Trust Center
11 things we promise + prove
We earn trust by being explicit about what we are + what we are not. No marketing words — just the 11 invariants Klaro enforces in code, in audits, and in operations.
Honest labels
CurrentEvery Klaro surface tags itself as live testnet, simulated, access-gated, partner-pending, or mainnet-only. We never let UI pretend to be more than it is.
No PII on-chain
RequiredRelease rule: only required hashes and wallet references may reach Arc. Real compliance data handling must be verified before launch.
Open source contracts
RequiredSolidity contracts are present in the repository for review. Deployment and independent audit evidence are not yet published.
Deterministic finality
RequiredTarget live behavior: verified Arc settlement can anchor a receipt. Current receipt screens clearly identify simulated previews.
Tested like money is real
RequiredRequired before live funds: passing contract tests, security analysis, coverage evidence, and independent review of money-moving paths.
Operator audit log
RequiredDemo disputes expose recorded decisions. Live on-chain audit stamping must be enabled and verified before funds can move.
Klaro is not a bank
RequiredWe don't hold customer fiat. We don't originate loans. We don't issue credit. Klaro is software for stablecoin-native vendor flows.
Engineering principles
RequiredEvery pull request is reviewed against a fixed set of principles — no overclaiming, no PII on chain, money flows modelled as explicit state machines, honest status labelling on every surface.
External audits before mainnet
RequiredSlither, Mythril, and Echidna pass on the published contract set before any mainnet promotion. Halmos formal verification covers the release, mint, and dispute-decision paths. Audit reports are published.
Bug bounty (planned)
RequiredImmunefi program launches at mainnet. Critical USDC-custody vulnerabilities qualify for up to $100k. Coordinated disclosure 90-day clock.
Uptime + status
RequiredBetterStack-powered status.klaro.so. 99.9% uptime objective. PagerDuty 24/7 on-call for severity-1 incidents.
More questions?
Read the full disclosures, privacy policy, and security.txt. Email trust@klaro.so for anything else.