Skip to main contentThe Transparency Gap: A $12.3B Blind Spot in Tokenized Asset InfrastructureRead the report
Chronicle

Chronicle / Security & Compliance

Security and compliance,
proven over time.

Security and compliance are embedded into how Chronicle engineers, operates, and maintains its data infrastructure and network. Our approach combines internationally recognized standards, independent audits, ongoing security programs, and an established network production track record since 2017.

Explore security & compliance ↓
  • Certification ISO/IEC 27001:2022 Certified
  • Assessment Penetration testing Completed
  • Audit Smart contract audits ABDK · Cantina · ChainSecurity
  • Program Bug bounty program Live · Up to $400K · Cantina

01 / Security standards & assessments

Certifications, audits and security programs.

Chronicle’s security posture and controls are regularly assessed by independent third parties across certification and attestation bodies as well as audit and security teams.

ISO/IEC 27001:2022

Chronicle is certified to ISO/IEC 27001:2022, providing assurance that Chronicle has implemented an Information Security Management System (ISMS) covering the design, development, operation and support of Chronicle’s data services end to end.

Certificate and audit report available on request

Penetration testing

Chronicle regularly commissions third-party penetration testing of relevant systems.

Attestation letter available on request

Smart contract audits

Chronicle smart contracts have been audited independently by leading auditor firms, including ABDK, Cantina, and ChainSecurity.

Four public audit reports in Documentation below.

Bug bounty program

Chronicle maintains an ongoing bug bounty program through Cantina.

Live since May 2024 · Rewards up to $400K

02 / Production track record

Proven in production for 8+ years.

Built for operational resilience and long-term reliability.

2017 First oracle on Ethereum

Selected integrations

  • Centrifuge logo
  • Grove logo
  • Janus Henderson logo
  • M0 logo
  • MoonPay logo
  • Morpho logo
  • Securitize logo
  • Sky logo
  • Steakhouse Financial logo
  • Superstate logo

03 / Security & compliance documentation

Security & compliance documentation.

Supporting documentation is available for review. Certain materials are provided on request.

ISO/IEC 27001:2022

What is ISO/IEC 27001:2022?

ISO/IEC 27001:2022 is a widely recognized international standard that defines requirements for an information security management system (ISMS).

Chronicle

Chronicle is certified to ISO/IEC 27001:2022 for the full scope of design, development, operation, and support of Chronicle’s oracle services, including the ingestion, processing, validation, cryptographic signing, and publication of price-feed and Proof of Asset data, as well as associated APIs, dashboards, and supporting cloud infrastructure; certification valid as of 31 July 2026, subject to annual audits.

Penetration testing

What is a penetration test?

A penetration test is a controlled security assessment in which testers attempt to identify and exploit vulnerabilities in an application, system, or network.

Chronicle

Chronicle regularly commissions third-party penetration testing of relevant systems. Reports and attestation letters are available on request.

Smart contract audits

What is a smart contract audit?

A smart contract audit is an independent review of smart contract code intended to identify security vulnerabilities, implementation issues, and other risks.

Chronicle

Chronicle has undergone independent security reviews by ABDK, Cantina, and ChainSecurity.

Bug bounty program

What is a bug bounty program?

A bug bounty program rewards security researchers for identifying and responsibly reporting qualifying vulnerabilities in live code.

Chronicle

Chronicle maintains an ongoing bug bounty program through Cantina.

Contractual documentation

  • Data Processing Agreement (DPA) Sets out the terms for processing and protecting personal data where applicable.
    Request access →
  • Service Level Agreement (SLA) Sets out applicable service commitments and performance terms for relevant Chronicle services.
    Request access →

Supporting documentation

Request supporting documentation.

Access the materials relevant to security review, vendor due diligence, or institutional onboarding.