Reports & Artifacts

Independent verification. Every day.

Daily third-party reserve attestations from Accountable, served via public API. Operational-controls reviews on top. Plus the full document pack — SOC 2, pen-test plan, AML policy, DPA, and smart-contract audit reports — available under NDA in one business day.

Document pack

Request the full pack

SOC 2 status, audit reports, pen-test plan, AML policy, DPA. One business day turnaround under signed NDA. Cite artifact IDs in your request to scope quickly.

compliance@flo.finance

Daily Attestation Reports

Public reports. Every report is produced independently by Accountable and served via public API the same day. No NDA, no waitlist.

Report DatePeriodTypeAuditorDownload
May 8, 2026May 8, 2026 · 00:00 UTCReserve AttestationAccountableHow to access
May 7, 2026May 7, 2026 · 00:00 UTCReserve AttestationAccountableHow to access
May 6, 2026May 6, 2026 · 00:00 UTCReserve AttestationAccountableHow to access
May 5, 2026May 5, 2026 · 00:00 UTCReserve AttestationAccountableHow to access
May 4, 2026May 4, 2026 · 00:00 UTCReserve AttestationAccountableHow to access
May 3, 2026May 3, 2026 · 00:00 UTCReserve AttestationAccountableHow to access

Our Independent Verifier

One specialised third-party firm across the attestation areas below. SOC 2 Type II is run separately by an independent SOC 2 auditor.

Accountable

Sole attestor

Specialised independent verification provider for tokenized asset issuers. Performs the daily reserve attestation, the cryptographic audit of the Merkle-tree proof of reserves, and the periodic operational-controls review. Attestation data is served publicly via the Accountable API.

Engagement type: Agreed-Upon Procedures (AUP) and attestation engagements. Scope and limitations disclosed on the face of each report.

Areas of Attestation

The scope covered by the independent verifier across the full trust stack.

1

Reserve Attestation

Independent verification that total on-chain Flo Finance token supply is fully backed 1:1 by the underlying assets held at institutional custodians. Covers stocks, treasury yield, commodities, FX, ETFs, fixed income, and private credit across every supported chain.

2

Proof of Reserves

Cryptographic audit of the Merkle-tree-based proof of reserves system. Verifies that the on-chain root hash correctly represents all liabilities and that none are omitted from the tree.

3

Controls Review

Assessment of operational controls including access management, key custody, multi-sig governance, incident response readiness, and change management.

Compliance & Data

Under NDA

SOC 2 status, pen-test plan, AML / sanctions policy, DPA template.

C-01Flo Finance security

SOC 2 Type II report (or bridge letter)

SOC 2 Type II is in progress, Year-1 observation window under way. Bridge letter and final report available on completion.

C-02Flo Finance security

Penetration test plan

Scope, scheduled testing windows, and chosen firm for initial and ongoing third-party pen tests across application and infrastructure. Executive summaries shareable post-test under NDA.

C-03Flo Finance compliance

AML & sanctions policy

AML program, AML officer structure, OFAC / EU / UK / UN sanctions screening methodology, and contract-level denylist enforcement.

D-01Flo Finance legal

Data Processing Agreement (template)

Standard DPA for partners whose distribution reaches EU or UK data subjects. SCCs included where needed for onward transfer.

Smart Contract

Under NDA for drafts; audit reports public

Architecture documentation and the four independent audit reports.

S-01Flo Finance engineering

Smart contract architecture

Architecture document covering mint controller, redeem controller, position ledger, bridge adapter, and the sanctions-enforcement hooks. Published diagrams and state machines.

S-02Flo Finance engineering

Smart contract audit reports (4×)

Independent audit reports from Sherlock, Halborn, Cantina, and Cyfrin. Issues categorised by severity, remediation status, and retest confirmation.

Reserves

Public

Attestations are public. Request the bundle or browse the daily table above.

A-01Flo Finance

Most recent proof-of-reserve attestation

Latest daily attestation, served via the public Accountable API. Total tokens per series, total underlying by CUSIP, 1:1 reconciliation, independence statement.

A-02Flo Finance

Historical attestations (trailing 12 months)

Trailing 365 days of daily attestations with auditor cover letters. Queryable via the Accountable API or downloadable as a date-range bundle.

How to Request

Artifacts under NDA are shared on a named-addressee basis. The process is designed to take one business day.

1

Email compliance@flo.finance

Cite artifact IDs (C-01, S-02, etc). Include the counterparty entity and the signatory who will execute the NDA.

2

Mutual NDA

We send our standard mutual NDA. Turnaround is typically a few hours. We accept reasonable markups.

3

Receive materials

Artifacts delivered via secure share to named recipients.

4

Follow-up call

Optional review call with our security leads to walk through anything your team flags.

Daily Cadence

Daily attestations, not quarterly

Reserves are attested every day by an independent third party and served via public API — no NDA, no waitlist, no PDF gate.