Security

Security, documented.

Non-custodial by default. Smart-contract audits by a tier-1 firm. SOC 2 and ISO 27001 programs active. Partner compliance pack on request.

Certification and audit program

Every partner gets the current posture snapshot with their compliance pack, including audit schedule, auditor identity, and scope.

ProgramStatusMilestone
SOC 2 Type IIn progressReport H2 2026
SOC 2 Type IIScheduledObservation window opens after Type I
ISO 27001In progressStage 1 audit H2 2026
GDPRActiveArt. 28 DPA with every partner. DPO engaged.
MiCA postureActiveLegal opinion on file. Shared with partners under NDA.
Smart-contract auditsScheduledPre-mainnet for every contract. Tier-1 auditor. Reports published post-remediation.
External pen-testScheduledAnnual cadence. First report available to enterprise partners.
Responsible disclosureActiveFormal program. Bounty platform partnership in selection.

Architecture principles

  1. Non-custodial by default. End-user funds sit in ERC-4337 smart-contract wallet accounts. The user's passkey (or MPC share plus recovery key) holds signing authority. We don't hold keys or funds. You don't hold keys or funds.
  2. Least-privilege everywhere. Session keys are time-boxed and scope-limited. Service-account keys are scoped to each microservice. Partner API keys are scoped to the partner namespace.
  3. Audit-log everything. Every state change emits a signed event. Merkle-rolled, periodically anchored on-chain. Retention 7 years by default.
  4. Key management. Production keys live in cloud-KMS. No private keys in Git, env files, or logs. 90-day rotation.
  5. Network segmentation. Production VPCs are isolated. Webhook sender IPs are published. Admin access goes through the cloud-provider session manager with MFA.

Responsible disclosure

Email security@ovaal.io. PGP key published at /.well-known/pgp-key.asc.

Acknowledgement within 24 hours. Triage and severity within 72 hours. Remediation timeline within 1 week. Disclosure coordination per OWASP standard.

High-severity researchers get paid cash rewards. Scope and reward bands publish on our bounty-platform partner once the managed program goes live.