> ## Documentation Index
> Fetch the complete documentation index at: https://docs.digitalasset.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Practices

> Our security stance.

Security is a fundamental part of how we operate. We recognise that firms using our **Registry**
application entrust us with sensitive information and technology supporting the issuance, management
and transfer of tokenised assets. We therefore take a structured, risk-based approach to security
across our people, processes and technology.

Security is embedded across our technology, processes and operations, with dedicated leadership,
disciplined controls and ongoing independent assessment.

<Steps>
  <Step title="Secure and resilient infrastructure">
    We apply established security practices to harden our infrastructure and production
    environments. Development, testing and production environments are segregated to reduce
    operational risk and limit the potential impact of security events.

    Our infrastructure is regularly assessed and maintained to support a secure and resilient
    operating environment.
  </Step>

  <Step title="Controlled production access">
    Access to production systems is tightly controlled and granted according to role and business
    need. Sensitive access is subject to peer review and regular permission reviews to ensure that
    access remains appropriate and limited to what is required.

    Privileged activity is subject to appropriate oversight and control.
  </Step>

  <Step title="Continuous monitoring">
    We maintain continuous monitoring and observability across our production environment to
    identify anomalous activity, operational issues and potential security events.

    Established processes support the timely investigation, escalation and response to identified
    issues.
  </Step>

  <Step title="Data resilience and recovery">
    Critical data is backed up using controlled processes designed to support recovery and business
    continuity.

    Our approach to data resilience forms part of our broader operational risk and recovery planning
    , which includes regularly testing and validating our Disaster Recovery procedures. Disaster
    recovery test results may be available upon request, subject to an NDA.
  </Step>

  <Step title="Secure software development">
    Security is considered throughout the software development lifecycle. Our development practices
    incorporate appropriate review and testing, and third-party libraries and dependencies are
    continuously assessed for known vulnerabilities.

    Identified vulnerabilities are evaluated and remediated according to their risk and potential
    impact.

    Details of completed smart contract audits and reviews of our off-chain components are available
    [here](https://docs.digitalasset.com/registry/security/audits).
  </Step>

  <Step title="Dedicated security leadership">
    Security has dedicated senior oversight through our CISO function, with responsibility for
    maintaining and continuously developing our security programme.

    Our security approach is supported by ongoing risk assessment, independent testing and assurance
    , and relevant industry certifications and standards.

    For further information on our security posture, controls and certifications, please visit our
    [Trust Center](https://www.digitalasset.com/trust-center).
  </Step>

  <Step title="Continuous improvement">
    Security is an ongoing responsibility. We regularly review our controls, assess emerging risks
    and use the results of monitoring, testing and independent assurance to strengthen our security
    programme over time.
  </Step>
</Steps>
