Chainvara
Policy engine

Decide exactly what can move, and who signs off

Every transfer and operation is evaluated against your policy before anything is signed: hard limits, then ordered transaction rules by initiator, vault, network, asset, operation, destination and amount, then approval tiers. Policies are versioned and changes need a second admin.

USDC25,000 USDC · API
1Sanctioned destinationBlock
2USDC > $10,000 via API2 approvals · CFO, owner
3Payouts ≤ $500 to trustedAllow
4Everything else1 approval
Rule 2 matched · waiting for CFO and owner

Controls you can prove

Transaction rules

Ordered rules: the first match allows, blocks, or requires N approvals from named roles such as CFO, compliance or security.

Hard limits

Per-transfer caps, a separate API cap, a rolling 24-hour limit, blocklists and allowlist-only mode.

Address book with cooldown

New destinations wait out a cooldown before they become trusted; untrusted ones need an approval or are refused.

Versioned and governed

Every change is a new immutable version; with two admins, a second one must approve it.

Bound to the request

The policy version is part of each transfer's intent hash: a policy change invalidates pending approvals.

Explained

Every decision lists its reasons, from the matching rule to the address-book status.

How it works

  1. 1

    Set your limits

    Caps, 24-hour limit and approval tiers in Policies.

  2. 2

    Add rules

    For example: USDC above $10,000 from the API needs 2 approvals from CFO or owner.

  3. 3

    Preview

    Test any transfer with the preview endpoint to see the decision before asking for it.

Preview a decision

const preview = await fos.transfers.preview({
  wallet_id, asset: "USDC", amount: "25000",
  destination: "0x…",
});
// → { decision: { outcome: "require_approval",
//      reasons: ["Rule “Large USDC”: 2 approvals from cfo / owner required."] } }

Works best with

Ready to see Chainvara in action?

Start free on test networks. Move to production when your controls are in place.