DeFlow Docs
Private betaVerified 2026-08-17

Risk and Assurance Status

Review DeFlow's current technical, operational, governance, legal, network, and assurance boundaries.

Current assurance status

AreaStatusWhat that means
External smart-contract auditNot engagedAudit preparation exists, but no independent report is available
Legal reviewAwaiting counselCompliance, custody, privacy, AML, eIDAS, and jurisdictional claims are not certified
NetworkSepolia testnetAvailability and finality can differ from production networks
AssetsTest assetsSepolia ETH and TestUSDC have no monetary value
GovernanceSingle EOANo current multisig or timelock protection

Principal current-release risks

  • Contract defects or unexpected state transitions.
  • Governance-key compromise or inappropriate use of governance powers.
  • Testnet congestion, reorganisation, faucet, RPC, or indexing failures.
  • Sandbox verification behaviour that differs from production providers.
  • Incomplete product workflows and data resets during development.
  • Documentation drift during rapid product changes.

Reporting a security concern

Do not post a potential vulnerability publicly. Contact security@deflowlabs.io with a concise description, affected component, reproduction steps, and non-sensitive evidence. Never include private keys, seed phrases, or identity documents.

The absence of a risk from this list does not mean it has been eliminated.