Fortress, not a badge

How we think about keys, custody, and the things that wake you at 3am.

Security Center is the public fortress: encryption in transit and at rest, access, monitoring, and how a pre-launch company talks about custody without pretending to be a bank. The legal Security page remains the short policy. This is the longer desk.

Transport

TLS. No cute exceptions for “just the waitlist.”

At rest

Encrypted stores for anything that is not public copy.

Access

Least privilege for staff. No shared root as culture.

Monitoring

Logs that a human will actually read.

Custody thinking

Segregation as a design, not a slogan. Partners when live.

Incidents

We will not fake a status history. When we have ops, we say so.

Risk Center
DA

Drawdown

−6.1%

Within band

Liquidity 30d

71%

Watch

Concentration

18%

OK

FX NAD

High

Hedged 40%

Credit

BB+

RWA sleeve

Ops

Green

No incidents

app.delvue.assets/security-center

Two URLs on purpose

/security is the short legal/security page already on the site. /security-center is the product fortress: how the desk is meant to be built. If they ever conflict, the legal page plus contracts win.

  • Legal brevity vs practice depth
  • No SOC2 theatre PDF unless we have one
  • Vendor questionnaires via waitlist / contact

Custody is not a CSS gradient

When assets exist, they should not sit in a hot wallet dressed as a product. Segregated accounts, registers for tokens, and clear failure modes belong in launch docs. This center is the promise to write them in public language.

  • Asset custody as a named topic
  • Transparency Center for verification philosophy
  • We will not say “bank-grade” without naming a bank

Application security

Auth, sessions, Google sign-in when Supabase is configured, waitlist forms that do not store extra junk. If you find a hole, contact us; do not file it as a fun tweet.

  • Auth is real-ish where configured; investing is not
  • No secrets in the public repo on purpose — tell us if we slip
  • Developer keys never in the marketing footer
01

Read /security

The short policy.

02

Read this center

The practice.

03

Read compliance

The licence-shaped questions.

04

Ask

Institutions: send the questionnaire.

LayerIntentNot claimed
SiteHTTPS, sane formsUnhackable
AccountsLeast privilegeZero staff risk
CustodySegregate when liveWe are a bank
TokensRegister + legalCode is law

Bug bounty?

Not a formal program on this page. Contact still works.

Pentest?

We will publish when we have something true to publish.

Proof of reserves?

RWA verification ≠ exchange PoR. See Transparency Center.

Status?

System Status on the site is currently a simple page — not a fake 99.99% history.

Security Center is on the map. The desk is not live.

Join the waitlist if this page is why you showed up. We email when onboarding opens.