> For the complete documentation index, see [llms.txt](https://city-protocol.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://city-protocol.gitbook.io/docs/issuance-and-operation-layer/structured-product-architecture/security-and-risk-controls.md).

# Security and Risk Controls

The Issuance & Operation Layer inherits City Protocol's security operating model and extends it to product-level issuance and operations.

<table><thead><tr><th width="281.2734375">Control</th><th>Purpose</th></tr></thead><tbody><tr><td>Component Whitelisting</td><td>Restricts products to approved TaaS products, verified VaaS vaults, and whitelisted external components.</td></tr><tr><td>Product Mandate Enforcement</td><td>Prevents managers from changing assets, weights, venues, leverage, liquidity terms, or fees outside the approved rule set.</td></tr><tr><td>Issuance Controls</td><td>Links product tokens, receipts, shares, or position records to approved registry entries, eligibility logic, NAV source, and redemption terms.</td></tr><tr><td>NAV Signer Quorum</td><td>Requires authorized valuation signers before product-level NAV becomes authoritative.</td></tr><tr><td>Deviation and Freshness Checks</td><td>Flags abnormal NAV moves, stale component data, missing reports, or inconsistent component pricing.</td></tr><tr><td>Status Propagation</td><td>If a component is paused, impaired, expired, or ineligible, the product status can update automatically.</td></tr><tr><td>Role Separation</td><td>Separates issuer, manager, NAV signer, whitelist manager, verifier, guardian, and governance roles.</td></tr><tr><td>Fee Visibility</td><td>Shows management fees, performance fees, entry/exit fees, and fee layering before subscription.</td></tr><tr><td>Emergency Pause</td><td>Allows deposits, redemptions, rebalancing, issuance, or transfers to pause during abnormal market, oracle, strategy, or security events.</td></tr><tr><td>Disclosure Versioning</td><td>Links each product to its current methodology, risk disclosure, component list, fee schedule, and material updates.</td></tr><tr><td>Look-Through Reporting</td><td>Lets integrators and participants inspect product-level exposure and underlying component status.</td></tr></tbody></table>

This layer provides infrastructure. It does not make the underlying assets risk-free. Products can carry market risk, liquidity risk, strategy risk, oracle risk, smart contract risk, counterparty risk, legal risk, and operational risk. Product pages should explain what the product represents, how NAV is calculated, who manages the strategy, who verifies the inputs, when redemptions can occur, and what can cause a pause.
