> For the complete documentation index, see [llms.txt](https://re0-2.gitbook.io/re-docs-v2/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://re0-2.gitbook.io/re-docs-v2/documentation/protocol/security-and-audits.md).

# Security and Audits

Security is the cornerstone of Re Protocol's design, ensuring participant trust and platform resilience. The protocol combines third-party audits, strict access controls, oracle guardrails, and daily custody/reserve attestations.

#### Independent Audits <a href="#independent-audits" id="independent-audits"></a>

The Re Protocol undergoes regular third-party audits of its smart contracts and infrastructure.

* **Certora** (Latest audit: Sept. 26, 2025): [certora.com/reports/re-core](https://www.certora.com/reports/re-core)
* **Previous audits (Hacken):** [hacken.io/audits/re-protocol/](https://hacken.io/audits/re-protocol/)

#### Oracle and Reserve Assurance <a href="#oracle-and-reserve-assurance" id="oracle-and-reserve-assurance"></a>

* reUSD/reUSDe price feeds are updated daily.
* A daily change guardrail is enforced on reUSD pricing—large moves above the configured threshold are rejected.
* Off-chain bank balances are verified daily by The Network Firm and published via Chainlink.
* The Network Firm also verifies ownership and balances of protocol custody wallets.

#### Emergency Mechanisms <a href="#emergency-mechanisms" id="emergency-mechanisms"></a>

* **Pause functionality:** The protocol can immediately halt all transactions during emergencies.
* **Recovery wallets:** Each ICL has a designated recovery wallet.

#### Secure Infrastructure <a href="#secure-infrastructure" id="secure-infrastructure"></a>

* **MPC wallets** for critical operations prevent single-party control.
* **Daily Fireblocks sweeps** move idle capital from each ICL into custody vaults.
* **Surplus Note Registry** records notarized agreements and emits NoteDraw/NoteRepay events.
* **Full on-chain transparency** — all transactions recorded and independently verifiable.

#### Compliance <a href="#compliance" id="compliance"></a>

* KYC/AML is required because protocol capital is deployed with a licensed reinsurance partner regulated by the Cayman Islands Monetary Authority (CIMA).
* KYC/AML powered by SumSub and Chainalysis.
* Continuous monitoring of wallet activities and risk profiles.

#### Participant Assurance <a href="#participant-assurance" id="participant-assurance"></a>

* Real-time reporting via the [transparency dashboard](https://app.re.xyz/transparency).
* The protocol is exploring additional custodial and operational risk insurance partnerships.
