Security

Enterprise-grade security architecture protecting user funds and protocol integrity across all remittance corridors.

Security Audits & Certifications

Quantstamp Full Audit

Complete smart contract audit completed Q4 2024. Zero critical issues found.

Trail of Bits Security Review

Economic security and game theory analysis. All recommendations implemented.

SOC 2 Type II Certification

Backend infrastructure compliant with SOC 2 security controls and data handling standards.

Core Security Features

Multi-Sig Custody

7-of-11 multisig wallets with geographic distribution across 4 continents. No single entity controls funds.

End-to-End Encryption

AES-256 encryption for all user data at rest and TLS 1.3 for all network communication.

Circuit Breakers

Automatic protocol pause if abnormal transaction volumes detected. 6-hour recovery activation window.

Formal Verification

Core lending contracts verified using Coq proof assistant. 99.99% correctness probability.

Risk Management Framework

LTV Collateral Caps

Dynamic loan-to-value ratios prevent over-leverage:

  • • Established corridors (>2M inflows): Max 85% LTV
  • • Growth corridors (500K-2M): Max 70% LTV
  • • New corridors (<500K): Max 50% LTV

Counterparty Risk Limits

Diversified oracle node selection and financial entity limits:

  • • Single entity max: 15% of total outstanding loans
  • • Single corridor max: 25% exposure cap
  • • Oracle concentration: Min 5 independent nodes

Insurance Fund

Protocol maintains 5% of total TVL in insurance reserve managed by multisig. Covers defaults exceeding statistical predictions.

Bug Bounty Program

We reward security researchers for responsible disclosure of vulnerabilities.

Critical$50,000 - $100,000
High$10,000 - $50,000
Medium$1,000 - $10,000
Low$100 - $1,000

Submit via security@remitstake.io with GPG encryption (public key available on GitHub)

Incident Response Policy

We maintain 24/7 security operations center and rapid response protocols for any identified threats.

Detection: Real-time monitoring with automated alerting for anomalies

Assessment: 15-minute triage to determine severity and scope

Mitigation: Immediate pause capability for affected components

Communication: Transparent updates to users and community within 1 hour