Security and controls

The platform is built around the assumption that it will be audited. These are the controls an auditor, custodian or regulator will ask about, stated plainly.

Four eyes on everything that matters

Asset approval, issuance opening, allotment, dividends, forced transfers, freezes, corporate actions, insolvency declaration and material NAV changes each need a requester and a different approver. The platform refuses self-approval.

Funds before units

No allotment until the custodian confirms receipt against the subscription reference. Minting follows allotment, never the other way round.

Register reconciled

The on-chain ledger, the platform register and the SPV's legal register are reconciled; custodians record proof of reserve and settlement attestations that investors can see.

Privacy-safe register

Identity documents are stored as hashes; the register holds statuses, expiries and evidence hashes, not the documents. Duplicates are refused or flagged.

Immutable audit trail

Every action is logged with actor, entity and IP. The Fund Suite's audit log is hash-chained and can be re-verified in one call.

Keys and access

Provider API keys are stored hashed and shown once; sessions use secure, same-site cookies; logins are rate-limited. NAV root keys and issuer chain keys belong in an HSM or multisig in production, and the deployment guide says so.

Contract assurance

Independent smart-contract audit on every deployment with findings closed before mainnet; penetration test of portals and APIs before launch; change control for upgrades.

People

Certified Information Systems Auditor and Certified Fraud Examiner on the team for control design and review; Chartered Accountants and a Company Secretary for the register and corporate actions.

To report a security issue in the website or platform, write to hello@kubermint.com with "security" in the subject. We acknowledge within two working days.