Security

Security you can verify.

Royco is built with security as its paramount priority. We have received multiple audits and formal verification from tier-one firms, in addition to employing continuous monitoring coupled with robust operational practices.

Live Access Control Dashboard
VIIIVIIVIVIVIIIIII
Bug Bounty
$250K
Audits
20
Settlement
24h+
Monitoring
24/7
Security Partners
Cantina
Certora
Hexens
Tomer Security First
Olympix
Hypernative
Immunefi
Nethermind
Architecture
01

Eight layers of defense.

Royco stacks eight independent defenses so a failure in any one is caught by the next.

Oracle policy

Because Royco markets can be deployed permissionlessly, each market’s oracle is selected by its creator. Asset issuers are instructed to use the asset’s fundamental balance-sheet valuation and avoid pricing based on illiquid secondary markets. Depositors should verify each market’s oracle design before participating.

Audits
02

Royco's complete audit history.

Royco Day audits and reviews are listed first, followed by the complete Royco Dawn, integration, and vault audit history.
Firm
Product
Engagement
Scope
Date
Report
Cantina
Day
Competitive Public Audit
Royco Day Core Contracts
Aug 2026
Certora
Day
Formal Verification
Royco Day Core Contracts (Autoprover)
Aug 2026
Verity Labs
Day
Formal Verification
Royco Day Invariants and Properties
Aug 2026
Cyfrin Solace
Day
AI Security Review
Royco Day Core Contracts
Aug 2026
V12
Day
AI Security Review
Royco Day Core Contracts
Aug 2026
[ No report ]
Certora
Day
Full Protocol Audit
Royco Day Core Contracts
Aug 2026
Tomer Security First
Day
Full Protocol Audit
Royco Day Core Contracts
Aug 2026
Hexens
Day
Full Protocol Audit
Royco Day Core Contracts
Aug 2026
Olympix
Day
AI Security Review
Royco Day Core Contracts
Jul 2026
Certora
Dawn
Formal Verification
Royco Dawn Core Invariants and Properties
Jul 2026
Certora
Day
Design Review
Royco Day Design Review
Jun 2026
[ No report ]
WatchPug
Pendle SY
Pendle Integration
Royco Tranche Pendle SY
Apr 2026
Certora
Dawn
Full Protocol Audit
Royco Dawn Core Contracts and Entry Point
Apr 2026
Hexens
Pendle SY
Pendle Integration
Royco Tranche Pendle SY
Apr 2026
Hexens
Dawn
Entry Point and Integrations
Royco Dawn Entry Point and Kernels
Apr 2026
Nethermind
Vault
Royco Makina Strategy
Bridge between Concrete Earn v2 and Makina
Mar 2026
Hexens
Dawn
Full Protocol Audit
Royco Dawn Core Contracts
Mar 2026
Cantina
Dawn
Competitive Public Audit
Royco Dawn Core Contracts (Whitelisted)
Feb 2026
Hexens
Dawn
Full Protocol Audit
Royco Dawn Core Contracts (Whitelisted)
Jan 2026
Hexens
Dawn
Full Protocol Audit
Royco Dawn Core Contracts
Jan 2026
External Audits
Governance
03

No hot wallet. No single signer. No instant upgrades.

Every privileged action (upgrades, parameter changes, signer rotations) moves through a predictable, on-chain procedure depositors can watch in real time.
01Proposed
02Signed(3-of-5 Multisig)
03Timelocked(72h Timelock)
04Executed
Breakdown of every privileged action by delay
Contract Upgrades72 hours
Oracle Swap72 hours
Risk Parameters72 hours
Fee Changes72 hours
Pausing/UnpausingInstant
Pausing and unpausing are instant. Neither action directly moves value. Every other listed action sits in public for 72 hours before it can execute.
Emergency Response
04

Hope is not a plan. We drilled for this long before.

We plan for failure. A security incident on Royco triggers a pre-rehearsed, on-call response, not a Slack thread at 3am.
RosterRoyco War Room

Hand-picked security engineers and council members: named, on-call, and rehearsed. When the alarm trips, the room is already live. No hunting for who’s on-call. No improvising the chain of command.

T + 0Detection
24/7
On-call rotation

Hypernative or the security council detects an anomaly. On-call rotation is paged immediately.

T + 2 MinTriage

Incident commander convenes the on-call engineers, and security council on a dedicated channel.

T + 15 MinContainment
<15m
Target MTTR

If the anomaly is confirmed, the security council executes an instant pause. Queue settlement halts.

T + 1 hourCommunication

A public post-to-known-channels status update is issued. Depositors are informed before markets are.

T + 24 hoursPost-mortem
<7d
Public write-up

A written post-mortem is prepared and published within 7 days of containment.

Open Source
05

The source is the truth. Fork it. Read it. Break it.

Every contract, test, and deployment script is public. The same files the auditors reviewed are the ones running in production.
Backed By
06

Investors who read reports. Not just pitch decks.

We chose our investors as carefully as they chose us: funds with a long record of backing protocols that take security seriously.
Electric CapitalNFXCoinbase Ventures
+ angels & operators
Curated Vaults
07

Vaults with nothing hidden. Managed in public, not in private.

Alongside the core protocol, Royco offers curated vaults, a separate product with its own security surface. Here's exactly how it's built, and exactly who's accountable for what.
01Vault Tokens
srRoyUSDCSenior Royco USDC
02Managed byDialectic on Makina
ManagerDialectic
ContractsMakina, Concrete
Multisig3-of-5 (separate Safe)
Timelock48h on allocation changes
Upgrade GateConcrete 3-of-5 whitelist
03Allocated Across
Royco senior tranches
+ venues selected by Dialectic
04AccountabilityWho owns what
Royco ProtocolGovernance
The eight layers above.
DialecticAllocation Policy
Withdrawal queue, vault allocations and rebalancing.
MakinaVault Contracts (Internal)
Internal vault infrastructure, deployments and scripts for managing positions.
ConcreteVault Contracts (User Facing)
User facing vault infrastructure and upgrades.
CounterpartiesDownstream Venues
Royco senior tranches and venues selected by Dialectic. Each has its own security surface.
Every allocation is on-chain and public, so you can always see exactly where your deposit sits.
Get started

Deposit with confidence.

You've read the dossier. The contracts, the audits, the timelocks, the queue. From here, it's your call.

This page documents the full security posture of Royco, and may include features that are currently in pipeline for an exhaustive release. The timelocks, queue delays, multisig, and monitoring described above are reviewed frequently and may change to tighten security. Specific parameters and implementation details remain subject to change as protocol evolves.