# Security

### Status: Mainnet Beta

Security is the absolute number one priority at Derivio. Multiple security audits were conducted by third-party audit firms, and bug bounties are available for white-hat hackers and the broader security community.&#x20;

Derivio is currently in public beta. Please do your own research and use Derivio at your own risk.

### Bug Bounty

If you find a bug or vulnerability in the smart contracts or website, please report to <security@derivio.xyz>.

* Critical vulnerability: Up to $300,000
* High vulnerability: Up to $25,000
* Medium or lower vulnerability: Up to $10,000

We are in the process of setting up a public bug bounty program with a third-party trusted platform. Please stay tuned.&#x20;

### Oracle

Derivio uses Pyth Network as the primary price oracle, which provides decentralized, real-time aggregated prices from Pythnet. For more information, see <https://pyth.network>.

Derivio allows the following backup oracle if Pyth is unavailable: weighted average of centralized exchange prices.

### **Audits**

June 2023: OtterSec audit

{% file src="<https://321027494-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIIIrSj6j1yGgDveIXYRQ%2Fuploads%2F4965lKusnmGVCpfVV67I%2F2023_06_Ottersec_Derivio_audit_final.pdf?alt=media&token=e7a9ecd7-394d-45c6-b6e7-a5b9ca601e70>" %}

July 2023: Halborn audit

{% file src="<https://321027494-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIIIrSj6j1yGgDveIXYRQ%2Fuploads%2FN5PTX2IG4kldvtJrnelF%2F2023_07_Halborn_Derivio_audit_final.pdf?alt=media&token=fd76dc97-3ed3-49a0-b783-01ffdf4c09c0>" %}
