Repository layout
Trust boundaries
- The model returns a proposal; it cannot directly call contracts or exchanges.
- Policy code constrains actions and target notional.
- Vault writes require the authorized onchain keeper.
- Exchange writes require explicit trading enablement and venue checks.
- Operator endpoints require
X-Molq-Operator-Key. - Decision evidence is committed to the logger and indexed independently.