Security

Controls your ops, compliance, and auditors can live with.

Security is not a checklist. Pragma Credit is designed for governance: permissions, approvals, audit trails, and separation of concerns.

RBAC + approvals

Limit who can post adjustments, change marks, or initiate mint/burn workflows.

🧾

Audit trails

Activity logs + daily snapshots built to “explain the delta” quickly.

🛡

Compliance hooks

Integrate KYC/KYB/KYT checks and allowlists for restricted workflows.

Governance model

Separation of concerns: eligibility vs settlement

Keep identity and entitlement checks off-chain (or in a dedicated policy layer), while enforcing mint/burn authority via controlled program logic.

Operational controls

  • 1 Dual control for sensitive actions
  • 2 Immutable activity logging
  • 3 Evidence attachments per event
  • 4 Role-limited admin actions

Tokenization controls

  • 1 PDA authority for mint/burn
  • 2 Subscription/redemption approvals
  • 3 Allowlist / transfer policy integration
  • 4 USDC vault accounting visibility

Security posture (template)

Replace these with your real controls and certifications as you mature. This page is designed to read like enterprise fintech security pages.

AreaControlStatus
AccessRole-based access control + least privilegeAvailable
ApprovalsDual-control for sensitive workflowsAvailable
AuditImmutable activity logs + daily snapshotsAvailable
ComplianceKYC/KYB/KYT integration pointsConfigurable