SettleMint

Compliance and security

Choose the right DALP compliance and security guide for public-chain privacy, pre-launch review, source verification, the layered security model, and the per-asset compliance modules that enforce regulated operations.

Use this section to pick the right DALP compliance or security page before a regulated programme goes live. Start with privacy when you need to know what becomes visible on EVM networks. Start with security when you need the control model. Start with compliance modules when you need per-asset transfer rules. Start with source verification when you need deployment and audit evidence.

This is a review hub, not a legal opinion. DALP documents the platform controls and evidence surfaces. Your organisation still owns policy choices, jurisdictional approval, custody arrangements, recovery targets, and operating procedures.

For SettleMint-hosted or managed deployments, procurement and security reviewers can also use the SettleMint Trust Center for security questionnaires, compliance frameworks, and governance policies. Operators can check the SettleMint status page for published platform availability and incident history.

Rendering diagram...

The pages below cover documented platform behaviour. They do not commit to regulator-specific approval, custody terms, SLA terms, or non-EVM deployment support. Treat those as organisation-specific controls unless a detail page states the DALP behaviour explicitly.

What DALP covers

DALP separates compliance and security review into four surfaces: public-chain privacy patterns, the layered security model, EVM compliance modules, and deployment evidence that lets an auditor reproduce what was deployed and what happened after.

AreaDALP definesYour organisation defines
PrivacyWhat stays off-chain by default, the public-chain visibility model, and supported routing patternsNetwork selection, RPC and routing decisions, legal review of public disclosure, and pre-launch approval ownership
SecurityIdentity, authentication, authorization, wallet verification, compliance, custody split, and routingOperator role assignment, policy approvals, custody arrangements, secret rotation, and incident response
CompliancePer-asset compliance modules for identity, geography, supply, approvals, collateral, and timelockModule configuration, policy thresholds, jurisdictional approvals, and review evidence
Audit evidenceSource verification, deployment auditability, indexed events, and operating-record retention modelRetention policy, regulator-specific reporting, control testing, and escalation procedures
ExclusionsDocumented platform behaviour and supported review surfacesLegal opinions, SLA commitments, custody arrangements, and bridge or cross-chain operating decisions

Pick the right path

If you need to...Start hereThen read
Decide if a regulated asset can use a public chainPublic chain privacyPublic EVM visibility model for the chain-visible data set
Inspect what is visible on EVM networksPublic EVM visibility modelTransaction ordering privacy for pre-confirmation exposure
Compare privacy architecture patternsPrivacy architecture patternsPre-launch privacy review before a regulated asset goes live
Trace deployed contracts and operating evidenceSource verification and deployment auditabilityThe deployment, bytecode, upgrade, and indexed-event sections inside the same page
Review the layered security control modelSecurity overviewAuthentication, Authorization, Wallet verification
Inspect identity and compliance evidenceIdentity and compliance control modelCompliance and custody split
Review per-asset compliance modulesAsset policyAsset policy concept, compliance modules overview, and the identity, country, supply, approvals, collateral, and timelock module pages
Review cross-chain and stablecoin trust boundariesBridge and cross-chain securityStablecoin operating responsibilities

Review model

DALP separates compliance and security review into four surfaces:

  • Privacy review answers what becomes visible on EVM networks, when public-chain visibility is acceptable, and which controls belong in the deployment architecture.
  • Security review inspects the layered control model: authentication, authorization, wallet verification, identity and compliance enforcement, custody split, and routing decisions.
  • Compliance module review inspects the per-asset rules DALP enforces on EVM for identity, geography, supply, approvals, collateral, and holding periods.
  • Audit evidence review traces deployed contracts, upgrade history, indexed events, and operating records that document what was deployed and what happened after.

Most regulated programmes go through all four. Use the privacy pages first when the network is undecided, the security pages when reviewing the platform controls, the compliance module pages when configuring per-asset policy, and the source verification page when packaging audit evidence.

Privacy

Source verification and audit evidence

Security overview

Compliance modules

On this page