[ARFC] Aave Risk Framework

Changelog

v1.1 — 2026-06-12

Edits resolving bridge-stack role definitions with LayerZero. The
common thread: requirements that assumed a single “vendor” are
reallocated across the messaging vendor, the verification operators,
and the issuer/application, to match which party actually holds each
control.

Normative:

  • §2.6 Pause pathways: vendor-side pause requirement broadened to a
    “vendor or verification-operator-enforced” ability to halt
    verification, exercisable by the vendor or operator’s incident team.
    Dropped the “(typically the vendor)” framing.
  • §2.10 Incident response: monitoring-responsibility requirement
    reworded — security/integrity monitoring of the verification-and-
    messaging layer sits with the entity operating that layer, alongside
    the issuer’s application-level monitoring of cross-chain correctness.
  • §2.11 Monitoring teams: rescoped so verification-layer integrity sits
    with the operating entity and application-level monitoring/response
    sits with the issuer; bullet 1 reworded accordingly. Removed the
    requirement that both vendor and issuer teams hold pause/rate-limit
    authority (this authority remains required at the on-call level under
    §2.10). Final bullet reworded to a mutual non-offloading obligation.

Editorial:

  • §2.6 Moved the single-pause-path line from the requirements list into
    the closing paragraph (no change in meaning).
  • §2.12 “Per-lane initial limits” → “Per-route initial limits” for
    consistency with the rest of Layer 2.

v1.0 — 2026-06-09

Initial ARFC.