CertiK’s latest Canton guide explains how a common token standard can make assets interoperable while effective security also brings together implementation, client software and operational permissions.
The firm’s August 11 article examines where the security of CIP-56-compatible assets actually resides. CIP-56 is Canton’s token standard. It gives wallets, applications and asset registries a common way to discover holdings and coordinate transfers.
Security beyond the interface
According to CertiK, the effective security of a particular asset brings together the standard, the concrete Daml implementation behind the asset, the way a client constructs and explains a transaction, and the operational permissions around the participant.
This is a practical point for institutions and application teams. Two assets can speak the same standard interface while using different rules for owners, administrators, providers and settlement executors. CertiK says those implementation-specific safeguards remain important when a generic wallet recognizes a CIP-56-compatible asset.
Why the distinction matters
For institutions assessing an implementation, the guide frames a standard as one part of the security model. CertiK argues that the code enforcing an asset’s rules, the software preparing a transaction and the access controls around the participant remain part of the effective security model.
CertiK outlines several kinds of authority: Daml choice authority, user preapprovals, operator delegation, Ledger API rights and topology permissions. These distinct mechanisms are enforced at different layers.
A guide for institutions and developers
The article is an educational analysis of the boundaries that institutions and developers can examine when they assess a CIP-56 implementation. CertiK says it has worked with teams targeting CIP-56 compatibility to review implementations against those boundaries.
CIP-56 specifies how systems can communicate with an asset. The guide highlights how an asset’s implementation and operational setup shape data protection, authorization and operational access.



