Regent Protocol Start building
Security

Posture, stated precisely.

How we defend the control layer — and exactly which assurances exist today versus which are on the roadmap. No certificate theater.

Identity & credentials

No bearer secrets on agents

Agents never hold payment credentials; identity payloads are KMS-signed at registration; the responsible party is always the verified session user, never a client-supplied value.

Enforcement

Fail closed

If the control layer cannot decide — identity unreachable, proof unmintable — the money action is refused, and the refusal is recorded.

Audit integrity

Structural tamper-evidence

Hashes on receipt, Merkle batching, on-chain commitments — altering a record after the fact breaks the math, not a policy.

Operations

Defense in depth

Multi-sig on program upgrades; per-IP rate limiting on every endpoint; org-scoped authorization on every route.

Assurance status
ItemStatusWhat that means
Independent security auditPLANNEDWill be stated here only when the report is public
SOC 2ROADMAPNo compliance claim before completion
Responsible disclosureOPENSecurity reports: info@regentprotocol.org

No bug-bounty program exists yet; we don't promise one until it does.

Trust Center → Contact security