Skip to main content

Our Approach

Security is foundational to Tori Finance. We employ a defense-in-depth strategy with multiple layers of protection, partnering with industry-leading security providers to safeguard protocol assets. Our security philosophy: trust but verify. Every critical component is independently audited, monitored, and attested.

Security Partners

We work exclusively with established, reputable security providers:

Sherlock and Nethermind

Smart Contract AuditsIndependent audits by two leading security firms

Hypernative

Real-Time MonitoringAI-powered 24/7 threat detection and prevention

Accountable

Proof of ReservesIndependent, real-time reserve attestations

Smart Contract Security

Audits

All Tori smart contracts are independently audited by Sherlock and Nethermind, two leading smart contract security firms. Sherlock protects over $50 billion in assets across Web3, and Nethermind is a leading blockchain research and security firm. View Audit Reports →

Bug Bounty Program

We maintain an active bug bounty program to incentivize responsible disclosure of potential vulnerabilities. How it works:
  • Security researchers can report vulnerabilities for rewards
  • Severity-based payouts for valid findings
  • Responsible disclosure process
  • Quick response to reported issues

Real-Time Monitoring

Hypernative Protection

Hypernative provides AI-powered threat detection with comprehensive monitoring:

What We Monitor

  • Smart contract interactions
  • Large or unusual transactions
  • Governance activities
  • Known attacker addresses
  • Protocol parameter changes
  • External dependencies

Proof of Reserves

Accountable Attestations

Accountable provides real-time, independent attestations on reserves and financials. This transparency enables anyone to verify the backing of trUSD at any time. What’s attested:
  • Total assets under management,
  • Liability coverage ratio,
  • Reserve fund status, and more.

Why This Matters

Unlike traditional finance where you trust institutions with your assets, Tori’s Proof of Reserves allows cryptographic verification:
  • Independent - Third-party attestation, not self-reported
  • Real-time - Continuous verification, not periodic
  • Verifiable - Anyone can check at any time
  • Transparent - Full visibility into backing

Asset Security & Custody

All assets are held in institutional-grade secure custody:

On-Chain Assets

Off-Chain Assets

Protocol reserves are never commingled with operational funds. All assets are held with qualified custodians, institutional partners, or through regulated instruments.

Operational Security

Our team follows strict operational security practices:

Access Control

Incident Response

Responsible Disclosure

Reporting Vulnerabilities

If you discover a security vulnerability, please report it responsibly: Email: [email protected]
Please do NOT:
  • Publicly disclose vulnerabilities before they’ve been addressed
  • Exploit vulnerabilities beyond what’s needed to demonstrate the issue
  • Access or modify other users’ data

What to Include

When reporting:
  • Detailed description of the vulnerability
  • Steps to reproduce
  • Potential impact assessment
  • Suggested fix (if any)

Our Commitment

  • Acknowledge receipt within 24 hours
  • Provide updates on remediation progress
  • Credit reporters (if desired) after fixes are deployed
  • No legal action against good-faith researchers

Continuous Improvement

Security is an ongoing process. Our approach:
While we employ extensive security measures, no system can guarantee perfect security. Audits are point-in-time assessments, and new challenges can emerge. This is why we use multiple layers of protection. See Risk Disclosures for more information.

Next Steps

Audit Reports

View detailed security audit reports

Contracts

View contract addresses

Backing Details

How trUSD is backed

Risk Disclosures

Understand all the risks