Institutional standards
The controls, standards, and operational practices that underpin a securities-grade tokenized asset platform.
Compliance-first architecture
Eligibility is never UI-only. Every subscription, allocation, and transfer passes through server-enforced gates — KYC tier, jurisdiction, accreditation status, and sanctions screening — before on-chain settlement. Transfer restrictions are encoded in permissioned token contracts and reconciled with off-chain records.
Identity & AML
- Tiered KYC via regulated identity providers (e.g. Sumsub).
- Ongoing sanctions, PEP, and watchlist screening — not one-time at signup.
- KYC data handled as highest-sensitivity PII: encrypted at rest, role-based access, full audit trail on every access.
- We store verification results and provider references — not raw identity documents — unless counsel requires otherwise.
Smart-contract & security standards
- Independent third-party audits required before any offering goes live.
- Battle-tested libraries; reentrancy protection on all fund-moving functions; caps and limits enforced on-chain.
- Permissioned token standard (ERC-3643-compatible) for transfer control and compliance hooks.
- OpenZeppelin-reviewed patterns; formal verification where applicable.
Custody & treasury
Investor funds and issuer treasuries are segregated. Custody integrations follow institutional-grade key management — multi-party controls, hardware security modules where required, and proof-of-reserve attestations published for qualifying offerings.
Operational controls
- Immutable audit logs for admin actions, approvals, and overrides.
- Four-eyes review for high-risk compliance decisions.
- Role-based access with mandatory 2FA for privileged accounts.
- Incident response and breach notification procedures aligned with DPDP / GDPR.
- Encrypted backups, PII-scrubbed application logs, defined retention schedules.
Due diligence on issuers
Every project passes an internal review workflow — draft, compliance review, approved, live — with a documented due-diligence checklist. Offerings require proof of independent contract audit, clear disclosure documents, and verified issuer identity before listing.
Note
Standards described here reflect our engineering and operational design. Final regulatory licensing, entity structure, and third-party attestations will be published as they are confirmed with counsel and auditors.