Security & Compliance

Custody you can verify.
Insurance you can claim.

MPC custody, $500M of insurance through Lloyd's of London, audited every 90 days, licensed in 38 jurisdictions. The kind of paranoid engineering that lets you sleep.

$500M
Lloyd's insurance coverage
95%
Assets in cold storage
90 days
Penetration test cadence
0
Customer-funds incidents

Defence in Depth

Four layers between an attacker and your funds.

Every layer is independent. Compromising one tells you nothing about the others.

MPC key generation

Keys are generated and split across three secure enclaves. No single party can sign alone. Recovery is mathematical, not human.

Biometric approval

Face ID and Touch ID gate every withdrawal above your policy threshold. Optional hardware key step-up.

Cold storage by default

95% of assets sit in air-gapped storage. Withdrawals from warm storage capped at 5% rolling 24h.

Geo-distributed signing

Co-signers in Zurich, Singapore and Toronto. No single jurisdiction can freeze your assets.

Certifications

Audited. Licensed. Insured.

The certifications you'd expect from a major custodian — and a few you wouldn't.

SOC 2 Type II

Annually audited by Deloitte. Continuous monitoring across security, availability and confidentiality.

ISO 27001:2022

Information security management certified by Bureau Veritas.

MiCA-licensed

Full crypto-asset service provider authorisation, Republic of Ireland.

PCI-DSS Level 1

Card production and processing certified to the highest tier.

GDPR & CCPA

Privacy-by-design. Data minimisation. Right to deletion enforced cryptographically.

Travel Rule (FATF)

Sumsub integration covers every jurisdiction with active rules.

Transparency

Proof of reserves, live.

Every Aurapay vault is independently attested by Armanino LLP every 24 hours. The Merkle root is published on-chain. You can verify your own balance is included in under a minute.

  • Daily on-chain attestations
  • Self-verifiable Merkle proofs
  • Public dashboard with real-time AUM
  • No rehypothecation. Ever.
Proof of reservesverified · 02:14 UTC
BTC47,210.482$3.06B
ETH412,884.220$1.04B
USDC1,820,400,000$1.82B
USDT640,210,000$640M
SOL1,202,440$185M
Total assets$6.75B
Total liabilities$6.71B
Reserve ratio100.6%

Bug Bounty

Up to $5M per critical.

We'd rather pay you to find it than read about it on Twitter.

Critical
$5M
Funds at risk · RCE
High
$250k
Auth bypass · privilege escalation
Medium
$25k
Data exposure · partial DOS
Low
$2k
Information disclosure

Read the security paper.

40 pages on key generation, threat model, recovery and disaster scenarios. Written by engineers, reviewed by Trail of Bits.