1
Dedicated security leadership
Security has dedicated senior oversight through our CISO function, with responsibility for
maintaining and continuously developing our security programme.Our security approach is supported by:
- Ongoing risk assessments
- Independent testing and assurance
- Relevant industry certifications and standards
2
Secure and resilient infrastructure
We apply established security practices to harden our infrastructure and production
environments. Development, testing and production environments are segregated to reduce
operational risk and limit the potential impact of security events.Our infrastructure is regularly assessed and maintained. No production data is used for testing
or in non-production environments.
3
Controlled production access
Access to production systems is tightly controlled and granted according to role and business
need. Access is granted on a just-in-time, peer approved basis with no standing permissions to
production for any staff. Sensitive access is subject to peer review and regular permission
reviews to ensure that access remains appropriate and limited to what is required.Privileged activity is subject to appropriate oversight and control.
4
Continuous monitoring
We maintain continuous monitoring and observability across our production environment to
identify anomalous activity, operational issues and potential security events.Established processes support the timely investigation, escalation and response to identified
issues.
5
Data resilience and recovery
Critical data is backed up using controlled processes designed to support recovery and business
continuity.Our approach to data resilience forms part of our broader operational risk and recovery planning,
which includes regularly testing and validating our Disaster Recovery procedures. Disaster
recovery test results may be available upon request, subject to an NDA.
6
Secure software development
Security is considered throughout the software development lifecycle. Our development practices
incorporate appropriate peer review and testing, and third-party libraries and dependencies are
continuously assessed for known vulnerabilities and licensing.Identified vulnerabilities are evaluated and remediated according to their risk, potential
impact and exploitability.Details of completed smart contract audits and reviews of our off-chain components are available
here.
7
Continuous improvement
Security is an ongoing responsibility. We regularly review our controls, assess emerging risks
and use the results of monitoring, testing and independent assurance to strengthen our security
programme over time.