The platform is built around the assumption that it will be audited. These are the controls an auditor, custodian or regulator will ask about, stated plainly.
Asset approval, issuance opening, allotment, dividends, forced transfers, freezes, corporate actions, insolvency declaration and material NAV changes each need a requester and a different approver. The platform refuses self-approval.
No allotment until the custodian confirms receipt against the subscription reference. Minting follows allotment, never the other way round.
The on-chain ledger, the platform register and the SPV's legal register are reconciled; custodians record proof of reserve and settlement attestations that investors can see.
Identity documents are stored as hashes; the register holds statuses, expiries and evidence hashes, not the documents. Duplicates are refused or flagged.
Every action is logged with actor, entity and IP. The Fund Suite's audit log is hash-chained and can be re-verified in one call.
Provider API keys are stored hashed and shown once; sessions use secure, same-site cookies; logins are rate-limited. NAV root keys and issuer chain keys belong in an HSM or multisig in production, and the deployment guide says so.
Independent smart-contract audit on every deployment with findings closed before mainnet; penetration test of portals and APIs before launch; change control for upgrades.
Certified Information Systems Auditor and Certified Fraud Examiner on the team for control design and review; Chartered Accountants and a Company Secretary for the register and corporate actions.
To report a security issue in the website or platform, write to hello@kubermint.com with "security" in the subject. We acknowledge within two working days.