Documentation

Security

Defense-in-depth architecture protecting every swap from wallet to chain. Cold custody, multi-sig governance, continuous penetration testing, and a public bug bounty.

Security Architecture

Velox operates a layered security model designed to protect user assets at every stage of the swap lifecycle. From wallet key management through on-chain settlement, every component is hardened, monitored, and independently tested.

The platform does not custody user funds — swaps settle atomically via smart contract directly to the user's wallet. However, the gas reserve and operational infrastructure require their own security guarantees, which we detail below with full transparency.

Defenses

Security Controls

Every layer of the Velox infrastructure is protected by controls that have been reviewed and tested by independent security auditors.

✓ Enforced

Multi-Signature Governance

All protocol upgrades, fee parameter changes, and gas reserve withdrawals require a 4-of-7 multi-sig threshold. Signers are geographically distributed and use hardware security modules.

✓ Enforced

Hardware Security Modules

Operational signing keys are stored in FIPS 140-2 Level 3 HSMs. Private keys never leave the secure enclave — all signing operations occur within tamper-resistant hardware.

✓ Enforced

DDoS Protection

Layer 7 traffic is routed through Cloudflare's enterprise-grade Web Application Firewall with rate-based DDoS mitigation. Origin IP addresses are never exposed publicly.

✓ Enforced

Two-Factor Authentication

All administrative access to infrastructure, dashboards, and CI/CD pipelines requires hardware-backed WebAuthn 2FA. SMS-based recovery is disabled. U2F/FIDO2 keys are mandatory for all team members.

✓ Enforced

Rate Limiting & Abuse Detection

API endpoints are protected by per-key and per-IP rate limiters. Anomaly detection triggers automatic circuit breakers when swap patterns deviate from baseline. No single actor can degrade service for others.

✓ Enforced

Immutable Audit Logs

Every administrative action, configuration change, and key operation is logged to an append-only, cryptographically verifiable audit trail. Logs are shipped off-site in real time and retained for a minimum of seven years.

Wallet Custody Model

Velox does not custody user funds — swaps are non-custodial by design. However, the protocol maintains operational wallets for gas sponsorship and fee collection. These are secured under a tiered custody model.

Wallet Tier Purpose Custody Type Signing Threshold Funds Exposure Rotation
Gas Hot Wallet Sponsors user transaction fees on TRON Hot Single-sig (HSM) ~15,000 TRX max (~$4,950) Daily auto-top-up from warm
Gas Warm Wallet Refills the hot wallet as needed Warm 2-of-3 multi-sig ~150,000 TRX max (~$49,500) Quarterly key rotation
Fee Collection Receives platform fee revenue Cold 4-of-7 multi-sig Accumulates; swept monthly Annual rotation
Treasury Reserve Long-term protocol reserves Cold 4-of-7 multi-sig Majority of protocol assets Annual rotation

Cold-to-Hot Ratio

Over 92% of protocol-managed assets are held in cold storage (4-of-7 multi-sig with geographically distributed hardware wallets). Hot and warm wallets are capped and automatically replenished — their compromise cannot drain more than the cap allows.

Penetration Testing

Velox undergoes recurring penetration tests covering the full attack surface: web application, API endpoints, WebSocket infrastructure, and cloud environment. Tests are conducted by external firms on a fixed cadence, with supplementary internal red-team exercises between engagements.

Q1

External Penetration Test — Cure53 (Jan 2026)

Full-scope black-box test against production infrastructure. Two medium-severity findings related to CSP header configuration were remediated within 48 hours. No high or critical findings.

All Findings Resolved
Q2

Internal Red Team Exercise (Apr 2026)

Simulated insider-threat scenario targeting CI/CD pipeline and key management infrastructure. Led to improvements in build attestation and deployment signing. Zero production impact.

Improvements Deployed
Q3

External Penetration Test — Upcoming (Sep 2026)

Next scheduled third-party test covering the SwapRouter v2.1 deployment, WebSocket upgrade, and new API authentication flow. Scope and firm to be announced.

Scheduled

Bug Bounty Program

Velox maintains a public bug bounty program hosted on Immunefi. Researchers who identify and responsibly disclose vulnerabilities are compensated based on severity and asset impact. The program covers smart contracts, backend infrastructure, and the web application.

Severity Smart Contract Web / API Example
Critical $50,000 — $150,000 $15,000 — $50,000 Direct loss of user funds, unauthorized contract upgrade, private key extraction
High $15,000 — $50,000 $5,000 — $15,000 Manipulation of swap rate, gas reserve drain, authentication bypass
Medium $5,000 — $15,000 $1,000 — $5,000 Fee calculation error under specific conditions, CSRF in sensitive endpoint
Low $500 — $2,000 $250 — $1,000 Gas inefficiency, missing input validation, information disclosure (non-sensitive)

Submissions are triaged within 24 hours and resolved on a timeline commensurate with severity. The full bounty scope, rules of engagement, and safe harbor provisions are published at immunefi.com/velox. Researchers are protected from legal action when operating within the published scope.

Incident Response

Velox maintains a documented, tested incident response plan covering security breaches, smart contract anomalies, and infrastructure outages. The plan defines escalation paths, communication protocols, and recovery procedures.

1

Detection & Triage

24/7 monitoring via on-chain event watchers, API anomaly detectors, and infrastructure health probes. Alerts are triaged by the on-call security engineer within 15 minutes. Critical alerts page the full incident response team.

2

Containment

Circuit breakers can pause the swap engine within one block (~3 seconds) via multi-sig. Gas reserve access is automatically throttled when anomalous withdrawal patterns are detected. System-wide pause requires 2-of-7 signers.

3

Communication

Status-page updates within 30 minutes of confirmed incident. Detailed post-mortem published within 5 business days of resolution. Direct notification to institutional partners via dedicated channels. Transparency is non-negotiable.

4

Recovery & Post-Mortem

After root cause is confirmed and remediated, service is restored under heightened monitoring for 72 hours. A blameless post-mortem is conducted, published, and all action items are tracked to completion in the public changelog.