Security & Transparency
Version 1.1 - Current live-production public review
Taryven treats security as an ongoing engineering and operational process. This review explains what has been tested internally, what has reached production readiness, what remains intentionally inactive, and what independent security work remains pending.
Clear status. No audit overstatement.
Internal functional, adversarial, boundary, accounting, fuzz, invariant, static-analysis, snapshot, corruption, integration, and production-state review has been performed across the currently reviewed production surface. Future lifecycle gates remain open.
Production Presale transaction construction, pricing economics, paused-state rejection, reconciliation, Safe-controlled activation, and pre-launch state were verified during the current production-readiness review.
The production Ethereum Presale is deployed on Ethereum Mainnet and purchasing is currently enabled. Production verification confirmed the approved Safe ownership and payment-token configuration.
The production Presale owner and Treasury authority are controlled through the Taryven Primary Safe with a two-of-three signing threshold.
Production PresaleDistribution and ReferralDistribution are not yet deployed to Base Mainnet. TGE has not been configured. Those steps remain future lifecycle gates.
Production ParticipantVesting is deployed on Base Mainnet. Its reviewed source matches production deployment provenance. The contract remains intentionally paused with TGE unset pending its controlled activation ceremony.
Taryven intends to engage a qualified independent third-party security firm after sufficient Presale funding is available. Independent review remains separate from the internal engineering review.
Future Merchant Registry, Payment Router, Rewards Vault, settlement, and related merchant/payment components are not represented as active production contracts until their applicable deployment and verification milestones are completed.
279 passing. 0 failing.
The current complete blockchain regression checkpoint reports 279 passing tests and zero failing tests.
The dedicated ParticipantVesting security suite reports 87 passing tests and zero failing tests. Reviewed ParticipantVesting controls include participant-pool limits, seat and beneficiary uniqueness, backing, vesting boundaries, termination accounting, pause controls, reentrancy protection, ownership protections, and TRYV rescue prohibition.
112 passing. 0 failing.
At the documented Phase 1 internal security checkpoint, Taryven's complete blockchain test suite reported 112 passing tests and zero failing tests for that reviewed development scope.
That historical result covered Presale, distribution, vesting, claims, Treasury protections, snapshot integrity, and related Presale-critical functionality.
Contract-enforced limits and protected administration.
Production purchasing cannot begin until authorized Presale control explicitly enables it.
The production Presale accepts only the specifically configured USDC and USDT payment-token contracts.
Contract logic prevents qualifying Presale contributions from exceeding the configured hard cap.
Pricing and contributions crossing stage boundaries are calculated through Presale contract logic.
Successful purchases create purchaser and global accounting records used for reconciliation and later distribution.
Once finalized, the Presale cannot be reopened through the normal administrative interface.
Treasury changes cannot happen instantly.
The production Presale owner and Treasury are controlled by the Taryven Primary Safe rather than a personal Founder wallet.
A proposed Treasury replacement does not immediately redirect purchaser payments. The delay creates an additional control period before the replacement can become effective.
Ownership renunciation is disabled in the reviewed Presale contract, reducing the risk of accidentally abandoning required administrative authority.
Allocation and release are separate from purchase.
Presale purchasing records allocation. It does not make the entire purchaser allocation immediately transferable.
The reviewed purchaser-distribution architecture uses an authoritative allocation snapshot, a Merkle allocation root, wallet-bound proofs, beneficiary claim accounting, global claim accounting, TGE configuration, staged vesting, and pause controls.
Historical Phase 1 testing verified that another wallet cannot simply reuse a beneficiary's proof, modifying an allocation invalidates the corresponding proof, duplicate immediate claims fail, and later claims are limited to newly vested TRYV.
The purchaser release schedule tested during the reviewed scope is 25% at TGE followed by 12 releases of 6.25% of the original allocation every 30 days.
Distribution data is independently reconstructed.
Taryven's reviewed snapshot process reconstructs Presale allocations from on-chain purchase records rather than relying solely on a manually maintained allocation list.
A separate verification process checks beneficiary addresses, unique wallets, positive allocations, exact allocation totals, independently regenerated Merkle roots, and independently regenerated beneficiary proofs.
The historical Phase 1 verifier reported SNAPSHOT INTEGRITY VALID for the reviewed test snapshot.
Invalid snapshot data was deliberately tested.
Taryven intentionally created corrupted test snapshots to verify that the independent snapshot-verification tooling rejects altered distribution information.
Tested corruption included incorrect total allocation, modified beneficiary allocation, incorrect Merkle root, incorrect Merkle proof, zero beneficiary allocation, and duplicate beneficiary wallets.
Testing goes beyond expected happy paths.
The documented internal security program includes deterministic randomized testing of purchasers, USDC and USDT purchases, contribution amounts, pricing around stage boundaries, hard-cap calculations, ledger reconstruction, per-wallet accounting, finalization behavior, and TRYV allocation-cap enforcement.
The historical Phase 1 tokenomics invariant suite also sampled valid pricing combinations to verify that the approved Presale pricing structure remained within the configured Presale & Market Launch allocation ceiling.
Slither was used as part of the documented Phase 1 Solidity review. The recorded checkpoint used Slither 0.11.6 across 22 contracts and 102 detectors.
The reviewed Slither output did not identify a Critical or High vulnerability in the documented Presale-critical scope. This statement describes that internal analysis only and is not an independent security certification.
Deployment was followed by production-state verification.
Taryven's production-readiness review continued after the historical Phase 1 development checkpoint.
Reviewed production gates included production network and environment configuration, Primary Safe authority, Presale owner and Treasury identity, paused-state verification, production application deployment, public-page verification, fail-closed future features, transaction construction, paused-Presale rejection simulation, pricing and stage-boundary economics, UI and contract economics parity, Safe-controlled activation, production Presale indexing initialization, and reconciliation readiness.
At the preserved historical pre-activation readiness checkpoint, the production Presale remained paused and not finalized with zero qualifying contributions, zero TRYV purchaser allocation, and zero purchases.
The activation path was verified at that historical checkpoint without executing the activation transaction. The Presale has since been authorized for live purchasing and is currently open.
Reviewed contract source is preserved by hash.
Taryven's internal review process records cryptographic hashes for reviewed contract source so later verification can identify whether security-sensitive source files have changed from a preserved checkpoint.
The current preserved review set includes the TRYV token, Presale, purchaser distribution, referral distribution, and participant vesting contracts.
A matching source hash is evidence that the compared source file is unchanged from the preserved reviewed version. It is not, by itself, proof that the contract is free from vulnerabilities.
Important project state should be observable.
Taryven intends to publish appropriate information including verified production smart-contract addresses, Treasury addresses, TRYV maximum supply and allocations, Founder and Advisor lock and vesting information, Presale status, Tokenomics, White Paper materials, internal security-review information, and independent audit materials when available.
Relevant Taryven-controlled liquidity pool and position information is also intended to be publicly identifiable on-chain where technically applicable.
Transparency does not eliminate risk, but it can make material project activity easier to evaluate independently.
Security work continues after a checkpoint.
Taryven does not treat a passing test suite, internal review, production deployment, or future independent audit as proof that software can never contain a vulnerability.
Internal testing, code review, static analysis, multisignature controls, and independent security audits can reduce risk, but they cannot guarantee that software is free from every vulnerability or that digital assets cannot be lost.
Security review continues as new contracts, application features, administrative functions, Treasury processes, integrations, and infrastructure reach production readiness.
READ DIGITAL-ASSET RISK DISCLOSURE