1
Secure and resilient infrastructure
We apply established security practices to harden our infrastructure and production
environments. Development, testing and production environments are segregated to reduce
operational risk and limit the potential impact of security events.Our infrastructure is regularly assessed and maintained to support a secure and resilient
operating environment.
2
Controlled production access
Access to production systems is tightly controlled and granted according to role and business
need. Sensitive access is subject to peer review and regular permission reviews to ensure that
access remains appropriate and limited to what is required.Privileged activity is subject to appropriate oversight and control.
3
Continuous monitoring
We maintain continuous monitoring and observability across our production environment to
identify anomalous activity, operational issues and potential security events.Established processes support the timely investigation, escalation and response to identified
issues.
4
Data resilience and recovery
Critical data is backed up using controlled processes designed to support recovery and business
continuity.Our approach to data resilience forms part of our broader operational risk and recovery planning
, which includes regularly testing and validating our Disaster Recovery procedures. Disaster
recovery test results may be available upon request, subject to an NDA.
5
Secure software development
Security is considered throughout the software development lifecycle. Our development practices
incorporate appropriate review and testing, and third-party libraries and dependencies are
continuously assessed for known vulnerabilities.Identified vulnerabilities are evaluated and remediated according to their risk and potential
impact.Details of completed smart contract audits and reviews of our off-chain components are available
here.
6
Dedicated security leadership
Security has dedicated senior oversight through our CISO function, with responsibility for
maintaining and continuously developing our security programme.Our security approach is supported by ongoing risk assessment, independent testing and assurance
, and relevant industry certifications and standards.For further information on our security posture, controls and certifications, please visit our
Trust Center.
7
Continuous improvement
Security is an ongoing responsibility. We regularly review our controls, assess emerging risks
and use the results of monitoring, testing and independent assurance to strengthen our security
programme over time.