Security & governance
Controls designed for independent validation.
ChainGuard is built around operational controls that a bank's own security and audit functions can inspect and test. They are presented here alongside an honest account of what remains open.
Implemented controls
Four control domains, each doing one job.
These are implemented in the platform today. They are grouped by the function they serve, so a reviewer can map them to their own control framework rather than read a flat list.
Identity and access
Who can act, and under what authority.
- Multi-factor authentication
- Role-based permissions
- Session revocation
- Break-glass audit
Segregation of duties
No single operator completes a sensitive action alone.
- Maker / checker
- Threshold governance
- Release controls
- Incident management
Record integrity
What was decided stays retrievable and intact.
- Append-only audit records
- Evidence integrity hashes
- Legal hold
- Versioned policies
Boundary hardening
What the platform accepts from, and sends to, the outside.
- Secret references
- Webhook validation
- SSRF controls
- Model validation
Change governance
What changes, changes under a recorded process.
The artefacts that determine an outcome are versioned and governed. A decision made last quarter can be re-read against the exact configuration that produced it.
- PoliciesVersioned; the version in force is recorded on every decision
- Rules and thresholdsChanged under threshold governance, never edited silently
- ModelsValidated before activation; activation flags default off
- Evidence packagesContent-hashed and subject to legal hold
- ReleasesPromoted under release controls with a recorded approver
- IncidentsManaged through a defined path with an audit trail
Assurance status
What remains open, stated plainly.
A compliance platform that overstates its own assurance position is the wrong platform for a regulated institution. These items are open.
Independent external security assessment
Required before any production-readiness claim. ChainGuard does not present its own testing as a substitute for third-party assessment.
Credential-rotation remediation
An operational prerequisite for any deployment, completed jointly with the institution before go-live.
Provider-specific certification
Depends on the deployment scope agreed with each institution, and on the providers that scope brings into the boundary.
Security controls are designed for independent validation within each deployment program. Nothing on this page should be read as a certification, an attestation, or a substitute for your own assessment.
Review the security and governance model for your deployment.
Map ChainGuard to your institution’s transaction, policy and evidence workflows.