Security & Transparency
Built on trust.
Verified at every step.
Every dollar invested, every head of cattle recorded, and every payout distributed on Cattle Coin AI is protected by cryptographic verification, independent audits, and institutional-grade infrastructure.
On-Chain Verification
Cattle listings, ownership records, and payout events are anchored to an immutable ledger via IPFS content hashes and evidence attestations — independently verifiable by anyone.
Escrow-Backed Wallets
Investor funds are held in segregated CattleCoin wallets and never commingled with operating capital. Disbursements only occur after admin-approved milestone events.
Admin Review Gate
Every cattle listing passes a multi-step review: documentation check, insurance verification, evidence hash validation, and manual approval before going live to investors.
Auth & Access Control
JWT-based sessions with short expiry, email OTP as a second factor, and role-based access (farmer / investor / admin) enforced at every API endpoint.
Document Integrity
Uploaded documents (vet records, insurance, titles) are SHA-256 hashed at upload and stored in S3 with server-side encryption. The hash is recorded on-chain and cannot be silently swapped.
Transparent Reporting
Farmers post dated herd updates visible to all shareholders. Rating history, payout logs, and listing timelines are permanently accessible to investors in their dashboard.
Security Posture
What's in place — and what's coming
We publish our security roadmap openly. The table below reflects the current state of the platform and planned controls as we scale from MVP to full production.
| Control | Status | Notes |
|---|---|---|
| JWT authentication | Live | HS256, 60-min expiry, refresh tokens |
| Email OTP (2FA) | Live | 6-digit code, 10-min TTL |
| Role-based access control | Live | Farmer / Investor / Admin scopes |
| Document SHA-256 hashing | Live | Stored on listing at upload time |
| IPFS evidence anchoring | Live | CID stored per listing |
| Admin listing review gate | Live | Listings cannot go live without approval |
| S3 server-side encryption | In Progress | AES-256 SSE-S3 being enabled |
| Third-party smart contract audit | Planned Q3 2026 | Engagement underway |
| SOC 2 Type I | Roadmap | Targeted before Series A |
| Bug bounty program | Roadmap | Launching with audit completion |
Questions about security?
Reach our security team directly — we respond within one business day.
Contact Security Team