Skip to content
CAI
Software that uses CAICheck a score

psavelis/enterprise-blockchain

70.4

Strong · 21 September 2026

39.2k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a modular, hexagonally-architected platform for post-quantum secure settlement and traceability across multiple blockchain networks. It integrates a recursive STARK proof generation pipeline with smart contracts on EVM, Hyperledger Fabric, and Corda to handle aid settlement, supply chain traceability, and provider clearance. The architecture supports hardware security modules, multi-party computation, and quantum-resistant cryptography, all orchestrated through a unified infrastructure layer for local development and testing.

Features

Add HSM, MPC, and post-quantum examples

Added new example projects that demonstrate HSM envelope encryption, HSM key ceremonies, real PKCS\#11 hardware HSM support, HSM transaction signing, hybrid KEM settlement, ML-KEM key exchange, MPC joint risk analysis, MPC sealed-bid auctions, quantum-resistant key sharing, and quantum-safe Merkle root payments.

examples · high confidence

Add local development infrastructure for Besu, Corda, and Fabric testnets

New Terraform modules have been introduced to provision local development environments for three blockchain networks. The \besu-devnet\ module deploys multiple Besu validator nodes with RPC and health-check configurations. The \corda-nodes\ module provisions Corda nodes (notary and two parties) with persistence volumes. The \fabric-testnet\ module sets up a Hyperledger Fabric test network comprising an orderer and two peer nodes, each with specific environment variables and port mappings. These modules enable local testing and development by managing Docker containers for each network.

infra/modules/besu-devnet, infra/modules/corda-nodes, infra/modules/fabric-testnet · high confidence

Add post-quantum cryptography primitives and configurable field arithmetic for MPC

The MPC module now includes implementations of post-quantum algorithms ML-KEM, ML-DSA, and Hybrid KEM (X25519 + ML-KEM-768) via the @noble/post-quantum library, alongside a configurable 256-bit field arithmetic system that supports both a secure production mode (secp256k1/25519 primes) and a fast demo mode (31-bit Mersenne prime).

modules/mpc · high confidence

Adds shared infrastructure modules for logging, storage, and telemetry

The modules/shared area now provides a suite of shared utilities and abstractions. A structured logging interface (Logger, ConsoleLogger, noopLogger) is introduced to allow domain modules to accept optional logging ports. A generic in-memory key-value store (InMemoryStore) and a collection store (CollectionStore) are added to decouple domain logic from concrete storage implementations. Additionally, OpenTelemetry integration is added, including an SDK initializer that configures tracing and metrics exporters based on environment variables, along with helper functions (withSpan, withSpanSync) to manage distributed tracing spans.

modules/shared · high confidence

Interactive STARK Settlement Demo with Real Prover Integration

The demo application now supports an interactive STARK settlement workflow, allowing users to select from four enterprise scenarios (Food Recall, Aid Voucher, Cross-Border FX, and MPC Auction) and choose a settlement rail (Solana, Bitcoin, or Fiat). The demo includes a toggle between a fast mock prover and a real Stone prover for cryptographic proof generation. The UI features a dark, cyber-luxury theme with live progress tracking, log panels, and security status indicators for post-quantum signatures and MPC authorization. The demo is fully containerized via a multi-stage Dockerfile and includes comprehensive Vitest tests for the settlement context, UI components, and hooks.

demo · high confidence

Introduce @psavelis/enterprise-blockchain package with HSM, credentialing, and aid-settlement modules

The @psavelis/enterprise-blockchain npm package is now available, providing production-grade TypeScript modules for recursive STARK settlement, post-quantum cryptography (ML-KEM/ML-DSA), MPC, HSM, and multi-rail infrastructure. This release adds three new functional areas: an HSM module offering asymmetric key generation, signing, and envelope encryption; a credentialing module for evaluating provider clearance and staffing assignments; and an aid-settlement module for reconciling grant claims. Each area includes domain entities, application services, and infrastructure implementations (including in-memory stores and audit logs).

packages/enterprise-blockchain · high confidence

Introduce Cairo circuits and Stone prover infrastructure for STARK proof generation

Added a new Cairo build system (Makefile, Scarb.toml, and Cairo source files) that defines the state transition, Tier-1 aggregator, and Tier-2 block circuits for a 3-tier recursive STARK proof pipeline. The Cairo circuits verify single-transaction state transitions, aggregate 128 base proofs into a Tier-1 proof, and aggregate 64 Tier-1 proofs into a final block proof covering 8,192 transactions. Additionally, a new Terraform module provisions the Stone prover as a Docker container, exposing a gRPC API on port 10000 and Prometheus metrics on port 9100, with volume mounts for Cairo artifacts and proof outputs.

cairo, infra/modules/stone-prover · high confidence

Introduce HSM module with PKCS\#11-style key management and audit capabilities

Added the HSM module, providing a hexagonal architecture for key management and cryptographic operations. The module supports both a software simulator (using node:crypto) and real hardware HSMs via PKCS\#11 (using graphene-pk11). It introduces services for asymmetric key generation (EC, Ed25519, RSA), symmetric key management (AES-128/256), and envelope encryption. The implementation includes a flexible audit logging system that supports in-memory, file-based (with cryptographic chaining for integrity), and syslog adapters for compliance tracking.

modules/hsm · high confidence

Introduce P2MR (Pay-to-Merkle-Root) module for quantum-safe outputs

Adds a new \modules/p2mr\ module implementing BIP-360-inspired Pay-to-Merkle-Root (P2MR) outputs. This feature enables users to create outputs that store only a Merkle root on-chain, keeping public keys hidden until spend time to mitigate quantum 'harvest now, decrypt later' threats. The module provides factory functions to create single-signature, timelock, and multisig script leaves, along with a script interpreter to verify spending conditions using post-quantum ML-DSA-65 signatures. It also includes a spend proof builder and validator to ensure the revealed leaf matches the stored Merkle root.

modules/p2mr · high confidence

Introduce aggregated STARK settlement layer with recursive proof composition

The stark-settlement module now provides a complete settlement system that generates and aggregates zero-knowledge proofs across three tiers: base proofs for individual transactions, Tier-1 proofs aggregating 128 base proofs, and Tier-2 block proofs aggregating 64 Tier-1 proofs. The module introduces a LedgerService for managing mirror accounts and transactions with ML-DSA-65 post-quantum signatures, an AggregatorService for recursive proof composition, and a SettlementService that coordinates outbound settlement to Solana, Bitcoin, and fiat rails. Domain entities, value objects, and port interfaces are defined to support this architecture, with infrastructure adapters providing concrete implementations for proof generation, clock/time, audit logging, and external chain interactions.

modules/stark-settlement · high confidence

Introduce new Solidity contracts for aid settlement, order registry, quantum-safe outputs, and traceability anchoring

Added five new Solidity contracts in the \contracts/solidity/src\ directory: \AidSettlement\ and its upgradeable counterpart \AidSettlementUpgradeable\ for on-chain reconciliation of aid voucher redemptions; \ConsortiumOrderRegistry\ for anchoring canonical orders and publishing audience views; \P2MRRegistryV1\ implementing a BIP-360-inspired Pay-to-Merkle-Root registry for quantum-safe outputs; and \TraceabilityAnchor\ for anchoring product traceability state roots from Hyperledger Fabric to an EVM-compatible chain with ECDSA oracle attestation. All contracts integrate OpenZeppelin's AccessControl and Pausable mechanisms, with the upgradeable variant using UUPS proxy patterns.

contracts/solidity/src · high confidence

Introduce shared retry policy and circuit breaker for integration adapters

A new shared retry policy and circuit breaker implementation has been added to the integrations module. This provides platform-specific retry configurations for Fabric, Besu, and Corda adapters, each defining which error codes are retryable and which are not. The implementation includes exponential backoff with jitter, OpenTelemetry instrumentation for distributed tracing and metrics, and a circuit breaker state machine. Additionally, environment variable retrieval functions have been updated to use strict undefined checks, improving reliability when reading configuration.

modules/integrations/shared · high confidence

Local blockchain and prover infrastructure via Terraform and Docker

The \infra\ directory now provides a complete local development environment for enterprise blockchain nodes (Besu, Fabric, Corda) and a Stone STARK prover, all orchestrated via Terraform modules and Docker Compose. This includes a new Dockerfile and configuration for the Stone prover, a SoftHSM2 container for PKCS\#11 testing, and an OpenTelemetry collector configuration for observability. Users can now spin up these services locally to support STARK proof generation and blockchain node interactions.

infra · high confidence

Multi-chain smart contracts for aid settlement, traceability, and provider clearance

Adds a multi-chain contract suite spanning EVM (Besu), Hyperledger Fabric, and Corda. On EVM, it introduces the AidSettlement contract (with upgradeable and non-upgradeable variants), ConsortiumOrderRegistry, and TraceabilityAnchor, along with Foundry deployment scripts and ABI exports. On Fabric, it provides the FoodTraceContract chaincode for food supply-chain traceability. On Corda, it adds the ProviderClearanceContract and associated flows for managing provider clearance states. These contracts enable grant/claim settlement, lot anchoring, and provider clearance workflows across the respective platforms.

contracts · high confidence

Repository infrastructure and developer experience improvements

The repository now includes a comprehensive set of configuration and governance files to standardize development and release workflows. A Makefile provides unified commands for Docker Compose operations, smoke tests, and Terraform management. Release automation is configured via .releaserc.json for semantic versioning. Code quality is enforced through ESLint, Prettier, and commitlint configurations. Environment variables for telemetry, blockchain nodes, and the STARK prover are documented in .env.example. Security scanning is configured via .snyk, and a security policy is defined in SECURITY.md. Additionally, .gitignore and .gitmodules are updated to manage build artifacts and third-party libraries.

(repo-wide) · high confidence

Behavioural changes

Besu client refactored into modular, interface-driven components with improved error handling and observability

The Besu client module has been refactored to use a hexagonal architecture, introducing dedicated classes for profile management, provider/signer creation, gas estimation, and transaction building, each implementing specific interfaces defined in ports.ts. Error handling is now centralized in error-mapper.ts, which normalizes ethers.js error codes and messages, enabling better diagnostics for conditions like insufficient funds or nonce issues. Additionally, the gas estimator and transaction builder classes now integrate with the shared retry and telemetry systems, adding structured logging and span attributes for blockchain platform and chain ID, improving observability and resilience.

modules/integrations/besu-client · medium confidence

Enforce commit message and pre-commit linting via Husky

Husky hooks have been added to enforce professional technical standards. The commit-msg hook now runs commitlint to validate commit messages, and the pre-commit hook runs lint-staged to check staged files.

.husky · medium confidence

Expanded local smoke tests and example runner coverage

Added a new smoke-test-local.sh script that validates the health of the local multi-platform stack (Besu, Fabric, Corda) by checking Docker health status and TCP port connectivity. The script supports a 'besu-only' mode for faster testing. Additionally, the run-all-examples.ts script was updated to include new examples for MPC, HSM, quantum-resistant cryptography, and STARK settlement, ensuring these are executed during the full example run.

scripts · medium confidence

Hardened Corda gateway client with SSRF protection and resilience patterns

The Corda gateway integration has been refactored to improve security and reliability. A new \ports.ts\ module introduces ISP-compliant interfaces (\ICordaProfileFactory\, \ICordaRequestBuilder\, \ICordaFlowInvoker\) that decouple the implementation details. The \CordaGatewayClientSketch\ now incorporates a circuit breaker and retry policies for transient failures. Crucially, the \CordaFlowInvoker\ now validates outgoing URLs against private IP ranges and enforces HTTPS, mitigating Server-Side Request Forgery (SSRF) risks. Telemetry attributes are also added to track request metrics.

modules/integrations/corda-gateway · medium confidence

Refactor domain modules into hexagonal architecture with explicit ports and adapters

The privacy, credentialing, and traceability modules have been refactored to follow a hexagonal architecture. Domain entities and ports are now explicitly defined in separate files (e.g., \modules/privacy/src/domain/entities.ts\, \modules/protocols/src/privacy-port.ts\), and adapters (e.g., \modules/protocols/besu/src/index.ts\) implement these ports to translate domain operations into platform-specific invocations (such as Besu contract calls or Corda flows). This change separates core domain logic from infrastructure concerns, making it easier to swap or extend protocol implementations for different blockchain platforms.

modules/protocols · high confidence

Refactored Fabric Gateway client into modular, testable components with observability

The Fabric Gateway integration has been refactored to replace the monolithic \FabricGatewayClientSketch\ class with distinct, interface-driven components: \FabricProfileFactory\, \FabricConnectionFactory\, and \FabricGatewayFactory\. This change introduces explicit interfaces (\IFabricProfileFactory\, \IFabricConnectionFactory\, \IFabricGatewayFactory\) to separate concerns and improve testability. Additionally, all client operations (creating gRPC clients, identities, and gateways) are now wrapped in OpenTelemetry spans, providing built-in observability for blockchain interactions.

modules/integrations/fabric-gateway · high confidence

Refactored aid-settlement and credentialing modules into hexagonal architecture

The aid-settlement and credentialing modules have been restructured to follow a hexagonal (ports and adapters) architecture. Domain entities and ports are now separated from application logic and infrastructure implementations. The previous monolithic classes (AidSettlementLedger and CredentialRegistry) now delegate to dedicated application services (Reconciler and ClearanceEvaluator) and use repository ports, making the code more modular and testable while preserving the original public API.

modules/aid-settlement, modules/credentialing · high confidence

Refactors traceability module with hexagonal architecture

The traceability module has been refactored to follow a hexagonal architecture, separating domain logic from infrastructure concerns. The previous monolithic \TraceabilityLedger\ class has been replaced by a \RecallAssessor\ application service that operates on \TraceabilityRepository\ and \TraceabilityWriter\ ports. This change introduces a new \InMemoryTraceabilityStore\ for in-memory data management and extracts domain entities and ports into dedicated files, while maintaining backward compatibility through a facade in the main index.

modules/traceability · medium confidence

Test coverage

Expanded test coverage for crypto, MPC, and blockchain modules

Added comprehensive test suites for the HSM, MPC, and quantum cryptography modules, including property-based fuzz tests for envelope encryption, ECDSA signing, and ML-KEM (Kyber) encapsulation. New end-to-end tests validate the full consortium workflow (traceability, privacy anchoring, credentialing, and aid settlement) and verify protocol adapters for Fabric, Besu, and Corda. Additional tests cover the P2MR module's Merkle tree and script leaf validation, while integration tests confirm connectivity and block production on live Besu nodes.

tests · high confidence

Dependencies

Updated Solidity library dependencies

The project has updated its Solidity library dependencies, specifically adding or updating submodules for forge-std, OpenZeppelin contracts, and OpenZeppelin upgradeable contracts. This ensures the codebase uses specific, stable versions of these essential libraries for smart contract development and security best practices.

contracts/solidity/lib · high confidence

Updated project dependencies and tooling

The project updated several dependencies and dev dependencies, including bumping TypeScript to 6.0.2, @types/node to 25.6.0, and c8 to 11.0.0. Additionally, new dev dependencies were added for commit linting (@commitlint), semantic release tooling, ESLint 10, Prettier, and Husky, while the root package.json was configured with workspaces and lint-staged hooks.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 67 → 70 (+3.6)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 78 → 79 (+0.5)
  • Architecture 82 → 79 (-2.8)
  • Maturity 88 → 88 (+0.3)
  • Readiness 68 → 72 (+4.6)
  • Security 57 → 64 (+7.0)

Resolved (52)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (contracts/fabric/package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Further sole-owners (lower concentration)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (contracts/fabric/package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 32 more

New (153)

  • AsymmetricKeyService.generateKeyPairAsync (cognitive 18) (modules/hsm/src/application/asymmetric-key-service.ts)
  • AsymmetricKeyService.generateKeyPairAsync (cyclomatic 17) (modules/hsm/src/application/asymmetric-key-service.ts)
  • AuditLogFactory.createFromEnv (cognitive 17) (packages/enterprise-blockchain/src/hsm/infrastructure/audit-log-factory.ts)
  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (contracts/fabric/package-lock.json)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (contracts/fabric/package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 133 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

psavelis/enterprise-blockchain was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 50c683a791c327ef6f2bb6e6318dbb1db714680a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.