# Security and audits (/docs/resources/security-and-audits)



## Read audit status by component and version [#read-audit-status-by-component-and-version]

This documentation was checked against implementation sources. That review is not an independent security audit. A feature running on testnet also does not establish production audit clearance.

Status checked on **17 September 2026**:

| Component                                | Available evidence                                                                                                  | Coverage limit                                                                                                                 |
| ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| Business Validator protocol              | The reviewed release-gap register lists an independent audit as an open mainnet requirement                         | No completed independent audit report was verified for revision `8a880c2` or its testnet deployment                            |
| JurisdictionModule                       | Project records report an external audit completed and remediated on 3 July 2026, with remediation commit `1f656e7` | The external report is held by platform operations; a public report and match to the deployed implementation were not verified |
| EscrowedOffering and SecondaryMarket     | Specifications describe a combined external audit/release gate                                                      | Completion and coverage of current deployments were not verified; testnet feature flags are not audit evidence                 |
| AssetMetadataRegistry and IssuerRegistry | Implementation source was reviewed                                                                                  | Independent audit coverage was not verified                                                                                    |
| Upstream T-REX and ONCHAINID             | Dependencies provide token and identity contracts                                                                   | This edition does not verify upstream audit coverage for every deployed version and integration                                |

“Not verified” means available evidence did not establish the claim. It does not assert that no review has ever taken place.

## Assess a release [#assess-a-release]

An applicable audit identifies the revision, contracts, exclusions, findings, remediation, and subsequent changes. A module audit does not cover later upgrades, the entire platform, or an asset's legal and operational risks.

Read [Trust model and admin powers](/docs/resources/trust-model) alongside this page. Upgrades, identity administration, external payment records, and price inputs remain relevant even for audited code.

Testnet supports integration testing with test assets. Production deployment and operational readiness require separate evidence. Remaining documentation gaps are maintained on [Documentation status](/docs/resources/documentation-status).
