Regulated-first, from the core
Security and compliance aren’t features bolted on afterwards — they’re embedded in Haidrun’s architecture and data model. Private deployment inside your own perimeter, bank-grade key security, and controls designed for the world’s regulatory frameworks.
Every layer hardened, from perimeter to key
Haidrun secures the whole stack in concentric layers — each one independent, each one auditable — with your most sensitive material, the signing keys, held in hardware at the centre.
Perimeter & data sovereignty
Deployed inside your own security perimeter — private cloud or on-premises. Your network, your data, your rules; no external blockchain dependencies.
Network security
TLS 1.3 with mutual TLS for every API client, a WAF with the OWASP ruleset, DDoS protection, private subnets, and an isolated HSM network segment.
Identity & access
Role-based access control, multi-factor authentication for administrative access, least privilege, and just-in-time elevation.
Data protection
AES-256 encryption at rest, TLS 1.3 in transit, field-level encryption for PII, and automatic key rotation.
HSM key core
All signing keys reside in FIPS 140-3 Level 3 hardware security modules. Private keys never leave the hardware boundary.
Built into the protocol, not the application
HSM-first signing
All signing keys reside in FIPS 140-3 Level 3 hardware security modules. Private keys never leave the hardware boundary, with automatic key rotation and per-client key isolation.
Zero-trust transport
TLS 1.3 with mutual TLS for all API clients, a WAF with the OWASP ruleset, DDoS protection, private subnets, and an isolated HSM network segment.
Encrypted end to end
AES-256 encryption at rest, TLS 1.3 in transit, and field-level encryption for personal data — with automated key rotation throughout.
Least privilege by default
Role-based access control, multi-factor authentication for administrative access, least-privilege permissions, and just-in-time elevation for sensitive operations.
Provable and immutable
An immutable audit trail with 7-year retention, real-time alerting on security events, and regular third-party penetration testing.
Engineered to stay up
Engineered for 99.99% availability with a sub-5-minute recovery-time objective, multi-availability-zone deployment by default, and exactly-once event processing.
Requirements embedded in the core
Regulatory requirements live in the core data model and workflows rather than being implemented per application. Haidrun is built for compatibility with the frameworks that govern regulated digital money.
MiCA
Own-funds and reserve requirements, on-chain reserve attestation, HSM key custody with a full audit trail, treasury controls, a built-in complaints workflow (Art. 71), and tiered client identification.
US GENIUS Act
1:1 reserve backing with real-time tracking, permitted reserve assets, monthly attestation, redemption at par, and reserve segregation.
FATF
Real-time AML transaction monitoring, risk-based limits, sanctions screening (EU, UN, OFAC), case management with SAR generation, and dynamic risk scoring with ongoing due diligence.
VARA and beyond
Engineered to support additional frameworks as you expand into new markets, with the same core controls applied consistently across jurisdictions.
Compliance across the full client lifecycle
Identity, screening and monitoring are native to the platform — applied continuously from onboarding through every transaction.
Verify
Document verification with liveness checks and beneficial-owner verification for corporate clients (KYB), with tiered client identification.
Screen
Sanctions and PEP screening against EU, UN and OFAC lists, with risk-based classification at onboarding.
Monitor
Real-time AML transaction monitoring with anomaly detection, risk-based limits, and dynamic risk scoring with ongoing due diligence.
Act
Case management with SAR generation and enhanced-due-diligence triggers — every step recorded in an audit-ready trail.
Supply you can prove, on-chain
Because the engine is the authoritative ledger for supply, total stablecoin supply is always derivable from chain state — so reserves reconcile deterministically, without off-chain assumptions.
Independently tested, continuously audited
Third-party penetration testing
Regular independent penetration tests, with findings tracked to remediation.
Immutable audit trail
Every privileged action and transaction recorded, with 7-year retention and real-time alerting.
Security standards
Controls aligned to the principles of leading information-security standards, including ISO 27001 and SOC 2.
Built for the world’s regulators
Talk to our compliance team, or request a demo.