on Route 53 zone changes, weekly Route 53 zone export to private git repo, KSK rotation runbook. All tracked to closure ahead of vault launch. Specific resource identifiers (account, hosted zone, KSK, CMK alias, key tag) provided on request under NDA.
Frontend/API Security: What protections are in place for frontends, APIs, and RPC endpoints? WAF? CDN? Rate limiting?
Frontend & API Security Runbook v1.0 published 2026-05-01 (available on request under NDA).
Current posture:
- Vercel Pro plan: global edge CDN, Vercel-managed TLS (Let's Encrypt auto-renewal), forced HTTPS, and Anycast L3/L4 DDoS absorption (vendor default).
- Authentication: JWT plus signed wallet messages (EIP-191/SIWE pattern) for all state-changing actions. Web3Auth provides MPC-based wallet connection with social login.
- The frontend never holds RPC API keys. Web3 read calls route through a server-side
/api/rpcproxy. - RPC: Alchemy primary. Single-provider dependency today; multi-provider fallback closure tracked in the Infrastructure Inventory and the Frontend & API Security Runbook.
Material residual gaps (all closing pre-vault-launch):
- Vercel Firewall managed rules not yet enabled.
- No custom rate limiting on auth / KYC / wait-list / signup, or per-wallet on deposit / redemption (closure via Vercel Firewall + Upstash Redis).
- No CAPTCHA on public forms (closure via Cloudflare Turnstile).
- Subresource Integrity hashes not yet enforced on third-party scripts.
- Strict Content-Security-Policy + security headers not yet set in
vercel.json. - Public API endpoint inventory pending as Appendix A.
Eleven items in total tracked to closure pre-vault-launch.
Deployment Pipeline Controls: Are all production releases subject to manual approval, CI checks, and checksum validation?
Application code (frontend + off-chain bots): pipeline operational today.
- Repo: GitHub. Branch protection on
main, with required reviewers and required status checks. - CI: GitHub Actions runs on every PR, covering unit tests, lint, and typecheck. Merge to
mainblocked until green. - Security scans in CI: Slither and Mythril for any Solidity in the repo; standard supply-chain scans on application dependencies.
- Tagged releases: GitHub Releases with semver tags for every production cut.
- Signed commits: policy documented in CONTRIBUTING.md; cryptographic enforcement on
main/ staging is a pre-launch closure item. - App deploy: Vercel auto-deploys on merge to
main; preview-per-PR enabled for review before merge.
Vault smart contracts: not yet deployed. Deployment ceremony will run once at vault launch (per Vault-Launch-Rollout-Plan):
- Final pre-deploy build reproducible from a tagged commit; bytecode hash recorded.
- Deploy transaction signed by Vault Security Council multisig (3-of-5 Gnosis Safe with offline keys); no single-party deploy authority.
- Post-deploy: deployment manifest published, covering commit hash, deployer address, deployed contract addresses, and bytecode hash for independent verification.
- Audit-to-deploy chain-of-custody preserved against Concrete's pre-audited release tags (per the supply-chain protection answer).
Environments: Does the team use dedicated development, staging and production environments?
Environments Policy v1.0 published 2026-05-01 (available on request under NDA). Three environments are operationally distinct:
- Production: VPC-prod, branch
main, public-facing. - Staging: VPC-staging, branch
staging. - Development: VPC-dev, Vercel preview URL per PR on feature branches.
All three live in one AWS account with VPC-level network separation, no VPC peering between prod and non-prod, separate RDS instances per environment, and per-environment third-party API keys scoped via Infisical.
Hard rules enforced:
- No production data in any non-prod environment (no
pg_dumpprod paths exist). - Non-prod cannot transact on mainnet; testnet/devnet RPC only.
- Non-prod uses sandbox API keys only for operator-system integrations and Blockpass.
- Branch-to-environment mapping is codified: merge to
maintriggers Vercel production deploy, merge tostagingtriggers staging deploy, all changes flow through PR. - Branch protection rulesets on all target branches (server repo:
main,nightly,alpha; token-contracts repo:main): required reviewers, required status checks, linear history, no admin bypass.
Material residual gap disclosed: the staging environment is currently publicly internet-accessible (a deliberate trade-off for partner demos), mitigated by no-prod-data + sandbox-keys-only + no-mainnet-tx + noindex/robots.txt. Closure via Cloudflare Access (free up to 50 users) targeted pre-vault-launch.
Defense-in-depth gap: single AWS account vs multi-account AWS Organizations, with closure Q3 2026, acceptable post-vault-launch. Seven items tracked to closure in the Environments Policy.
Supply Chain Protection: Detail the mitigations in place to protect the project from supply chain attacks (incl dependencies, CI/CD workflows etc).
Supply Chain Security Policy v1.0 published 2026-05-01 (available on request under NDA).
Operational controls today:
- Branch protection rulesets configured on all production branches (server repo: main, nightly, alpha; token-contracts repo: main): required reviewers + required status checks + linear history + no admin bypass.
- Tests gate CI deploys on both repos; CI must pass before merge.
- Slither static analysis runs in token-contracts CI.
- Tagged releases on both repos via release-please (semver tags, automated CHANGELOG, release artefacts).
- Commit-signing setup documented in CONTRIBUTING.md on both repos.
- Dependabot CVE alerts active on the DualMint GitHub org; lockfile committed (package-lock.json / pnpm-lock.yaml) with
--frozen-lockfileenforced in CI; all repos private to the DualMint GitHub org. - Reproducible smart contract builds: same source produces identical bytecode under deterministic Foundry / Hardhat settings (fixed compiler version, fixed optimiser runs, no metadata timestamp drift).
- No npm packages published, which closes one full attack class (no compromised-publishing vector).
Remaining closure items pre-vault-launch:
- Pin all third-party GitHub Actions to commit SHA (not floating tag) by launch.
- Enable GitHub Push Protection org-wide by launch.
- npm-audit CI gate failing on high / critical CVE by launch.
- CODEOWNERS file routing package.json /
*.sol/ workflows / Vercel config to CTO by launch. - Signed-commit enforcement (beyond documentation) on main / staging by launch.
- Bytecode hash artefact + commit-to-deploy chain-of-custody manifest by launch.
- Socket.dev for transitive supply chain risk by launch.
- Pre-commit secret scanner (gitleaks) by launch.
- OpenZeppelin / Concrete dep pin to audited release tags by launch.
Reproducible builds directly address the audit-to-deploy bytecode-match question that surfaces in institutional contract-security diligence.
Logging: What logging, monitoring practices are in place for non-smart contract components including application servers, cloud infra, admin dashboards and off-chain bots?
Logging & Monitoring Policy v1.0 published 2026-05-01 (available on request under NDA).
Operational today:
- All application servers and four off-chain bots (reconciliation pipeline, Chainlink oracle relayer, NAV calculator, peaq telemetry ingest) emit structured JSON logs to AWS CloudWatch Logs.
- Admin dashboard actions write to a separate dedicated audit-log stream with a minimum schema (
actor_id,actor_role,source_ip,action,subject_id,before_state,after_state,reason,result,request_id). - CloudTrail enabled multi-region for AWS identity audit (per the IAM Policy); Vercel native log store for frontend / edge.
- An application-layer rule enforces no PII in any log stream. Users are referenced by hashed wallet address or internal ID, never by name / SSN / identity-doc fields.
Bot health thresholds, per bot: Chainlink relay success rate ≥99.5%, NAV variance <1% epoch-over-epoch (per the Operator Default Playbook), telemetry cross-reference agreement ≥98% (per the Vault Smart Contract Spec). These are codified as CloudWatch Alarms; today they surface in the CloudWatch console and are reviewed by CFO + Operations on a fixed cadence. Severity-tiered on-call paging (Stage 1 to 4 per the Operator Default Playbook) is a pre-launch closure item, with tooling under selection.
Material residual gaps (owners and dates assigned, all closing pre-vault-launch):
- Default 30-day CloudWatch retention upgraded to 90-day hot + 1-year S3 Glacier archive.
- No on-call paging today; paging tooling under selection, deployed with CTO + CFO rotation by vault launch.
- Application error-tracking tier by launch.
- Vercel Log Drain to CloudWatch by launch (eliminates the Vercel 3-day retention gap).
- CloudWatch Dashboard for 4-bot health widgets with healthy / alert thresholds by launch.
- S3 Object Lock for admin audit-log immutable 1-year retention by launch.
Eleven items in total tracked to closure pre-vault-launch.
Malware: How are you monitoring and or mitigating risks from malware throughout your infrastructure?
Malware & Endpoint Security Policy v1.0 published 2026-05-01. Available on request under NDA.
Operational controls today:
- 5-MacBook homogeneous fleet (macOS only, easier to harden than mixed-OS).
- macOS built-in protections active on every device: Gatekeeper code-signing enforcement, XProtect malware signatures, MRT removal tool.
- Phishing resilience training conducted with the Chainlink security team as part of the Chainlink BUILD partnership.
Designed signing model (not yet deployed):
The Vault Security Council multisig (Gnosis Safe, 3-of-5 target; final seat count being confirmed) is not yet deployed; it goes live at vault launch. Air-gapped offline signing is the designed and documented signing model for Council signers: keys held on signing-only machines, transactions prepared online and transferred to the air-gap (QR / USB), signed offline, signature returned for broadcast. The signing SOP codification, the signer-address registry, and the Charter update documenting each signer address are pre-launch closure items. We do not yet have a deployed Safe with named signers.
Hardening items in flight (closure ahead of vault launch):
- Air-gap signing SOP: formal codification of the existing operational discipline (radio-disabled hardware spec, tx transfer mechanism, pre-signing tx hash verification, seed backup discipline, loss/theft protocol, quarterly testnet rotation drill).
- EDR deployment on daily-driver MacBooks.
- MDM deployment.
- Hardware-token (YubiKey) issuance for non-signing privileged access (AWS root, registrar, GitHub admin, SSO).
- Quarterly phishing-simulation cadence with an institutional-tier vendor.
- Malware Incident Response Runbook with Stage 1 to 4 escalation per Operator Default Playbook.
- Vault Security Council Charter update documenting Gnosis Safe + air-gapped signing operational state with each signer address.
Optional further hardening (non-blocking): dedicated hardware wallets inside each air-gapped setup so the private key never exists in software memory at all. Deferred to Council decision.
Operational DD
Execution infrastructure, NAV audits, redemptions, and incidents.
Collateral Movement Authority: Who holds permission to move collateral? Is there segregation between trading vs. custody authority? Is movement gated via policy, multi-sig, or automated triggers?
Trading vs custody segregation: not applicable. DualMint runs no trading positions. The structural segregation that matters in this protocol is between physical collateral, on-chain treasury, vault depositor capital, and corporate equity.
Collateral movement authority by category:
- Physical RWA collateral (machines and robotics): legal title held by the BVI SPV (DualMint Ltd.; single SPV now, one per asset class as the portfolio scales), which retains ownership of the equipment with contractual step-in and repossession rights, bankruptcy-remote from the operating entity. The operator holds a revocable licence under the Operator Security Agreement (OSA); the mechanism is title retention plus step-in, not filed liens (the SPV sits outside the US filing system), and OSA rollout across operators is in progress, targeted pre-launch. Transfer or liquidation can be compelled only on a confirmed event of default, executed through the SPV's ownership and step-in rights per the Operator Default Playbook; there is no separate third-party collateral agent. DualMint employees, including the CEO and CFO, have no authority to unilaterally move physical collateral.
- On-chain treasury (USDC operating treasury, fee accruals, the ring-fenced Origination Reserve): to be held in the Vault Security Council multisig (Gnosis Safe, 3-of-5 target; final seat composition being confirmed), deployed and onboarded at vault launch. Movement requires 3 of the target signers. The Council Operator wallet, with bounded permissions per the Vault Security Council Charter, executes routine epoch-close distributions within concentration limits; cross-limit changes require full Council resolution.
- Vault depositor capital: held in the ERC-4626 vault contract on the launch chain (TBD). Smart contract logic governs deposit / mint / burn / redeem per the Depositor Terms; no off-chain authority can move depositor capital without an on-chain transaction. Council emergency powers can pause new deposits and/or redemptions in Stage 3+ events but cannot redirect depositor capital to non-LP destinations.
Role-permission matrix (Council seats are the target composition; the Safe is deployed and signers onboarded at vault launch, final seat count being confirmed):
- CEO + acting CTO: root AWS, GitHub admin; targeted Council multisig signer.
- CFO: operational reconciliation, MLRO, treasury attestation; targeted Council multisig signer.
- CRO: operator origination, partnership; targeted Council multisig signer.
- Independent Council members (including an independent auditor / depositor representative seat): remaining targeted Council multisig signers.
- Engineers: code repo write access only; no production AWS write; no multisig signing authority.
Monitoring and Alerts: What monitoring systems exist for positions, margin levels, and trade execution errors? Are alerts routed to humans, and is there 24/7 coverage?
Not applicable in the traditional sense: DualMint has no trading positions, no margin, and no trade execution errors to monitor. The relevant analogues for this protocol are buffer health, cash-flow cross-reference, oracle / bot health, and depositor flow.
Operational monitoring today:
- Off-chain bot health (operational). 4 bots: reconciliation pipeline, Chainlink oracle relayer, NAV calculator, peaq telemetry ingest. Per-bot thresholds: Chainlink relay success rate ≥99.5% per 24h, NAV variance <1% epoch-over-epoch, telemetry cross-reference agreement ≥98% per Vault Smart Contract Spec.
- AWS infrastructure: CloudWatch + CloudTrail multi-region, 90-day hot retention, 1-year S3 cold archive.
- Application + admin dashboard logging: structured JSON to dedicated CloudWatch log group; admin actions written to a separate audit-log stream with full schema. No PII in any log stream.
Designed; deploys with vault contracts (at vault launch): Vault Guardian System (six agents: Liquidity Guardian, Operator Watchdog, Telemetry Verifier, Exit Queue Manager, Risk Aggregator, Alert Dispatcher; 20 metrics; 24/7 automated zone-gate enforcement across Green / Yellow / Orange / Red buffer zones).
Alert routing (severity-tiered per Stage 1 to 4):
- Today: alerts visible in CloudWatch console; CFO + Operations review on a fixed cadence. There is no 24/7 human on-call coverage today. 24/7 automated zone-gate monitoring (Vault Guardian) and severity-tiered paging both go live at vault launch.
- By vault launch: on-call paging tooling under selection, deployed with rotation across CEO + CFO + Operations.
- Stage 1 (Watch) → team chat notification.
- Stage 2 (Yellow) → paged CFO + Operations.
- Stage 3 (Red) → CFO + CEO + Council convened.
- Stage 4 (Critical) → all Council + 72-hour LP communication.
Alert thresholds are informed by 16 months of operational data from the established marketplace lines, not theoretical assumptions.
Redemptions and SLAs: What is the typical redemption process and response time under normal vs. stressed market conditions? Are there formal or informal SLAs for fulfilling redemptions?
Redemption logic per the Operator Default Playbook, Insured Yield Vault Architecture, and Vault Liquidity Risk Framework (also covered by the Redemption Policy and Redemption Priority answers in Section 4):
Normal-conditions SLA:
- 30 days from buffer (Green zone, buffer ≥20% TVL).
- FIFO with priority tiers: (1) base depositors (no lockup, highest priority); (2) boosted depositors at maturity (by lock expiration date); (3) pro-rata within each tier if liquidity is insufficient.
- Penalty interest of 1%/month on redemptions delayed past Day 31 that are not justified by a gate trigger (designed; to be reflected in the signed Depositor Terms).
Stressed-conditions SLA:
- 90-day SLA in Orange zone (buffer 10 to 15%; 60-day notice required for new redemption requests).
- 120-day max in Red zone (buffer <10%; 90 to 120 day max SLA).
- Three independent gates govern; the most restrictive applies (per the Operator Default Playbook):
- Liquidity gate by buffer zone (above).
- Asset-impairment gate: ≥10% of the vault at Stage 2+ → +30 days SLA; >20% → pause all redemptions pending Council review.
- NAV-impairment gate: >5% NAV drop → +14 days; >15% → Council convened, redemption gate review, potential structured wind-down.
Alternative exit routes (designed / under evaluation, not yet live; redemption remains the primary path):
- Secondary-exit venue: we are exploring immediate-exit options; the current lean is a batch auction plus tranching via a third-party AMM. Not deployed; expected to activate around the ~$30M TVL threshold. Initial liquidity sizing is under finalisation.
- Future Morpho borrow against sUSDm (post curator listing, under DD).
Tail-event redemption (all assets depleted scenario): an external stop-gap liquidity facility (in negotiation; provider not disclosed; no signed agreement), which is a liquidity bridge for timing mismatches rather than a loss absorber, activates if consummated to bridge the timing mismatch. DualMint, acting through the BVI SPV's step-in rights as secured party of record, activates a 3 to 6 month wind-down with blended recovery on physical asset liquidation; under the designed legal priority waterfall, LPs recover ahead of DualMint operational and equity claims (to be reflected in the signed Depositor Terms / waterfall docs).
Past redemption events: pre-vault-launch, no vault redemptions to date. NFT marketplace redemption (sale of a holding to a secondary buyer) is operational across 1,300 assets: fluid, no SLA pressure observed.
Incident Response Protocols: Describe incident escalation paths and examples of past disruptions. How are trading halts, custodian outages, or failed hedge events handled?
Trading halts, custodian outages, failed hedge events: not applicable. DualMint is not a trading protocol, so there are no trading halts to manage, no centralised custodian, and no hedge positions. The DualMint-relevant incident classes are operator default, smart contract anomaly, NAV deviation, oracle / data-source failure, and infrastructure / signing compromise.
Today vs at-launch: the escalation framework below is documented. Automated on-call paging and the standing Vault Security Council (with emergency-pause authority) become operational at vault launch; the Council is not yet deployed or onboarded, and paging tooling is under selection. The response-time targets below are the designed SLAs; they are not enforced by paging tooling today (first Council emergency-pause drill on testnet targeted 2026-08-01).
Escalation path (Stage 1 to 4 severity tiers per the Operator Default Playbook + Vault Security Council Charter):
- Stage 1: Watch (single yellow flag): automated alert to CFO + Operations within 1 hour. Internal investigation; no external disclosure. Examples: cash-flow variance 10 to 20% on a single asset, oracle relayer single-event failure, telemetry transient gap.
- Stage 2: Yellow (sustained anomaly): escalation to CFO + CEO within 15 minutes. Operator Watchdog cure period engaged if operator-side. Examples: revenue cross-reference failure on a single operator >24h, NAV variance >1% epoch-over-epoch, off-chain bot down >2h.
- Stage 3: Red (material event): Council convened within 48 hours. Possible Council emergency pause. Examples: confirmed operator default, smart contract anomaly with LP impact potential, NAV variance >5%.
- Stage 4: Critical. Immediate Council convene; emergency pause invoked; 72-hour LP communication; legal counsel notified. Examples: smart contract exploit, multisig signer compromise, regulatory enforcement action, malware compromise of Council signing infrastructure.
Equivalent to a "trading halt": Council emergency pause (per the Vault Security Council Charter) pauses new deposits and/or redemptions. Auto-expires after 7 days unless Council 3-of-5 votes to extend. All extensions are time-bounded and logged on-chain via emergency event emission. Resumption requires Council vote plus post-incident review (filed internally) within 7 days of resume.
Past disruptions:
- Vertriqe (AirUp operator) payment dispute Tx 4 + Tx 6, settled via Tx 8 within OSA cure-period engagement (Appendix A, Vertriqe reconciliation). Operator-level only; no LP impact. Retrospectively classified as Stage 2.
- No Stage 3 or Stage 4 events to date across 16 months of marketplace operation on the established lines.
LP communication: Stage 3+ events trigger 72-hour LP communication. Channels: monthly LP report (institutional), email to depositor of record, on-chain event emission, dashboard banner notification.
Financial
Revenue model, fees, runway, tokenomics, token structure, and reserves.
Fundraising History: Detail all of the historic fundraises, including the date, lead investors, amount raised and valuations.
Closed to date:
- $2M convertible note (2023). Single aligned institutional holder. Outstanding and unconverted, sitting outside the Delaware equity cap table, and expected to convert into Delaware Holdings equity ahead of maturity.
- peaq Holding Ltd $100K Post-Money SAFE. Strategic round, closed 2026-04-01.
- Founder personal capital. Over $200K deployed (skin in the game).
In progress: a raise via DualMint Holdings, Inc. (Delaware). Current raise terms, including sizing, instrument, and use-of-funds allocation, are provided under NDA to qualified investors and are not disclosed in this public packet. The Company Overview deck and the full cap table are provided to qualified investors under NDA.
RWA-specific anchor LPs are targeted for vault allocation after curator endorsement, a separate track from the equity raise.
The LP Program: Detail the current LP program and the target APY, including the amount, lock-up duration and vesting schedule. Is there a target APY and/or a floor APY that guarantees returns regardless of market cap volatility?
The realized, onchain-verifiable record across the established marketplace lines is 15.72% net yield, zero defaults, over 16 consecutive months of distributions. On that basis the Machine Yield Index, a single senior pool, targets a blended ~13 to 15% net effective yield to all depositors after buffer drag, accruing as sUSDm price-per-share appreciation rather than a separate distribution. Returns are variable and tied to operating cash flow: the target is not a floor and not guaranteed.
There is no mandatory lockup. The base (flexible) tier redeems via a 30-day queue. Depositors may make optional 3/6/12-month boost elections, which weight a depositor's share of accrued yield higher through a boost multiplier (longer locks earn more). Boosts redistribute yield across depositors rather than adding new yield; only the locked portion is non-redeemable until its tenor matures.
Tiered boost elections (per the Senior Capital Investment Framework):
| Tier | Boost | Early-exit penalty (DRAFT) | Lockup |
|---|---|---|---|
| Flexible | 1.0× | none | none (30-day redemption queue) |
| 3-month | 1.25× | graduated 25 to 100% of accrued yield | locked portion only |
| 6-month | 1.5× | graduated 25 to 100% of accrued yield | locked portion only |
| 12-month | 3.0× | 5% of principal | locked portion only |
The 12-month tier can reach the mid-20s% effective APY only under a specific cohort mix (where the 12-month lock represents ~30% of TVL) and compresses toward the pool's ~13 to 15% blended yield as long-lock capital dominates (worked example in the Senior Capital Investment Framework). This is a boost-premium artifact redistributed across depositors, not a sustainable standalone APY or new yield. Because boosts redistribute rather than add yield, the flexible (1.0x) tier earns below the blended 13 to 15% and the locked tiers earn above it; all tiers sit on the same 15%+ gross asset yield, so the flexible tier remains competitive. Early-exit penalties are DRAFT design terms, not yet in executed depositor terms. After launch, the dashboard will publish effective APY by tier monthly.
Yield-smoothing policy (Operator Default Playbook): in an impaired period, supplementing affected LPs is funded from DualMint's retained fee income (the 7% net share of the origination and processing fees), not from the ring-fenced first-loss reserves, so the loss waterfall is never drawn down to hold yield. Smoothing is capped at the prior 3-month average, and the liquidity buffer is never used for it.
Equity: Does there exist equity in any legal entity besides the token in (3.4). If so, what does the cap table look like and how much equity exists. How much is for OpEx and future growth? How much, if any, is reserved for first loss, should it occur?
Yes. Equity sits in DualMint Holdings, Inc. (Delaware C-Corp): common stock issued to the founding team (Bill Lee, Hung-Chou Tai, David Sakai; exact percentages per the redacted cap table, available to qualified investors under NDA). The peaq Holding $100K Post-Money SAFE was signed 2026-04-01 as a strategic round.
The current raise is issued by DualMint Holdings, Inc. (Delaware); terms are provided under NDA to qualified investors and are not disclosed in this public packet.
The $2M convertible note is outstanding and has not yet converted, so it does not currently change the equity split. It is held by a single aligned institutional holder and is expected to convert into Delaware Holdings equity ahead of maturity. The cap table is documented in DualMint-Cap-Table.docx, provided to qualified investors under NDA.
Use-of-funds detail for the current raise is provided under NDA to qualified investors and is not disclosed in this public packet. Capital to date is over $200K founder personal capital plus the peaq $100K SAFE.
First-loss reserved: there is no equity-level junior tranche. All loss absorption is per-asset (operator economic exposure via equipment ownership) and portfolio-level (Origination Reserve, Solvency Reserve, two-tier insurance, the Stop-Gap Liquidity Facility, and RFQ liquidation, which are the six non-depositor layers of the loss waterfall). DualMint's operational claims and equity holders rank 3rd and 4th in the legal-priority waterfall; they recover nothing until LPs and the Stop-Gap Liquidity Facility (in negotiation, provider not disclosed) are made whole. The subordination is structural, not policy.
Incentive Alignment: Detail the financial incentives that ensure the long-term alignment of all directors and contributors to the success of the project.
Founder alignment runs on long-dated equity vesting and real capital at risk. Founder equity carries a 12-month cliff plus a 36-month linear vest. Founders have deployed over $200K of personal capital, so they have direct skin in the game.
Subordination is structural, not policy: per the legal-priority waterfall, DualMint's operational claims rank 3rd and equity holders rank 4th, both subordinate to LPs in any wind-down. The current raise is issued by DualMint Holdings, Inc. (Delaware), with terms provided under NDA to qualified investors; the peaq strategic investment (Post-Money SAFE, 2026-04-01) is an equity instrument at the holding-company level.
Operator alignment comes from the 10% origination fee plus equipment ownership as the operator's economic exposure (Layer 1 of the loss waterfall, non-cash; on default the machine is repossessed and reassigned). The operator posts no cash first-loss; their skin in the game is losing the machine and its income stream.
DualMint's protocol revenue comes only from yield (the 10% processing fee on cash flows, never on principal), so there is no incentive to onboard non-performing assets. Council compensation is paid from DualMint's operational treasury, never from vault assets.
Alignment today is structural: subordination below LPs, unpaid founders, and over $200K of founder capital at risk. Founder upside is equity in the holding company; explicit performance triggers tied to vault performance are an open documentation item, not yet contractual.
Financial Runway: What is the current burn rate and the implied financial runway?
Current out-of-pocket monthly burn is ~$29,472 (engineering, marketing, legal-adjacent tools, and vault infra/monitoring/ops), founders currently unpaid, meaningful skin in the game. On closing the raise, founder salary is reinstated at $10K/mo (below-market), taking fully loaded burn to ~$39,472/mo.
Runway extends materially on closing the current raise via DualMint Holdings. Raise sizing, use-of-funds allocation, and the resulting runway calculation are provided under NDA to qualified investors and are not disclosed in this public packet. Precise runway depends on raise timing and the recurring commission run-rate (currently ~$733/mo, offsetting burn slightly).
Capital to date:
- over $200K founder personal capital deployed (skin in the game).
- peaq Holding Ltd, $100K Post-Money SAFE, strategic round, closed 2026-04-01.
- $2M convertible note (2023), single aligned institutional holder, outstanding and unconverted, expected to convert into Delaware Holdings equity ahead of maturity.
- Current raise (DualMint Holdings, Delaware), in flight; terms provided under NDA to qualified investors.
Forward: pre-launch burn carries one-time legal and insurance-placement spend. Post-launch, origination (10% of asset value) and processing (10% of cash flow) fees offset operational cost; self-sustaining target at ~$25M TVL.
Detailed infrastructure inventory, the fully-loaded burn model, and related-party vendor arrangements are available in diligence.
Fee Generation: Does the protocol charge fees for the usage of the protocol? What is the purpose of these fees? Which parties benefit from these fees and how are they distributed?
Two protocol fees:
(a) Origination Fee, 10% of asset value, paid by the operator at onboarding, not deducted from LP capital. Of that fee, 30% (= 3% of asset value) is carved into a segregated, ring-fenced Origination Reserve that protects LP principal as Layer 2 of the loss waterfall. The remaining 70% of the fee (= 7% of asset value) is DualMint income.
(b) Processing Fee, 10% of cash flows, deducted from yield monthly, never from principal. Of that fee, 30% (= 3% of cash flow) funds the Solvency Reserve (Layer 3 of the waterfall); the remaining 70% (= 7% of cash flow) is DualMint income, covering servicing, IoT monitoring, reconciliation, and platform operations.
There is no management fee (no AUM-based charge) and no performance fee. Because the origination fee is paid by the operator and DualMint earns income only on yield rather than on principal, there is no incentive to onboard non-performing assets.
Beneficiaries: DualMint (operations, the 7% income portion of each fee) and the two ring-fenced reserves that sit in the loss waterfall (the 3% carves from origination and processing, protecting LP principal). At current marketplace scale (~$7,500/mo of cash flow processed) the reserve balances are early-stage; both scale with origination volume and vault TVL. See the GitBook docs for the full fee and waterfall mechanics.
Revenue Model: How does the protocol generate or plan to generate revenue? If the protocol is already generating revenues, are there dashboards or reports tracking these metrics?
Two revenue streams.
(1) Marketplace (live). The two seasoned machine lines have a 16-month track record of monthly distributions since May 2025, currently processing ~$7,500/mo of cash flow, with zero operator defaults. The broader marketplace roster spans multiple machine and robotics lines, with further categories incoming; 1,310 positions originated and sold onchain. DualMint's revenue is a minting commission (on origination) plus a yield commission (on cash-flow processing), standard 10%, with some early deals at 5%. To date DualMint has earned $18,580.90 in commissions (minting + yield), and $52,602.60 in cash flow has been distributed to investors onchain across the established lines. Both figures are sourced from DualMint's dashboards and are onchain-verifiable. Revenue is early-stage and stated at its actual run-rate, not scaled up.
(2) Machine Yield Index (upcoming, not live). Same fee structure, scaled to vault TVL; yield accrues to depositors as sUSDm price-per-share rather than as separate distributions. As an illustrative example at $100M TVL, 20% gross asset yield (the midpoint of the 15 to 25% historical range on operating cash flow before buffer drag), and up to 80% deployed: annual cash flow ~$16M, annual processing fee ~$1.6M (10% of cash flow), with the balance accruing to depositors. These are illustrative figures, not projections or guarantees.
Reporting: the marketplace has live transfer records (Appendix A, Vertriqe reconciliation). The vault will publish a monthly NAV and distribution dashboard, with aggregate metrics on a public dashboard once it is live. See the GitBook docs for vault mechanics.
Economic Flow: Please diagram or describe the full flow of value across the protocol and any service providers: who earns what fees, in what order, and under what conditions (e.g., vault fees, spreads, rebates, token emissions, OTC splits).
Value moves through the protocol in a fixed order:
- Operator pays the 10% origination fee at onboarding. 30% of that fee (= 3% of asset value) is carved into a segregated, ring-fenced Origination Reserve (DualMint's committed first-loss cash, Layer 2 of the loss waterfall). The remaining 7% is DualMint income.
- Asset is deployed under an Operator Security Agreement (OSA), and the operator runs the business. IoT-instrumented payment systems collect the monthly cash flow, cross-referenced against operator-system API access.
- In the designed vault flow (vault not yet live), the vault's routing logic applies the cash-flow waterfall per asset:
- (i) principal recovery first, up to that period's amount due, which reduces unrecovered capital on that asset;
- (ii) the 10% processing fee, of which 30% (= 3% of cash flow) funds the Solvency Reserve (Layer 3 of the loss waterfall) and 70% (= 7%) is DualMint income;
- (iii) the residual, net yield, routed to the vault.
- Yield accrues to depositors as sUSDm price-per-share appreciation. There is no separate distribution event at the vault. Lockup tiers carry boost multipliers that weight a depositor's share of accrued yield (longer locks earn more), a redistribution across depositors rather than an external subsidy.
No token emissions. No spreads, because DualMint is not a market-maker. No OTC splits. No rebates. End-to-end value-flow diagrams (revenue flow via the SPVs, and the default/recovery flow) are in the GitBook docs.
Reserve & Insurance Mechanisms: Are there any dedicated reserves, safety modules or insurance pools in place to absorb losses from unforeseen market shocks, contract exploits or systemic events? If any, detail the size of each reserve/insurance component.
What exists today. Two protection layers are funded and operating now: the Origination and Solvency reserves (DualMint cash) and Tier 1 operator-carried asset insurance (in force). Layer 1 asset recovery and reassignment is contracted through the OSA and SPV step-in rights. The remaining layers (the Tier 2 performance bond, the Stop-Gap Liquidity Facility, and RFQ liquidation) are designed and being placed or negotiated. Tier 2, a performance bond covering operator non-performance rather than asset residual value, is the load-bearing layer for LP principal and is not yet bound: the central protection gap (see qa-offchain-risk-04).
Reserve and insurance architecture maps to the canonical six-layer loss waterfall (all non-depositor capital; see the GitBook docs). Depositor principal sits last: it is what the layers protect, not a layer itself. The vault liquidity buffer is separate: it is undeployed depositor capital that funds redemptions, not loss absorption, and is never counted as a loss layer.
Loss-absorbing reserves and insurance (strict order):
Origination Reserve (Layer 2, cash): 30% of the 10% origination fee, equal to 3% of asset value, carved into a segregated, ring-fenced reserve at onboarding. The remaining 7% is DualMint income. This is DualMint's own committed first-loss cash, drawn after asset recovery (Layer 1) for any residual shortfall. Operators post no cash; their economic exposure is equipment ownership (Layer 1), recovered via repossession and reassignment.
Solvency Reserve (Layer 3, cash): 30% of the 10% processing fee, equal to 3% of monthly cash flow, carved into a segregated reserve. The remaining 7% is DualMint income. Builds with every monthly distribution, held in stablecoins. Funded from DualMint's processing share, so LP yield is unaffected. Drawn after the Origination Reserve for any residual shortfall.
Insurance, two-tier (Layer 4, off-chain): a single waterfall layer with two components. Tier 1 is commercial asset insurance on the physical machines (theft, fire, physical damage, loss), carried by the operator and already in force per asset class, with loss-payee written into operator agreements. Tier 2 is a performance bond covering operator non-performance, priced on non-performance rather than asset residual value; placed through YAS (Hong Kong MGA, licence FA2648) and carried by Zurich, in discussion, not yet bound; actual terms are set at placement, since no policy is held today. This gap is market-wide: no live carrier writes true payment-default insurance, a gap shared by every comparable protocol (market context: Offchain Risk section).
Stop-Gap Liquidity Facility (Layer 5, cash): an external cash / liquidity facility that bridges redemption timing and provides the floor bid for LP secondary exit. In negotiation; provider not disclosed while terms are being finalised; not yet executed.
RFQ liquidation (Layer 6): the final layer before depositor principal; last-line liquidity sourced from funds, LPs, and OTC desks via RFQ, drawn only after Layers 1 to 5 are exhausted.
Smart-contract / custody / crime (exploit) cover is maintained as a separate program, not a numbered waterfall layer; it is under evaluation.
Not loss-absorbing (liquidity, kept separate from the waterfall):
- Vault liquidity buffer: 15% minimum/target, color-coded zone-gate enforced (green >20% / yellow 15 to 20% / orange 10 to 15% / red <10%), held higher during the early deployment ramp. This is undeployed depositor capital; it cannot protect depositors from loss because it is their own money. Its job is redemption liquidity and limiting deployed exposure.
- Stop-gap liquidity facility: external revolving facility (in negotiation; provider not disclosed while terms are being finalised, no signed agreement). Bridges redemption timing mismatches only; does not absorb asset losses; recovers in the LP tier of legal priority.
Other coverage:
- D&O insurance: being sourced, not bound. Covers ordinary fiduciary claims; gross negligence and wilful misconduct excluded.
Loss-event sequencing in extreme tail: most loss events resolve at Layer 1 (recovery and reassignment of the machine) with no cash drawn. Depositor principal is impaired only after Layers 1 to 6 are exhausted.
Insurance carrier failure mitigation: the Origination Reserve and Solvency Reserve (Layers 2 to 3) are independent of any commercial carrier; insurance carriers (Layer 4, both tiers) will be selected with credit-rating diligence at policy placement.
Counterparty Risk: List all of the material counterparties that a proper functioning of the protocol relies on and provide information on the size of the respective risk exposure.
Material counterparties and exposure sizing:
Tier 1, operational counterparties (capital exposure):
Operators (machine and robotics operators): primary capital exposure. Risk mitigated by the canonical six-layer loss waterfall (Collateral & Strategy: Loss Waterfall), with Layer 1 asset recovery & reassignment absorbing first (mechanics and recovery targets: Collateral & Strategy: Bad Debt Management). Concentration limit 15% single operator (pre-loss defence). 1,310 positions across multiple operators give diversification at portfolio level.
Insurance carriers (asset insurance Tier 1 per asset class, operator-carried and in force; Tier 2 performance bond covering operator non-performance via YAS (Hong Kong MGA, licence FA2648), carried by Zurich, in discussion, not yet bound). Failure mode: carrier insolvency or claim denial. Mitigation: the Origination Reserve and Solvency Reserve (cash, Layers 2 to 3) are independent of any carrier; carrier credit-rating diligence at OSA execution. Operator covenant requires continuous certificate validity; lapse triggers OSA cure period. The BVI SPV (DualMint Ltd.) is the secured party of record, bankruptcy-remote, holding title and step-in rights over the financed machines (structure: Operational: Organizational Structure; enforcement: Collateral & Strategy: Bad Debt Management). There is no separate third-party collateral agent.
Tier 2, infrastructure counterparties (operational dependency, not capital exposure):
Concrete ERC-4626 vault framework: protocol-level dependency. Risk: framework bug or exploit affecting vault accounting. Mitigation: the vault launches on Concrete's independently audited ERC-4626 stack as deployed, so DualMint introduces no unaudited core vault code at launch, keeping the contract surface minimal.
M0 (stablecoin infrastructure): extension-token dependency for the vault's M0-extension token (USDm). Risk: M0 protocol issue affecting the extension token. Mitigation: M0 is an established stablecoin infrastructure partner, also used by Daylight (an RWA-adjacent peer).
Chainlink (oracle layer): data provenance dependency. Risk: oracle outage or compromised data. Mitigation: 2-source cross-reference (IoT telemetry + operator-system API) per Vault Smart Contract Spec means single-source oracle failure does not block NAV. DualMint is in the Chainlink BUILD program and the oracle integration is live.
peaq Network (IoT telemetry layer): data source dependency. Risk: peaq network outage or Machine ID compromise. Mitigation: 2-source cross-reference as above; peaq strategic investor (peaq Holding $100K SAFE 2026-04-01).
Operator-system APIs (POS / payment-rail data): data source dependency. Risk: API outage or coverage limitation. Mitigation: 2-source cross-reference; backup providers under evaluation.
AWS (cloud infrastructure): single-region dependency at launch (ap-southeast-1). Risk: regional outage. Mitigation: multi-region failover plan post-launch (out of scope for v1). Vercel (frontend) is multi-region by default.
Tier 3, service counterparties:
Blockpass, KYC/KYB. Risk: compliance failure. Mitigation: ongoing diligence on the Blockpass DPA plus sanctions-screening confirmation.
Horizons Law (general + US counsel) + Pacifica Legal (Panama counsel), legal counsel. Both engagement letters are signed. Risk: scope failure or insufficient regulatory analysis. Mitigation: US securities-law coverage is provided by Horizons Law (engaged), and Panama regulatory/AML analysis by Pacifica Legal; counsel is engaged, not pending.
External stop-gap liquidity facility: a timing-mismatch bridge only, not loss-absorbing. In negotiation; provider not disclosed while terms are being finalised, no signed agreement. Risk: facility unavailable when needed. Mitigation: alternative liquidity at the vault-token layer (secondary-exit venues under evaluation, such as a batch auction with tranching via a third-party AMM, plus a Uniswap v3 sUSDm pool); this facility is one of multiple paths.
Reserve and insurance counterparties (per the canonical six-layer waterfall):
Origination Reserve: 30% of the 10% origination fee (= 3% of asset value) is ring-fenced as DualMint's own committed first-loss cash (Layer 2 of waterfall); the remaining 7% is protocol income. Held in Council multisig treasury, drawdown gated by 2-source oracle consensus (no single-party authority).
Solvency Reserve: 30% of the 10% processing fee (= 3% of monthly cash flow) is carved into a segregated reserve (Layer 3); the remaining 7% is protocol income. Builds with every monthly distribution, held in stablecoins; funded from DualMint's processing share, so LP yield is unaffected.
Insurance carriers (Layer 4, off-chain, two-tier): Tier 1 asset insurance on the physical machines per asset class, carried by the operator and already in force; operator must maintain certificate validity continuously, and lapse triggers an OSA cure period. Tier 2 is a performance bond covering operator non-performance, priced on non-performance rather than asset residual value, placed through YAS (Hong Kong MGA, licence FA2648) and carried by Zurich; in discussion, not yet bound.
External stop-gap liquidity facility: in negotiation; provider not disclosed while terms are being finalised, no signed agreement. If consummated, it bridges redemption timing mismatch only (does not absorb loss) and recovers in the LP tier of legal priority.
D&O insurance: being sourced, not bound. Covers ordinary fiduciary claims; gross negligence and wilful misconduct excluded.
Smart-contract / custody / crime (exploit) cover: maintained as a separate program, not a waterfall layer. Under evaluation; no provider bound, coverage tier and pricing pending.
Loss-event sequencing (qualitative, no validated stress model): We have not published a calibrated portfolio stress model, and recovery rates are unmeasured because there has been no live default or wind-down to date. Qualitatively: small defaults are expected to resolve at Layer 1 recovery plus the Origination Reserve with no LP impact; larger correlated defaults would draw the Solvency Reserve, the insurance and liquidity layers (most unbound or unexecuted today), and in the extreme would trigger a structured wind-down via the BVI SPV's step-in rights with potential principal impairment. This is the central, disclosed execution risk; we do not state a specific portfolio-default percentage at which principal is impaired because no model backs such a figure.
Insurance carrier failure mitigation: the Origination Reserve and Solvency Reserve (cash, Layers 2 to 3) are independent of any commercial carrier; insurance carriers (Layer 4, both tiers) selected with credit-rating diligence at OSA execution.
Common Investor Objections & Responses
Pre-answered objections from institutional LPs.
Are token holders effectively buying equipment and renting it to businesses with 4-8 year payback periods?
Yes in essence, though the structure is more specific than "buying and renting." Token holders hold a claim on the cash flows from a finance lease (lease-to-own), with a DualMint-owned SPV holding the equipment for the duration of the term.
Mechanics
- A DualMint-owned BVI SPV (single SPV now; one per asset class as the portfolio scales) owns the equipment during the lease term.
- The operator leases the equipment from the SPV and runs the day-to-day operations.
- Operator lease payments flow through the SPV → Boring Vault Corp (Panama) → Panama PIF → vault depositors as yield.
- At the end of the term, ownership of the equipment transfers to the operator (lease-to-own / finance lease).
- During the term, the SPV holds enforceable step-in rights via the lease agreement: if telemetry or payments show underperformance, the SPV can terminate the lease, repossess the equipment, and reassign it to a replacement operator without judicial process (mechanics: Collateral & Strategy: Bad Debt Management).
Why this works for token holders
- LPs hold a claim on lease-payment cash flows, not direct ownership of physical equipment. The equipment is collateralised by SPV ownership during the term.
- The asset is self-amortizing: as the lease is paid down, the loss exposure on residual value reduces over time. The portfolio de-risks itself.
- Operator failure during the term doesn't equal LP loss: the SPV repossesses and reassigns the asset, and the new operator picks up lease payments.
Payback periods (design parameters, by category)
- Financing terms run roughly 18-36 months by category (design parameters from the category playbooks), not 4-8 years. Category-level figures are playbook assumptions; only the seasoned machine lines carry 16 months of live history.
- Early principal recovery supported by the 10% operator origination fee paid at entry
The "4-8 year payback" framing of the original question does not hold for DualMint specifically. Token holders are also not locked into a single operator: if performance deteriorates during the term, the SPV terminates the lease and reassigns the asset. Recovery economics are modeled from category resale data, with the live-default track record disclosed in the Offchain Risk gaps answer (qa-offchain-risk-04).
For the full lease-to-own structure and asset-class mechanics, see the GitBook docs.
What happens if the business closes, the operator fails, or the equipment stops generating revenue?
Investor capital is the last loss. Six sequential layers of non-depositor capital sit ahead of it, drawn in strict order: (1) asset recovery & reassignment (non-cash: the SPV repossesses the machine and redeploys it to a replacement operator; modeled recovery 70 to 95% via reassignment, 50 to 80% via liquidation), (2) the Origination Reserve (3% of asset value, DualMint's own ring-fenced first-loss cash), (3) the Solvency Reserve (3% of monthly cash flow, building with every distribution), (4) two-tier insurance (Tier 1 asset cover in force; Tier 2 performance bond via YAS/Zurich, in discussion, no provider bound), (5) an external stop-gap liquidity facility (in negotiation, not executed), and (6) RFQ liquidation. The layer-by-layer walk, funding status, and drawdown sequencing are at Collateral & Strategy: Loss Waterfall; recovery mechanics at Collateral & Strategy: Bad Debt Management.
Liquidity (separate, not loss absorption): the vault liquidity buffer (undeployed depositor capital) plus amortisation throw-off and the secondary market service the redemption SLA. The stop-gap facility is a liquidity bridge, not a loss absorber.
Historical performance (established marketplace lines): 16 consecutive months of distributions since May 2025, zero operator defaults, zero principal losses across 1,310 positions originated and sold onchain.
In practice: If an operator closes their business, the equipment doesn't become worthless. The SPV exercises repossession rights and redeploys the asset to a replacement operator, targeting a 14 to 45 day transition. Cash flow may pause during transition, but the operator's economic exposure (equipment ownership) and the Origination Reserve are designed to absorb downtime. The default mechanics are documented in the GitBook docs.
How do you handle credit risk in a market where SMEs traditionally have high default rates?
Short answer: We transform credit risk into usage risk plus recovery-execution risk. Instead of underwriting whether an operator will repay, we underwrite whether the machine will generate cash flow, scored continuously by the Asset Performance Index, and we hold the equipment as collateral so a failed operator is replaced rather than written off. The risk is not eliminated, it is converted into something observable and recoverable.
DualMint does not extend unsecured credit to operators. Instead, we underwrite usage risk: the machine's ability to generate cash flows regardless of operator creditworthiness.
Key Differences from Traditional Credit:
| Traditional SME Credit | DualMint Usage Risk Model |
|---|---|
| Asks: "Will the operator pay back the loan?" | Asks: "Will the machine generate cash flow?" |
| Underwrites operator's credit score | Underwrites machine's usage metrics (IoT data) |
| High exposure to operator failure | Limited exposure: operators are swappable |
| Unsecured or partially secured loans | Secured by equipment + step-in rights |
| Single operator, single point of failure | Operator redundancy via existing network + vendor-financing onboarding |
| Quarterly financial statements (lagging) | Real-time IoT telemetry (leading indicators) |
How We Transform Credit Risk into Usage Risk:
- Asset Ownership or Legal Control
- SPV owns equipment or holds enforceable step-in rights
- Operators do not own the equipment outright (finance lease, revenue-share)
- If operator defaults, asset is recovered, not written off
- Operator Swappability
- Because the SPV holds title, a defaulted operator can be replaced without writing off the asset; the machine keeps generating cash flow under the new operator
- Replacement channels and handoff playbook: Collateral & Strategy: Bad Debt Management
- Asset Performance Index and IoT Monitoring
- Real-time usage data (cycles, transactions, uptime) via Peaq integration feeds the Asset Performance Index (0 to 100 composite), which gates origination, monitoring intensity, and vault eligibility
- Early warning indicators trigger intervention before defaults occur
- Underperformance thresholds (flagging operators ~40%+ below benchmark, with a ~14-day review window) are playbook parameters set from the seasoned lines' operating data
- Collateral, Not Unsecured Exposure
- The collateral is title-retention: the bankruptcy-remote SPV holds legal title to the equipment, the operator holds a revocable licence and posts no cash, and DualMint holds contractual step-in and repossession rights via the Operator Security Agreement (OSA)
- Operator pays a 10% origination fee at onboarding; 30% of it (= 3% of asset value) is ring-fenced as the Origination Reserve first-loss layer
- The financed amount is sized below replacement value by category, so recovery sits below the asset's resale value at the deal level, with no asset markup on top
- Diversification Across Categories
- Vault spreads capital across multiple independent machine and robotics categories as they qualify
- Concentration limits cap exposure at 10% per single asset, 15% per single operator, and 50% per sector
- Category-level risk is uncorrelated (failure in one machine category doesn't predict failure in another); early concentration is a ramp stage, not a structural ceiling (the full concentration argument: Collateral & Strategy: Historical Drawdowns)
Result: The model structurally mitigates traditional credit risk by converting it into usage risk. Operator failure is recoverable rather than a write-off, with the residual being execution risk on that recovery (live-default track record disclosed in the Offchain Risk gaps answer, qa-offchain-risk-04). Asset failure, rare for predictable equipment categories, is the other residual, addressed by IoT monitoring, diversification, and redeployment.
The category-level underwriting and the loss waterfall are detailed in the GitBook docs.
If an operator defaults, is it really easy to find another operator and redeploy the asset?
Structurally yes, but not because a backup roster sits on standby. The incoming operator is offered a fully-amortized, located, telemetry-equipped machine on revenue share: no capex, no financing, an established customer base, and 6-12 months of utilization history handed over. A nearby operator who would never fund that deployment from scratch takes it on revenue share. The machine is the moat, not the operator.
- Local peer network: operators in the same category nearby; each onboarded operator names 2-3 local peers at onboarding
- Venue / property operator: when the asset sits in a mall or commercial property, the venue's ops team is a natural step-in
- Dealer referrals: regional machine and robotics equipment dealers refer local operators at need (finder's fee + service-contract retention)
- Industry associations: distressed-asset bulletins within category trade groups
Inducements (under design, not finalized): 30-day transition working capital from the origination fee buffer, reduced 5% processing fee for the first 6 months, optional path to acquire the asset at appraised value after 18 months of clean performance.
Simulated redeployment SLA (no live default to date):
- Telemetry trigger to cure notice: days 0-7
- Cure period: 7 days
- SPV step-in declared (no judicial process): T+14
- Channel activation, backup selected: T+14 to T+21
- Lease assignment + cash management transition: T+21 to T+30
- Full handoff, revenue resumption: T+30 to T+45
Revenue gap to LPs: 30-45 days, smoothed by the liquidity buffer and amortisation throw-off (buffer is liquidity, not a loss layer).
Record: 0 defaults, 0 redeployments across 16 consecutive months and 1,310 positions. DualMint will publish the first live channel-activation case study (response time, cost actuals, revenue gap) within 30 days of the first default event.
How do you underwrite new asset categories without a historical track record?
DualMint uses a structured incubation phase to validate new categories before adding them to the pooled vault.
Incubation Phase Process (3-6 Months):
- Initial Funding via 1:1 NFT Tokens (Not Pooled Vault)
- Fund 10-20 assets in a new category through individual bespoke NFT tokens
- Each NFT sold directly to retail investors represents one specific asset
- Operators pay origination fees and sign revenue-share agreements
- Capital raised: ~$300K to date through this incubation mechanism (a subset of total marketplace primary sales)
- Data Collection Period (3-6 Months)
- Collect continuous usage data across different operators and locations
- Monitor payment consistency, maintenance patterns, failure modes
- Track seasonality, geographic variance, operator behavior
- Build dataset for category-level performance modeling
- Category-Level Performance Analysis
- Build the Asset Performance Index (API) baseline from real telemetry: uptime, utilisation, revenue consistency, operator track record
- Determine category-specific payback periods, volatility bands, durability
- Identify early warning indicators and performance thresholds
- Create category playbook with standardized underwriting parameters
- Vault Inclusion Criteria
- Performance must be predictable across multiple operators
- API scores hold above the category floor across real cash flow data
- Category playbook documented with clear risk parameters
- Only add to pooled vault once the empirical risk profile is established
Example: a live machine category
- Status: graduated from incubation; live on the marketplace and fully allocated
- Path taken: seeded as 1:1 NFTs, telemetry collected across plays/day, prize cost %, and foot-traffic correlation, then opened to the broader roster once the performance profile held
Example currently in incubation: a new machine category
- Status: incoming Q3 2026, not yet live
- Key metrics tracked: sessions/day, kWh dispensed, uptime, site utilisation
- Vault inclusion: only after the data-collection window produces a stable performance profile
Benefits of Incubation Model:
- Vault only includes assets with proven, measurable performance
- Eliminates cold-start problem (no pooled capital exposed to untested categories)
- Creates clear pipeline where new asset types earn their way into vault
- Retail investors funding 1:1 NFTs serve as category validation capital before vault inclusion
Result: By the time a category enters the Machine Yield Index vault, DualMint holds 3-6 months of empirical data on its cash flows, volatility, redeployment options, and API score history. Vault safety compounds with scale rather than degrades. The incubation criteria and asset-class playbooks are documented in the GitBook docs.
What is DualMint's role in the ecosystem? Are you a marketplace, a lender, a fund manager, or something else?
DualMint is onchain equipment financing: cash-flowing SMB equipment leasing, paid out monthly. The protocol finances revenue-generating machines and robotics, leases them to local operators, and distributes the operating cash flow to onchain depositors. It is not a marketplace, a lender against borrower credit, or a fund picking tradable securities. It is the full-stack infrastructure that runs the equipment-leasing lifecycle end to end:
1. Origination & operator sourcing
- Source operators via ecosystem partnerships (Peaq, Arbitrum) and channel structures (vendor financing, territory distributors)
- Category-specific sourcing pipelines (franchises, equipment distributors, and more)
2. Underwriting & risk evaluation
- Develop category-specific underwriting frameworks (usage metrics, financing-to-replacement-value ranges, payback periods)
- IoT-based risk scoring (telemetry via vendor APIs and Peaq Machine ID, pulled periodically and on-demand)
- Incubation phase for new categories (3-6 months data collection via 1:1 NFTs)
3. Legal structuring & SPV management
- Form SPVs to isolate vault liabilities and hold equipment title
- Draft finance-lease, revenue-share, and asset-assignment contracts
- Manage step-in rights, repossession logistics, and operator KYB
4. Tokenization & onchain infrastructure
- Mint ERC-4626 vault tokens (Concrete technology)
- A USDm ERC-20 stablecoin layer (M0 integration) is designed, not yet live
- USDC settlement and reserves (Circle)
- Price feeds and proof-of-reserves (Chainlink)
- Onchain settlement of cash flow distributions
5. Marketplace liquidity
- P2P orderbook for 1:1 RWA NFTs (live marketplace)
- A secondary venue for sUSDm vault-share trading (a batch-auction venue with an external floor-bid backstop) is designed, not yet live
6. Yield routing & distribution
- Collect cash flows from operators (onchain or via payment rails)
- Marketplace NFTs distribute USDC/USDT monthly; vault yield accrues as sUSDm price-per-share appreciation rather than separate distributions
- Manage the liquidity buffer (15% minimum target, color-coded zones) for redemption smoothing
7. Vault architecture & portfolio management
- Balance vault exposure across categories (concentration limits: 10% single asset, 15% single operator, 50% single sector)
- Rebalance as new operators onboard
- Monitor performance and trigger interventions when needed
8. Reserves & protocol operations
- Origination Reserve and Solvency Reserve management (the cash first-loss layers of the waterfall)
- Asset insurance and the Tier 2 performance bond program (being sourced)
- Multi-sig treasury controls
Ecosystem partners:
- Peaq: Machine ID layer for telemetry attestation; operator sourcing in machine-economy verticals
- Arbitrum: Primary L2 deployment; grant program; distribution
- M0: Stablecoin infrastructure for the designed USDm layer (not yet live)
- Concrete: ERC-4626 vault standard
- Chainlink: Price feeds, proof-of-reserves attestation
- Circle: USDC settlement and reserve currency for distributions
In function: DualMint operates as a private-credit aggregator's underwriting-and-servicing stack for SME equipment: it aggregates, underwrites, and manages a diversified portfolio of machines, with a data layer that grows with every deployed asset.
What DualMint does not do:
- Operate the equipment directly (operators handle day-to-day operations)
- Take custody of investor funds outside SPV structures
- Speculate on asset prices or engage in prop trading
- Issue uncollateralized credit or unsecured loans
Result: DualMint is the infrastructure layer that turns SME equipment cash flow into onchain yield, from origination through to distribution. The full architecture is documented in the GitBook docs.
Does the team have the capacity to manage this operationally? How can a lean team handle $50M-$100M in financing?
Short answer: the vault replaces bespoke deal-by-deal work with programmatic financing, so capacity scales with system maturity rather than headcount. The Asset Performance Index does the underwriting work that a credit analyst would do by hand.
Today (1:1 marketplace): 9 employees. 1,310 positions originated and sold onchain, 16 consecutive months of distributions on the established lines, zero defaults, $50M+ operator pipeline. Constraint: manual deal structuring per 1:1 NFT.
What changes at vault launch: category playbooks and API scoring replace manual diligence, IoT telemetry feeds reporting without human intervention, one pooled vault structure replaces hundreds of individual deals, and onboarding is largely automated (Blockpass KYB, template contracts, self-serve IoT activation via Peaq). Origination and local operator management shift to vendor-financing and territory-distributor channels (program status and mechanics: the pipeline-scaling answer in this section). A decentralized validator network for field checks is in development.
Capacity ladder:
- Near term: published TVL ladder, $500K Month 1 to $10M Month 6, on the existing team plus automation
- Year 2: $50M-$100M TVL, adding 1-2 ops hires and an institutional BD lead
- Year 3 (illustrative): $100M-$300M TVL at 8-12 total headcount, against 50+ for a traditional private credit fund of comparable size, where underwriting and servicing are bespoke
Onboarding a new operator post-launch runs near-fully automated: KYB, SPV title transfer and OSA execution at onboarding, auto-generated revenue-share agreements, self-serve IoT activation, onchain cash-flow routing. The full-scale build proves out at vault launch; the honest gaps are catalogued in the honest-gaps answer (Off-chain Risk).
How do you scale your pipeline and risk evaluation without massive headcount expansion or sacrificing underwriting quality?
Scaling runs through external channels, category playbooks, and partner ecosystems, not BD headcount. Status upfront: the channel program is in draft and early appointment; the track record to date was originated by the core team and existing ecosystem relationships.
Channel structures (rolling out, not fully operational):
- Embedded vendor financing. Machine manufacturers and distributors bring the buyers and operators (they already sell the equipment); DualMint is the financing rail. Origination travels with existing sales channels.
- Territory distributors. Appointed local representatives hold geographic + category territory with full-stack responsibility: sourcing, onboarding, monthly monitoring, swap-out coordination. Under the draft program they post first-loss capital (a territory bond) and earn a vested share of origination and processing fees. The bond is channel-level alignment on distributor-sourced deals, not a layer of the vault loss waterfall.
- Compliance gate: KYC on every distributor, KYC + KYB on every operator via Blockpass with automated sanctions monitoring. No deal closes without clean results.
Category playbooks (target parameters; validated on the seasoned machine lines):
- Asset Performance Index (API) floor per category, scored from IoT telemetry
- Usage thresholds (minimum daily usage counts per category)
- Payback benchmarks ~18-30 months; maintenance assumption <10% of monthly revenue
- Seasonality patterns per category
- Intervention trigger: usage 40%+ below benchmark for 30+ days starts redeployment
Underwriting cost falls with category depth: first 10 assets template-driven on the API score with analyst review, 11-50 semi-automated against the playbook, 51+ programmatic. Every deployed machine adds data (usage by geography and season, installation conditions, recovery timelines, operator scoring, category loss tables, unit economics), so pricing accuracy compounds with volume. Dataset licensing is future optionality, not a current revenue line.
Partner pipelines: Peaq (IoT device and operator network; robotics, micro-factories, autonomous vehicles) and the Arbitrum ecosystem (protocols and DAOs needing equipment financing) carry built-in operator networks DualMint sources from.
Robotics fleets are the sharpest fit for this model: IoT-native telemetry and a revenue-share structure that underwrites what fixed-amortisation lenders cannot (the full argument is in the Competitors answer, Operational section). Mid-market RaaS operators run $10M-$100M fleets, the ticket size that scales the vault on a single relationship.
Timeline:
- Months 0-6: internal underwriting + ecosystem pipelines; TVL ladder $500K Month 1 to $10M Month 6; core team + PE advisor.
- Months 6-12: first distributors onboarded in 3-5 geographies posting bonds; 5+ playbooks documented; capacity $50M-$100M TVL; +2-3 ops hires.
- Months 12-24: channels at scale, automated underwriting for mature categories; team 8-12 people (vs 50+ for traditional private credit).
The channel program builds toward this over the timeline above; the honest gaps are catalogued in the honest-gaps answer (Off-chain Risk). Sourcing and underwriting framework: GitBook docs.
How do I get out? Redemption and liquidity under normal and stressed conditions
DualMint's assets are equipment cash flows. They pay back steadily, but they are not instantly liquid, so the liquidity design gives a depositor three ways out, matched to how quickly they need the money.
1. Redeem at NAV through the queue. The standard redemption SLA is 30 days, 90 days under stress, 120 days maximum. The depositor receives full net asset value. The buffer and incoming amortization fund it.
2. The buffer and self-amortization do the work in the background. The vault holds a 15% target liquidity buffer, held in stablecoins and never deployed, monitored by zone (green above 20%, yellow 15 to 20%, orange 10 to 15%, red below 10%). On top of that, every asset amortizes as it runs: the machines return principal steadily, so the book self-liquefies over time rather than depending on forced asset sales.
3. Instant exit through a secondary floor. For a depositor who will not wait for the queue, the design routes to a secondary venue backed by a committed floor bid, so there is always a buyer at a transparent, bounded discount. This layer is a designed backstop being sourced; it is not yet bound.
How this sits against the field. Redemption gating on illiquid credit is standard, onchain and off, and DualMint sits at the more-liquid end of it.
- Apollo's flagship private-credit BDC caps redemptions at 5% of NAV per quarter. In a stressed quarter it received requests for 16.8% of NAV and honored a fraction of them.
- Midas's mF-ONE, the largest RWA market on Morpho, targets a 10% instant sleeve and caps core redemptions at 5% of fund NAV per quarter.
- DualMint's 15% target buffer and 30-day standard SLA are more liquid than both.
The same subordination logic underpins DualMint's loss waterfall: capital positioned to absorb losses first, DualMint's own reserves and insurance, sits ahead of capital positioned to absorb losses last, depositor principal. It's the same discipline behind senior-versus-junior tranching in onchain credit, such as Centrifuge's senior and junior tranches, applied to protocol capital rather than a depositor-facing tranche split.
Proven versus designed. The buffer, the SLA, and self-amortization are core vault mechanics. The secondary instant-exit floor is a designed backstop being sourced, not a bound facility today. A detailed liquidity-stress model, with sizing and reference data from comparable protocols, is available in diligence.