Skip to content

Architecture

Stormbit is organized as vaults with an epoch lifecycle. Capital sits in a vault, and each transaction drawn against it is a defined structure recorded on chain. The software is non custodial: Stormbit Labs does not custody assets and holds no withdrawal key over user collateral.

A transaction follows an order-ticket lifecycle: the holder states an intent, a counterparty prices it, the holder or an approved delegate authorizes it from their own wallet, and the contract settles the outcome on chain. Stormbit Labs does not select, approve, or initiate a holder’s transaction.

Each vault operates in epochs. A manager opens an epoch and proposes terms, which the contracts validate on chain against configured bands. Epochs finalize and close as open cranks, and holders claim their positions.

The contracts use AccessControl roles. An administrative role sets protocol parameters and credit limits, assigns roles, and operates defined settlement fallback functions. A security role can pause and unpause. An upgrade role can modify contract logic only while the system is paused; a live, unpaused system cannot have its logic changed. A price-reporting role posts settlement prices. Roles cannot be renounced; role membership changes only by explicit administrative action.

The manager is not an AccessControl role: it is a per-vault address assignment set by the administrative role. It is the only privileged actor in epoch operations. It cannot withdraw funds, redirect payouts, or choose recipients.

A holder may approve a delegate for their own positions. This is self service and involves no protocol role. One property to note: approval is per delegate, not per action. A delegate approved on a contract may exercise every delegation-gated function on that contract for the approving holder.

Collateral moves only along the coded settlement paths. Routine settlement prices are posted by the price-reporting role and must sit within a narrow band of an on-chain reference. If a settlement post is missed or the reference is unavailable, an administrative backstop can settle, and its price input is constrained only by a wide sanity check that does not apply if the reference feed is unavailable. Because the settlement price determines the allocation of escrowed value between the parties at expiry, the backstop is a material administrative power over settlement outcomes. Settlement prices are not independently validated.

A deliberately large surface has no caller gating. Deposits are open to any address. Epoch finalization, epoch close, and share claims are open cranks. Repayment is open, so any address may repay another’s debt, with the collateral still returning to the borrower. These properties describe who can call the contracts, not an invitation to transact.


See Contract addresses for deployments per network, published as they are verified.