> For the complete documentation index, see [llms.txt](https://docs.noon.capital/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.noon.capital/5.-the-security-framework/overview.md).

# Overview

Every protocol says it is safe. The difference is whether you can **check the claim**.

This section is <mark style="color:blue;">**Noon**</mark>'s security and trust framework laid out in **eight** pillars, each answering exactly one question, each with its own page, and each written so the claims are verifiable.

## <mark style="color:$primary;">The eight pillars</mark>

<figure><img src="https://3816918787-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FL26rQzcNmiUZrCXkxkjS%2Fuploads%2FTfe10O4R13o8hz9UQuJO%2FSecurityWheel.png?alt=media&amp;token=7a239fff-d4a0-451d-a00d-7d663f5fe430" alt=""><figcaption></figcaption></figure>

<table><thead><tr><th width="69">No</th><th width="185.54541015625">Pillar</th><th width="100">Type</th><th width="165.272705078125">The specific question it answers</th><th>Primary Focus &#x26; Verification Target</th></tr></thead><tbody><tr><td>1</td><td><a data-mention href="/5.-the-security-framework/trusted-custody.md">Trusted Custody</a></td><td><mark style="color:$success;background-color:$success;"><strong>Prevent</strong></mark></td><td>Where are <mark style="color:purple;"><strong>Noon</strong></mark>'s underlying reserves actually held?</td><td>Qualified off-chain custodians (Alpaca) and institutional MPC vaults (Fordefi, Safe).</td></tr><tr><td>2</td><td><a data-mention href="/5.-the-security-framework/smart-contract-security-and-audits.md">Smart Contract Security &amp; Audits</a></td><td><mark style="color:$success;background-color:$success;"><strong>Prevent</strong></mark></td><td>Are <mark style="color:purple;"><strong>Noon</strong></mark>'s smart contracts secure and bug-free?</td><td>Multi-firm pre-deployment audits (Quantstamp, Halborn, Hashlock, Sherlock, etc.).</td></tr><tr><td>3</td><td><a data-mention href="/5.-the-security-framework/world-class-operational-security.md">World-Class Operational Security</a></td><td><mark style="color:$success;background-color:$success;"><strong>Prevent</strong></mark></td><td>Are the human workflows and access keys secure?</td><td>SEAL Framework compliance, multi-sig administration, and key management policies.</td></tr><tr><td>4</td><td><a data-mention href="/5.-the-security-framework/disciplined-risk-management.md">Disciplined Risk Management</a></td><td><mark style="color:$success;background-color:$success;"><strong>Prevent</strong></mark></td><td>How is capital exposure allocated and bounded?</td><td>Strategy deployment caps, delta-neutral rebalancing rules, and credit vetting.</td></tr><tr><td>5</td><td><a data-mention href="/5.-the-security-framework/independent-collateral-verification.md">Independent Collateral Verification</a></td><td><mark style="color:violet;background-color:violet;"><strong>Prove</strong></mark></td><td>Can anyone verify protocol claims in real time?</td><td>On-chain Proof-of-Reserves, real-time collateral tracking, and transparent balances.</td></tr><tr><td>6</td><td><a data-mention href="/5.-the-security-framework/layered-insurance.md">Layered Insurance</a></td><td><mark style="color:yellow;background-color:$warning;"><strong>Protect</strong></mark></td><td>If a strategy or venue fails, what absorbs the loss?</td><td>The Noon Insurance Fund (daily volatility), Nexus Mutual (DeFi), and broker policies.</td></tr><tr><td>7</td><td><a data-mention href="/5.-the-security-framework/robust-governance.md">Robust Governance</a></td><td><mark style="color:yellow;background-color:$warning;"><strong>Protect</strong></mark></td><td>Who controls protocol changes, and how are they made?</td><td>48-hour public timelocks, separated administrative roles, and $sNOON governance votes.</td></tr><tr><td>8</td><td><a data-mention href="/5.-the-security-framework/thorough-incident-response-framework.md">Thorough Incident Response Framework</a></td><td><mark style="color:yellow;background-color:$warning;"><strong>Protect</strong></mark></td><td>What exact protocol happens when an anomaly occurs?</td><td>Bug bounty programs, emergency circuit breakers, and response execution flows.</td></tr></tbody></table>

## <mark style="color:$primary;">How the Pillars Work Together</mark>

The framework operates as a continuous, defense-in-depth safety engine:

#### 1. <mark style="color:$success;background-color:$success;">Prevent</mark> (Pillars 1–4)

*The first line of defense stops exploits and capital degradation before they happen.*

* Custody architectures isolate collateral from platform insolvency.
* Smart contract auditing and formal verification prevent code exploits.
* Operational security rules neutralize human error, phishing, and key compromise.
* Strict allocation bounds prevent over-concentration in any single yield vector.

#### 2. <mark style="color:violet;background-color:violet;">**Prove**</mark> (Pillar 5)

*Eliminating trust through continuous, public verification.*

* Real-time on-chain reporting and independent collateral attestations allow stakers, integrators, and security researchers to inspect total reserves, vault locations, and $USN supply 24/7/365.

#### 3. <mark style="color:yellow;background-color:$warning;">**Protect**</mark> (Pillars 6–8)

*Fail-safe systems that contain anomalies and compensate for black-swan events.*

* Layered insurance buffers absorb mark-to-market fluctuations and third-party protocol risks.
* Public timelocks and role separation prevent sudden, malicious protocol changes.
* A structured incident response protocol guarantees rapid containment if a security event is detected.

## <mark style="color:$primary;">For Security Researchers & Whitehats</mark>

Found a potential vulnerability or security flaw? Noon maintains an active bug bounty program and rapid-response triage system:

* 🛡️ Submit a Report: [Thorough Incident Response Framework](/5.-the-security-framework/thorough-incident-response-framework.md)
* 📄 Verify Active Deployments: [Contract Addresses & Oracles](/6.-resources/contract-addresses-and-oracles.md)
