Security & Trust
Audits & security process
How we approach audits, monitoring, and incident response.
Audit status
We will publish the following.
- audit partners (when engaged)
- dates and scope
- links to reports (when available)
Scope
Aqua0's vaults, adapters, and Composer are built on audited OpenZeppelin primitives, not custom re-implementations of that plumbing.
| Contracts | Built on | Upgrade path |
|---|---|---|
| Per-asset vault | AccessControlUpgradeable, PausableUpgradeable, ReentrancyGuard | Shared UpgradeableBeacon, owned by a timelocked multisig |
| Composer, vault factory, vault registry | UUPSUpgradeable | Each singleton upgrades itself |
Audit effort is scoped to the thin Aqua0-specific layer built on top of those primitives, not a re-audit of the underlying OpenZeppelin code.
- the async withdrawal request/claim path and its settlement guard
- the hybrid PnL harvest, reconciliation, and clawback logic
- adapter wiring
- the Composer's routing and authorization
Security process (high-level)
- staged deployments and controlled rollouts
- monitoring and alerting
- fast incident response and clear communications