Private betaVerified 2026-08-17
Risk and Assurance Status
Review DeFlow's current technical, operational, governance, legal, network, and assurance boundaries.
Current assurance status
| Area | Status | What that means |
|---|---|---|
| External smart-contract audit | Not engaged | Audit preparation exists, but no independent report is available |
| Legal review | Awaiting counsel | Compliance, custody, privacy, AML, eIDAS, and jurisdictional claims are not certified |
| Network | Sepolia testnet | Availability and finality can differ from production networks |
| Assets | Test assets | Sepolia ETH and TestUSDC have no monetary value |
| Governance | Single EOA | No current multisig or timelock protection |
Principal current-release risks
- Contract defects or unexpected state transitions.
- Governance-key compromise or inappropriate use of governance powers.
- Testnet congestion, reorganisation, faucet, RPC, or indexing failures.
- Sandbox verification behaviour that differs from production providers.
- Incomplete product workflows and data resets during development.
- Documentation drift during rapid product changes.
Reporting a security concern
Do not post a potential vulnerability publicly. Contact security@deflowlabs.io with a concise description, affected component, reproduction steps, and non-sensitive evidence. Never include private keys, seed phrases, or identity documents.
The absence of a risk from this list does not mean it has been eliminated.