Skip to main content

Security

VlowCore makes settlement predictable, scalable and controllable.

Organisations buy more than an API. They buy a settlement architecture that keeps assets and transaction states correct, traceable and reportable within the agreed scope. The blockchain does not see the intermediate transactions. One hundred million state updates between two parties can become only two on-chain transactions, cryptographically secured from escrow to final settlement.


Multiple independent nodes

Multi-node validation.

Every transaction is validated by multiple independent nodes, with at least two active nodes. One node cannot execute a transaction by itself. The setup is trustless: no single party, including a customer running its own node, determines the ledger state alone.

Distributed key generation

The key never lives on one node.

The key that signs transactions is never fully present on a single node. It is generated in a distributed way, so no node can reconstruct the full key. The practical outcome: a customer running its own node cannot manipulate its own ledger state. Attempts to falsify state are detectable within the network and can be removed.


Cross-chain finality

Under one second, with security guarantees intact.

Each node checks the transaction itself. Cross-chain finality is already guaranteed with two nodes. The hard technical distinction is the speed of the distributed key process: finality under one second, while keeping the security guarantees intact. Open on one chain, close on another, without security concessions.

No single point of failure

VlowCore does not take custody of assets.

Collateral remains in the on-chain escrow. If VlowCore is unavailable, each party can claim the last signed state itself. There is no central custody position where assets are trapped and no single point that can bring down the entire system.


Independently audited

Existing audit scope.

Existing audit

So far, the off-chain execution layer and multi-chain anchoring have been independently audited by Cure53. The anchoring uses the same protocol homogeneously across chains: only the interface changes, while the core security layer remains the same within the existing audit scope.

New modules

The integration layer and Stablecoin & RWA Settlement Layer sit outside the existing audit scope. Both receive their own external audit before they are positioned as production components.

The same applies to the configurable capabilities: the Fee Engine, Transaction Profiles, Policy Zones and Jurisdictional Zones, and the optional Compliance & Policy Module. These components do not automatically fall under the existing Cure53 audit scope.

The existing audit covers the core. The integration layer and the Stablecoin & RWA Settlement Layer receive their own audit track after development.

Compliance & Policy Module · optional

Controls that run inside the customer environment.

The customer configures the rules for its own environment. The optional Compliance & Policy Module runs the controls within that environment and records the outcomes in a verifiable way. That lets the customer show auditors, supervisors or other authorised parties how its own policy was applied technically.


Talk to our team.

Discuss the architecture, sandbox route or pilot fit.