defirisk.co
rubric v1.7.0

Guardian/pause-keeper distinct from upgrader

Superstate's assessment for RD-F-034 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

pause() and accountingPause() are callable by owner (the upgrade EOA), not a separate guardian role. No dedicated guardian contract or distinct pause-keeper address found in repo or docs. However, SEC-regulated context provides external accountability: fund manager, BNY Mellon custodian, E&Y financial auditor. Scored yellow rather than red because the RWA corporate structure provides out-of-band accountability that partially offsets the absence of an on-chain guardian role (PD-042 RWA regime).

Sources #

Methodology #

Determine whether a pauser/guardian role exists and is held by an address distinct from the upgrader address.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol superstate factor RD-F-034 score yellow collected_at 2026-05-16 00:06:37