Our Approach
Security is foundational to Tori Finance. We employ a defense-in-depth strategy with multiple layers of protection, partnering with industry-leading security providers to safeguard protocol assets. Our security philosophy: trust but verify. Every critical component is independently audited, monitored, and attested.Security Partners
We work exclusively with established, reputable security providers:Sherlock and Nethermind
Smart Contract AuditsIndependent audits by two leading security firms
Hypernative
Real-Time MonitoringAI-powered 24/7 threat detection and prevention
Accountable
Proof of ReservesIndependent, real-time reserve attestations
Smart Contract Security
Audits
All Tori smart contracts are independently audited by Sherlock and Nethermind, two leading smart contract security firms. Sherlock protects over $50 billion in assets across Web3, and Nethermind is a leading blockchain research and security firm.
View Audit Reports →
Bug Bounty Program
We maintain an active bug bounty program to incentivize responsible disclosure of potential vulnerabilities. How it works:- Security researchers can report vulnerabilities for rewards
- Severity-based payouts for valid findings
- Responsible disclosure process
- Quick response to reported issues
Real-Time Monitoring
Hypernative Protection
Hypernative provides AI-powered threat detection with comprehensive monitoring:What We Monitor
- Smart contract interactions
- Large or unusual transactions
- Governance activities
- Known attacker addresses
- Protocol parameter changes
- External dependencies
Proof of Reserves
Accountable Attestations
Accountable provides real-time, independent attestations on reserves and financials. This transparency enables anyone to verify the backing of trUSD at any time. What’s attested:- Total assets under management,
- Liability coverage ratio,
- Reserve fund status, and more.
Why This Matters
Unlike traditional finance where you trust institutions with your assets, Tori’s Proof of Reserves allows cryptographic verification:- Independent - Third-party attestation, not self-reported
- Real-time - Continuous verification, not periodic
- Verifiable - Anyone can check at any time
- Transparent - Full visibility into backing
Asset Security & Custody
All assets are held in institutional-grade secure custody:On-Chain Assets
Off-Chain Assets
Protocol reserves are never commingled with operational funds. All assets are held with qualified custodians, institutional partners, or through regulated instruments.
Operational Security
Our team follows strict operational security practices:Access Control
Incident Response
Responsible Disclosure
Reporting Vulnerabilities
If you discover a security vulnerability, please report it responsibly: Email: [email protected]What to Include
When reporting:- Detailed description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Suggested fix (if any)
Our Commitment
- Acknowledge receipt within 24 hours
- Provide updates on remediation progress
- Credit reporters (if desired) after fixes are deployed
- No legal action against good-faith researchers
Continuous Improvement
Security is an ongoing process. Our approach:While we employ extensive security measures, no system can guarantee perfect security. Audits are point-in-time assessments, and new challenges can emerge. This is why we use multiple layers of protection. See Risk Disclosures for more information.
Next Steps
Audit Reports
View detailed security audit reports
Contracts
View contract addresses
Backing Details
How trUSD is backed
Risk Disclosures
Understand all the risks