Skip to content

Security & trust

Trust is something we evidence, not claim

Here is how Aureon controls access, models custody, and records audit evidence — and precisely which gates remain external.

Role-based access & tenant isolation

Every operator action is governed by role-based access control with tenant isolation. The API verifies the JWT signature and authorizes on each request — the client never enforces authority on its own.

Custody by design (multisig)

Aureon's custody model is designed around multisig approval. Production signing is disabled, and the PROD-9 custody gate stays closed until a real key ceremony and hardware evidence are in place.

Audit & evidence

Operator actions are recorded with correlation IDs; readiness and runtime truth are surfaced rather than asserted. Local proof manifests and reproducible checks back every status we publish.

Production gates that stay closed

Custody, external security audit, legal/compliance sign-off, and on-chain deployment are explicit gates. None are bypassed for appearance; the platform is production NO-GO until each is genuinely met.

What's proven vs external

The honest gate status

A green item is proven and currently healthy. Blocked and pending items are owner- or vendor-gated and remain closed.

Engineering environmentLocally verified
Local Besu networkHealthy — 4 validators, chain ID 20250
Remote CINot executed — account billing gate
ProductionNO-GO — not authorized
AUR tokenNot deployed
FeeRouterNot deployed
Custody (PROD-9)Not proven — blocked
Production signingDisabled
External auditNot passed
Regulatory approvalNot obtained