Receipts.Everything you can read, run, or verify.
Every promise on this site is backed by something concrete: an audit, a formal proof, a contract you can inspect, code you can build. Here it all is.
What you can verify, today, with a block explorer.
Public addresses, open-source contracts, formal proofs. Every number on this site that matters can be re-derived from the chain — and these are the headline ones.
Figure 5Headline metrics, last 12 months. Trend lines derived from indexer snapshots; the underlying transactions are public.
The whole portfolio.In one vault.
We are not the cheapest. We are not the loudest. We are the only one that covers all nine chains and every safety mechanism in a single on-chain plan.
| Feature | HeirVault | Casa | Sarcophagus | Vault12 | Inheriti |
|---|---|---|---|---|---|
Bitcoin vaults Native Taproot, no wrapping | — | — | — | ||
EVM vaults · 7 chains Ethereum, Base, Arbitrum, Polygon, BSC, Avalanche, Hyperliquid | — | — | |||
Solana vaults Native Anchor program | — | — | — | — | |
Tron / TRC20 vaults | — | — | — | — | |
M-of-N heir multisig Quorum enforced by contract, not human policy | — | ||||
20-min commit–reveal Front-running protection on every claim | — | — | — | — | |
Guardians · extension only Trusted contacts can delay claim, never withdraw | — | — | — | — | |
Aave yield while waiting | — | — | — | — | |
Open-source · MIT | — | — | — | ||
Public recovery URL If we disappear, your family still claims | — | — | — | ||
Standing orders Recurring transfers, not just inheritance | — | — | — | — |
- 01External audit
OpenZeppelin
Full-scope audit covering InheritanceVault, Factory, PremiumManager, MultiSig, and the CCIP cross-chain relay. Public report.
Read the report → - 02Formal verification
Halmos · 51 symbolic proofs
Properties proved across four test files: invariants on shares, claim flow correctness, recovery safety, and pause behavior. Proofs ship with the open-source repo at v1.
- 03Static analysis
Slither · Aderyn · Mythril
Three independent static analyzers run on every contract change. CI fails the build on any medium-or-higher finding. The CI policy is published with the repo at v1.
- 04Open-source
MIT-licensed, every line
Smart contracts, backend, frontend, indexers — one repo, MIT, opens publicly at v1 mainnet. Until then the audit report is the authoritative reference.
Contract addresses, every chain
The factory contract is the entry point on each chain. Vaults are deployed as clones from these addresses.
Mainnet deploys ship with v1.
Factory addresses for the seven EVM chains — Ethereum, Base, Arbitrum, Polygon, BSC, Avalanche, Hyperliquid — go live when the OpenZeppelin audit closes. Bitcoin uses a Taproot multisig (P2TR), Tron uses TRC20-compatible contracts, Solana an Anchor program. All addresses, bytecode, and the source repo become public at the same moment, so every claim on this page can be verified against a block explorer.
Want early access to a testnet deploy, or to review the audit draft? Write us at hello@heirvault.xyz.
Bug bounty
Up to $250,000 for critical findings on production contracts. Scoped, fair, and public. Disclosure timeline is 90 days from confirmed report.
security@heirvault.xyz →