
Security
Protecting digital assets with institutional-grade infrastructure. Our security architecture is designed to meet the requirements of regulated financial institutions.
All private keys generated and stored in FIPS 140-2 Level 3 HSMs (AWS CloudHSM, Azure Dedicated HSM, Thales Luna). Never leaves the module in plaintext.
Read docs →2-of-3 and 3-of-5 threshold signing. Key shares distributed across geographic regions and organizational boundaries — no single party can move funds.
Read docs →NIST FIPS 204 (ML-DSA / Dilithium), FIPS 203 (ML-KEM / Kyber), FIPS 205 (SLH-DSA / SPHINCS+). End-to-end quantum-safe — consensus, signing, key exchange, MPC.
Read docs →CKKS-based FHE coprocessor on the Z/A-Chain VM. Orders matched, portfolios analyzed, and compliance checks run on encrypted data — values never decrypted.
Read docs →OIDC via Hanzo IAM (hanzo.id). SAML 2.0 and OAuth 2.0 for your IdP. Role-based access, fine-grained scopes, and full audit log.
Read docs →SOC 2 Type II, penetration-tested by independent firms, full audit trail on every transaction. KYC/AML, sanctions, SAR/CTR built into the pipeline.
Read docs →Annual third-party penetration tests conducted by leading security firms. Continuous vulnerability scanning with automated remediation workflows.
24/7 security operations center (SOC) monitoring. Documented incident response procedures with defined SLAs and communication protocols.
Multi-region disaster recovery with RPO/RTO targets. Regular DR drills and documented recovery procedures. Encrypted off-site backups.
Rigorous third-party risk assessment program. All critical vendors undergo security review and contractual security requirements.
Full list of third-party security reviews of the Lux Network, consensus, EVM, bridge, and smart contracts — open for public review at github.com/luxfi/audits.
Machine-checked proofs of Quasar certificate soundness, post-quantum finality without BLS, and protocol safety — github.com/luxfi/proofs.
Comprehensive security model of the Lux Network: threat model, assumptions, reductions, and defense-in-depth.
How keys flow between HSMs, threshold MPC, and on-chain signing — with the attacker model and key-custody proofs.
The review process, tooling (Slither, Halmos, Foundry invariants), and acceptance criteria for contracts shipping to mainnet.
Every paper across Lux, Hanzo, and Zoo — consensus, PQ crypto, FHE, threshold signing, DeFi, and AI safety.
We work with security researchers to identify and address vulnerabilities. If you discover a security issue, please report it responsibly.
security@lux.financialOur security team is available to discuss your specific requirements.
Talk to Sales