Pre-production MVPEVM-first · Chain-agnostic · Production network not selectedProduct status

Trust / Security

Security claims should be inspectable.

Novera treats security as a lifecycle discipline across requirements, design, implementation, testing, and release. Current safeguards and planned controls are intentionally separated.

MVP

Public security guidance

The public repository defines reporting scope and handling guidance. No external audit or certification is claimed.

Open SECURITY.md

Control posture

Current safeguards and planned evidence.

PLANNED

Threat modeling

Document assets, actors, trust boundaries, abuse cases, and mitigations as architecture matures.

MVP

Data minimization

The MVP is limited to synthetic data and should not accept real identity documents or sensitive customer information.

MVP

Secrets discipline

Credentials, keys, seed phrases, and production configuration remain outside public materials and source.

PLANNED

Independent review

Security review is a production eligibility requirement. No completed audit is claimed.

PLANNED

Incident readiness

Operational monitoring, incident response, and continuity controls will be defined before production eligibility.

MVP

Responsible disclosure

The public repository includes scope, reporting guidance, and a non-public contact path.

Current data boundary

Synthetic data only.

Do not submit real identity documents, customer data, payment credentials, wallet keys, confidential legal documents, or regulated records to the MVP or through the public contact flow.

Audit status

No audit claimed.

No smart-contract, application, infrastructure, compliance, or certification audit is represented as complete. Any future audit will be named, dated, scoped, and linked.

Report a vulnerability

Use the public security policy.

Please follow the reporting guidance in the public repository. Do not include sensitive personal data or exploit public systems while reporting.

Security reporting instructions

System trust

Review every boundary.

Security posture depends on the architecture, product scope, integration status, and regulatory boundaries working together.