Security & Compliance Resources

41 articles

Configure your own verifier network from 55+ DVN providers. Immutable contracts, audit trails you own, and compliance controls built into the standard. Security frameworks, audit documentation, and compliance guides for regulated issuers.

All Security & Compliance resources

FAQ

How is LayerZero secured?

LayerZero's security model rests on three principles: immutability, configurability, and independence. Contracts are immutable and non-upgradeable — once deployed, no party (including LayerZero) can modify them. Every application chooses its own security stack, selecting from 55+ Decentralized Verifier Network (DVN) providers and setting confirmation thresholds per lane. No single third party can compromise a deployment or halt cross-chain activity.

What is a DVN (Decentralized Verifier Network)?

A DVN is an independent network that verifies cross-chain messages before they're delivered on the destination chain. Over 55 independent providers operate DVNs, from crypto-native firms to enterprises like Fidelity Center for Applied Technology, Google Cloud, and Deutsche Telekom MMS. Every application selects which DVNs verify its messages and at what confirmation thresholds. Issuers with strict data-sovereignty rules can run their own DVN on-premises.

Can issuers customize their own security stack?

Yes. That's a defining feature of LayerZero. Every application configures its own security model. That includes which DVN providers verify its transactions, how many DVNs are required, the confirmation depth per source chain, and which Executor delivers messages. If none of the 55+ existing DVNs meet a specific requirement, an issuer can run its own DVN (as Deutsche Telekom MMS does for GDPR compliance). Security posture is a first-class configuration, not a fixed vendor decision.

How does LayerZero support regulatory compliance?

LayerZero gives issuers the controls they need to meet their own regulatory obligations. Controls include allow-lists and deny-lists for AML/KYC enforcement. Per-chain rate limits. Pause and lock functions the issuer executes directly. And a complete cross-chain audit trail. Contracts are immutable and open-source — regulators can review them without an NDA. The issuer — not LayerZero, not any external multisig — controls the deployment end to end, which is what makes examiner verification possible.

Can regulators verify and audit LayerZero transactions?

Yes. Every LayerZero message is public and independently verifiable through LayerZero Scan. Because contracts are immutable and open-source, examiners can review the code directly. They can confirm which DVN providers validated each transaction and verify how compliance rules are enforced across every chain — with no dependency on a vendor to produce the data.

Curated Articles