Security built like a private bank.
Protecting over $200 million in physical assets demands military-grade custody, threshold cryptography, and institutional segregation of duties. Plainly explained, without corporate jargon.
Multi-Party Computation (MPC) Wallets
Every member account is backed by an institutional MPC wallet architecture. Rather than relying on a vulnerable single private key, your key authority is mathematically partitioned across your personal device, a hardened cloud HSM enclave, and an air-gapped recovery vault.
FIDO2 Passkeys & Hardware Security Keys
Loop'D supports modern biometric passkeys (Apple Touch ID, Face ID, Windows Hello) alongside physical YubiKeys. Passkeys eliminate phishing and credential stuffing attacks by design.
Withdrawal Allowlists & 24-Hour Cool-Off
To safeguard member balances against session hijacking, all outbound fiat and crypto withdrawal destinations must be explicitly allowlisted.
2-of-3 Multi-Party Operator Approvals
All platform-wide minting, token burning, vault releases, and large treasury transfers require 2-of-3 independent digital signatures from authorized officers.
Immutable Append-Only Audit Log
Every operator action, KYC approval, vault intake scan, and parameter adjustment is cryptographically chained to an append-only audit log.
Syndicated Lloyd's of London Insurance
All physical assets resting in Loop'D facilities are insured at 100% of Fair Market Value under commercial policies underwritten by Lloyd's of London syndicates.
Institutional Compliance Posture
How on-chain transfer restrictions enforce statutory identity and jurisdiction rules.
ERC-3643 Permissioned Token Standard
Transfer rules execute on-chain. Both buyer and seller must hold verified identity claims (ONCHAINID) for the asset's tier and jurisdiction before a trade can settle.
Real-Time Sanctions Screening
Automated continuous watchlist matching against SECO (Switzerland), OFAC (US), EU, and UN consolidated lists. Suspicious activities report immediately to MROS.
Quarterly Penetration Audits
Smart contracts and infrastructure undergo recurring adversarial penetration testing by top-tier independent security firms including Trail of Bits and Kudelski Security.
Swiss Banking Secrecy Standards
Headquartered in Zurich, all member identity data is encrypted and housed in Swiss Tier-IV datacenters under strict FADP and GDPR compliance.
Responsible Disclosure & Bug Bounty
We welcome collaboration with the global cybersecurity community. Our security desk offers cash bounty rewards for responsibly disclosed vulnerabilities.
Security Hall of Fame & Bug Bounty Recipients
Recognizing independent researchers who helped harden Loop'D infrastructure.
| Researcher | Affiliation | Research Area | Year | Reward Tier |
|---|---|---|---|---|
| Dr. Fabian Vogt | Independent Researcher (Munich) | ERC-3643 Claim Verification Logic | 2026 | Critical ($25,000) |
| Sylvie Mounier | Trail of Bits Alumni | MPC Key Shard Timeout Re-entrancy | 2025 | High ($15,000) |
| Kasper Lind | KTH Royal Institute of Technology | Merkle Tree Sum Bound Invariant | 2025 | High ($10,000) |
| Alexander Gross | ConsenSys Diligence | Dispute SLA Resolution State Machine | 2024 | Medium ($5,000) |