psavelis/enterprise-blockchain
70.4
Strong · 21 September 2026
39.2k
lines of production code
TypeScript
primary language
4
measurements over time
What this system is
This system is a modular, hexagonally-architected platform for post-quantum secure settlement and traceability across multiple blockchain networks. It integrates a recursive STARK proof generation pipeline with smart contracts on EVM, Hyperledger Fabric, and Corda to handle aid settlement, supply chain traceability, and provider clearance. The architecture supports hardware security modules, multi-party computation, and quantum-resistant cryptography, all orchestrated through a unified infrastructure layer for local development and testing.
Features
Add HSM, MPC, and post-quantum examples
Added new example projects that demonstrate HSM envelope encryption, HSM key ceremonies, real PKCS\#11 hardware HSM support, HSM transaction signing, hybrid KEM settlement, ML-KEM key exchange, MPC joint risk analysis, MPC sealed-bid auctions, quantum-resistant key sharing, and quantum-safe Merkle root payments.
examples · high confidence
Add local development infrastructure for Besu, Corda, and Fabric testnets
New Terraform modules have been introduced to provision local development environments for three blockchain networks. The \besu-devnet\ module deploys multiple Besu validator nodes with RPC and health-check configurations. The \corda-nodes\ module provisions Corda nodes (notary and two parties) with persistence volumes. The \fabric-testnet\ module sets up a Hyperledger Fabric test network comprising an orderer and two peer nodes, each with specific environment variables and port mappings. These modules enable local testing and development by managing Docker containers for each network.
infra/modules/besu-devnet, infra/modules/corda-nodes, infra/modules/fabric-testnet · high confidence
Add post-quantum cryptography primitives and configurable field arithmetic for MPC
The MPC module now includes implementations of post-quantum algorithms ML-KEM, ML-DSA, and Hybrid KEM (X25519 + ML-KEM-768) via the @noble/post-quantum library, alongside a configurable 256-bit field arithmetic system that supports both a secure production mode (secp256k1/25519 primes) and a fast demo mode (31-bit Mersenne prime).
modules/mpc · high confidence
Adds shared infrastructure modules for logging, storage, and telemetry
The modules/shared area now provides a suite of shared utilities and abstractions. A structured logging interface (Logger, ConsoleLogger, noopLogger) is introduced to allow domain modules to accept optional logging ports. A generic in-memory key-value store (InMemoryStore) and a collection store (CollectionStore) are added to decouple domain logic from concrete storage implementations. Additionally, OpenTelemetry integration is added, including an SDK initializer that configures tracing and metrics exporters based on environment variables, along with helper functions (withSpan, withSpanSync) to manage distributed tracing spans.
modules/shared · high confidence
Interactive STARK Settlement Demo with Real Prover Integration
The demo application now supports an interactive STARK settlement workflow, allowing users to select from four enterprise scenarios (Food Recall, Aid Voucher, Cross-Border FX, and MPC Auction) and choose a settlement rail (Solana, Bitcoin, or Fiat). The demo includes a toggle between a fast mock prover and a real Stone prover for cryptographic proof generation. The UI features a dark, cyber-luxury theme with live progress tracking, log panels, and security status indicators for post-quantum signatures and MPC authorization. The demo is fully containerized via a multi-stage Dockerfile and includes comprehensive Vitest tests for the settlement context, UI components, and hooks.
demo · high confidence
Introduce @psavelis/enterprise-blockchain package with HSM, credentialing, and aid-settlement modules
The @psavelis/enterprise-blockchain npm package is now available, providing production-grade TypeScript modules for recursive STARK settlement, post-quantum cryptography (ML-KEM/ML-DSA), MPC, HSM, and multi-rail infrastructure. This release adds three new functional areas: an HSM module offering asymmetric key generation, signing, and envelope encryption; a credentialing module for evaluating provider clearance and staffing assignments; and an aid-settlement module for reconciling grant claims. Each area includes domain entities, application services, and infrastructure implementations (including in-memory stores and audit logs).
packages/enterprise-blockchain · high confidence
Introduce Cairo circuits and Stone prover infrastructure for STARK proof generation
Added a new Cairo build system (Makefile, Scarb.toml, and Cairo source files) that defines the state transition, Tier-1 aggregator, and Tier-2 block circuits for a 3-tier recursive STARK proof pipeline. The Cairo circuits verify single-transaction state transitions, aggregate 128 base proofs into a Tier-1 proof, and aggregate 64 Tier-1 proofs into a final block proof covering 8,192 transactions. Additionally, a new Terraform module provisions the Stone prover as a Docker container, exposing a gRPC API on port 10000 and Prometheus metrics on port 9100, with volume mounts for Cairo artifacts and proof outputs.
cairo, infra/modules/stone-prover · high confidence
Introduce HSM module with PKCS\#11-style key management and audit capabilities
Added the HSM module, providing a hexagonal architecture for key management and cryptographic operations. The module supports both a software simulator (using node:crypto) and real hardware HSMs via PKCS\#11 (using graphene-pk11). It introduces services for asymmetric key generation (EC, Ed25519, RSA), symmetric key management (AES-128/256), and envelope encryption. The implementation includes a flexible audit logging system that supports in-memory, file-based (with cryptographic chaining for integrity), and syslog adapters for compliance tracking.
modules/hsm · high confidence
Introduce P2MR (Pay-to-Merkle-Root) module for quantum-safe outputs
Adds a new \modules/p2mr\ module implementing BIP-360-inspired Pay-to-Merkle-Root (P2MR) outputs. This feature enables users to create outputs that store only a Merkle root on-chain, keeping public keys hidden until spend time to mitigate quantum 'harvest now, decrypt later' threats. The module provides factory functions to create single-signature, timelock, and multisig script leaves, along with a script interpreter to verify spending conditions using post-quantum ML-DSA-65 signatures. It also includes a spend proof builder and validator to ensure the revealed leaf matches the stored Merkle root.
modules/p2mr · high confidence
Introduce aggregated STARK settlement layer with recursive proof composition
The stark-settlement module now provides a complete settlement system that generates and aggregates zero-knowledge proofs across three tiers: base proofs for individual transactions, Tier-1 proofs aggregating 128 base proofs, and Tier-2 block proofs aggregating 64 Tier-1 proofs. The module introduces a LedgerService for managing mirror accounts and transactions with ML-DSA-65 post-quantum signatures, an AggregatorService for recursive proof composition, and a SettlementService that coordinates outbound settlement to Solana, Bitcoin, and fiat rails. Domain entities, value objects, and port interfaces are defined to support this architecture, with infrastructure adapters providing concrete implementations for proof generation, clock/time, audit logging, and external chain interactions.
modules/stark-settlement · high confidence
Introduce new Solidity contracts for aid settlement, order registry, quantum-safe outputs, and traceability anchoring
Added five new Solidity contracts in the \contracts/solidity/src\ directory: \AidSettlement\ and its upgradeable counterpart \AidSettlementUpgradeable\ for on-chain reconciliation of aid voucher redemptions; \ConsortiumOrderRegistry\ for anchoring canonical orders and publishing audience views; \P2MRRegistryV1\ implementing a BIP-360-inspired Pay-to-Merkle-Root registry for quantum-safe outputs; and \TraceabilityAnchor\ for anchoring product traceability state roots from Hyperledger Fabric to an EVM-compatible chain with ECDSA oracle attestation. All contracts integrate OpenZeppelin's AccessControl and Pausable mechanisms, with the upgradeable variant using UUPS proxy patterns.
contracts/solidity/src · high confidence
Introduce shared retry policy and circuit breaker for integration adapters
A new shared retry policy and circuit breaker implementation has been added to the integrations module. This provides platform-specific retry configurations for Fabric, Besu, and Corda adapters, each defining which error codes are retryable and which are not. The implementation includes exponential backoff with jitter, OpenTelemetry instrumentation for distributed tracing and metrics, and a circuit breaker state machine. Additionally, environment variable retrieval functions have been updated to use strict undefined checks, improving reliability when reading configuration.
modules/integrations/shared · high confidence
Local blockchain and prover infrastructure via Terraform and Docker
The \infra\ directory now provides a complete local development environment for enterprise blockchain nodes (Besu, Fabric, Corda) and a Stone STARK prover, all orchestrated via Terraform modules and Docker Compose. This includes a new Dockerfile and configuration for the Stone prover, a SoftHSM2 container for PKCS\#11 testing, and an OpenTelemetry collector configuration for observability. Users can now spin up these services locally to support STARK proof generation and blockchain node interactions.
infra · high confidence
Multi-chain smart contracts for aid settlement, traceability, and provider clearance
Adds a multi-chain contract suite spanning EVM (Besu), Hyperledger Fabric, and Corda. On EVM, it introduces the AidSettlement contract (with upgradeable and non-upgradeable variants), ConsortiumOrderRegistry, and TraceabilityAnchor, along with Foundry deployment scripts and ABI exports. On Fabric, it provides the FoodTraceContract chaincode for food supply-chain traceability. On Corda, it adds the ProviderClearanceContract and associated flows for managing provider clearance states. These contracts enable grant/claim settlement, lot anchoring, and provider clearance workflows across the respective platforms.
contracts · high confidence
Repository infrastructure and developer experience improvements
The repository now includes a comprehensive set of configuration and governance files to standardize development and release workflows. A Makefile provides unified commands for Docker Compose operations, smoke tests, and Terraform management. Release automation is configured via .releaserc.json for semantic versioning. Code quality is enforced through ESLint, Prettier, and commitlint configurations. Environment variables for telemetry, blockchain nodes, and the STARK prover are documented in .env.example. Security scanning is configured via .snyk, and a security policy is defined in SECURITY.md. Additionally, .gitignore and .gitmodules are updated to manage build artifacts and third-party libraries.
(repo-wide) · high confidence
Behavioural changes
Besu client refactored into modular, interface-driven components with improved error handling and observability
The Besu client module has been refactored to use a hexagonal architecture, introducing dedicated classes for profile management, provider/signer creation, gas estimation, and transaction building, each implementing specific interfaces defined in ports.ts. Error handling is now centralized in error-mapper.ts, which normalizes ethers.js error codes and messages, enabling better diagnostics for conditions like insufficient funds or nonce issues. Additionally, the gas estimator and transaction builder classes now integrate with the shared retry and telemetry systems, adding structured logging and span attributes for blockchain platform and chain ID, improving observability and resilience.
modules/integrations/besu-client · medium confidence
Enforce commit message and pre-commit linting via Husky
Husky hooks have been added to enforce professional technical standards. The commit-msg hook now runs commitlint to validate commit messages, and the pre-commit hook runs lint-staged to check staged files.
.husky · medium confidence
Expanded local smoke tests and example runner coverage
Added a new smoke-test-local.sh script that validates the health of the local multi-platform stack (Besu, Fabric, Corda) by checking Docker health status and TCP port connectivity. The script supports a 'besu-only' mode for faster testing. Additionally, the run-all-examples.ts script was updated to include new examples for MPC, HSM, quantum-resistant cryptography, and STARK settlement, ensuring these are executed during the full example run.
scripts · medium confidence
Hardened Corda gateway client with SSRF protection and resilience patterns
The Corda gateway integration has been refactored to improve security and reliability. A new \ports.ts\ module introduces ISP-compliant interfaces (\ICordaProfileFactory\, \ICordaRequestBuilder\, \ICordaFlowInvoker\) that decouple the implementation details. The \CordaGatewayClientSketch\ now incorporates a circuit breaker and retry policies for transient failures. Crucially, the \CordaFlowInvoker\ now validates outgoing URLs against private IP ranges and enforces HTTPS, mitigating Server-Side Request Forgery (SSRF) risks. Telemetry attributes are also added to track request metrics.
modules/integrations/corda-gateway · medium confidence
Refactor domain modules into hexagonal architecture with explicit ports and adapters
The privacy, credentialing, and traceability modules have been refactored to follow a hexagonal architecture. Domain entities and ports are now explicitly defined in separate files (e.g., \modules/privacy/src/domain/entities.ts\, \modules/protocols/src/privacy-port.ts\), and adapters (e.g., \modules/protocols/besu/src/index.ts\) implement these ports to translate domain operations into platform-specific invocations (such as Besu contract calls or Corda flows). This change separates core domain logic from infrastructure concerns, making it easier to swap or extend protocol implementations for different blockchain platforms.
modules/protocols · high confidence
Refactored Fabric Gateway client into modular, testable components with observability
The Fabric Gateway integration has been refactored to replace the monolithic \FabricGatewayClientSketch\ class with distinct, interface-driven components: \FabricProfileFactory\, \FabricConnectionFactory\, and \FabricGatewayFactory\. This change introduces explicit interfaces (\IFabricProfileFactory\, \IFabricConnectionFactory\, \IFabricGatewayFactory\) to separate concerns and improve testability. Additionally, all client operations (creating gRPC clients, identities, and gateways) are now wrapped in OpenTelemetry spans, providing built-in observability for blockchain interactions.
modules/integrations/fabric-gateway · high confidence
Refactored aid-settlement and credentialing modules into hexagonal architecture
The aid-settlement and credentialing modules have been restructured to follow a hexagonal (ports and adapters) architecture. Domain entities and ports are now separated from application logic and infrastructure implementations. The previous monolithic classes (AidSettlementLedger and CredentialRegistry) now delegate to dedicated application services (Reconciler and ClearanceEvaluator) and use repository ports, making the code more modular and testable while preserving the original public API.
modules/aid-settlement, modules/credentialing · high confidence
Refactors traceability module with hexagonal architecture
The traceability module has been refactored to follow a hexagonal architecture, separating domain logic from infrastructure concerns. The previous monolithic \TraceabilityLedger\ class has been replaced by a \RecallAssessor\ application service that operates on \TraceabilityRepository\ and \TraceabilityWriter\ ports. This change introduces a new \InMemoryTraceabilityStore\ for in-memory data management and extracts domain entities and ports into dedicated files, while maintaining backward compatibility through a facade in the main index.
modules/traceability · medium confidence
Test coverage
Expanded test coverage for crypto, MPC, and blockchain modules
Added comprehensive test suites for the HSM, MPC, and quantum cryptography modules, including property-based fuzz tests for envelope encryption, ECDSA signing, and ML-KEM (Kyber) encapsulation. New end-to-end tests validate the full consortium workflow (traceability, privacy anchoring, credentialing, and aid settlement) and verify protocol adapters for Fabric, Besu, and Corda. Additional tests cover the P2MR module's Merkle tree and script leaf validation, while integration tests confirm connectivity and block production on live Besu nodes.
tests · high confidence
Dependencies
Updated Solidity library dependencies
The project has updated its Solidity library dependencies, specifically adding or updating submodules for forge-std, OpenZeppelin contracts, and OpenZeppelin upgradeable contracts. This ensures the codebase uses specific, stable versions of these essential libraries for smart contract development and security best practices.
contracts/solidity/lib · high confidence
Updated project dependencies and tooling
The project updated several dependencies and dev dependencies, including bumping TypeScript to 6.0.2, @types/node to 25.6.0, and c8 to 11.0.0. Additionally, new dev dependencies were added for commit linting (@commitlint), semantic release tooling, ESLint 10, Prettier, and Husky, while the root package.json was configured with workspaces and lint-staged hooks.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 67 → 70 (+3.6)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 78 → 79 (+0.5)
- Architecture 82 → 79 (-2.8)
- Maturity 88 → 88 (+0.3)
- Readiness 68 → 72 (+4.6)
- Security 57 → 64 (+7.0)
Resolved (52)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (contracts/fabric/package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Further sole-owners (lower concentration)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (contracts/fabric/package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 32 more
New (153)
- AsymmetricKeyService.generateKeyPairAsync (cognitive 18) (modules/hsm/src/application/asymmetric-key-service.ts)
- AsymmetricKeyService.generateKeyPairAsync (cyclomatic 17) (modules/hsm/src/application/asymmetric-key-service.ts)
- AuditLogFactory.createFromEnv (cognitive 17) (packages/enterprise-blockchain/src/hsm/infrastructure/audit-log-factory.ts)
- Coverage not measured — JavaScript/TypeScript suite
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (contracts/fabric/package-lock.json)
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (contracts/fabric/package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 133 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
psavelis/enterprise-blockchain was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 50c683a791c327ef6f2bb6e6318dbb1db714680a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.