The Digital Asset Risk & Compliance Standard

The Trust
Standard for
Digital Assets

A purpose-built opsec standard with a continuous monitoring platform to keep you protected. When your GitHub, cloud, or multisig drifts, you know instantly. When a new attack vector emerges, your controls update automatically.

One standard, one platform, keeping you compliant in real time.

12
Audit Domains Across the Stack
3
Certification Tiers
240+
Control Requirements Defined

The industry is losing billions.
Not from code,
but from operations.

$4.8B+
Funds stolen · 2024 to 2025
Through operational failures, social engineering, and key compromise.
$2.5B+
Lazarus Group · 2024 to 2026
Attributed to North Korea's Lazarus Group across 2024–2025, targeting exchanges, protocols, and funds through social engineering, supply chain attacks, and infrastructure compromise.
Opsec vs. code exploits
More funds are lost to operational failures than smart contract exploits. Code gets audited. Teams, keys, and operational processes do not.

A standard and a platform. Continuous by design.

DARC combines two approaches: a standard that defines what operational security looks like for digital asset teams, and a platform that keeps you measured against it every day. The standard sets the bar. The platform makes sure you stay above it.

Continuous monitoring

DARC is not a one-time check. Through the platform, your code repository, cloud infra, DNS, multisig wallets, and more, are monitored every day. Continuous by default, wherever possible.

Always-current controls

When the threat landscape shifts, controls are added or updated for every subscriber. We see incidents across the industry firsthand. That intelligence becomes a control update before most teams have even heard of the attack.

Subscription-based · monitored daily · updated as threats evolve

The weakest link is usually deep in the team.

Every DARC plan includes an employee portal. Security travels down to every team member, with their own controls and scope-specific training.

Onboarding a new employee? Get them to your security baseline from day one — controls assigned, training queued, contracts ready to sign.

Personal control view

Each team member sees their own controls and exactly what's expected of them. No more buried, stagnant security policies that nobody reads.

Trainings

Modules on the most common crypto-native attack vectors: recruiting scams, wallet drainers, clipboard swaps, fake meeting links.

Contracts

Ready-to-sign templates drafted to satisfy DARC controls: NDAs, security policies, acceptable use, and key holder agreements.

Co-built with SEAL

The Security Alliance

SEAL is one of the leading security organizations in digital assets. Their emergency response team has protected billions in on-chain assets and responded to many of the industry's largest security incidents.

Every control in the DARC framework was written and reviewed by Wonderland and SEAL practitioners with hands-on incident experience.

12 Domains Across the Stack

GV Governance & Compliance
DARC1

Named security owner, plain-language policy, asset inventory, secure onboarding & offboarding, NDAs, social engineering awareness.

DARC2

Risk register, data classification, security metrics, regulatory awareness, threat intelligence, domain-specific ownership, change management.

KM Key Management
DARC1

Keys encrypted at rest, tested backup recovery, 2FA on all key systems, no two keys on same device, written Key Compromise Protocol.

DARC2

Formal key lifecycle docs, geographic backup distribution, rotation schedules, tamper-evident storage, background checks, spend verification.

MS Multisig Governance
DARC1

Multisig on all fund wallets, hardware wallets required, independent signer verification per transaction, no single-entity threshold control.

DARC2

Risk classification, signer training & assessment, transaction simulation, emergency playbooks, monitoring, 12-hour quorum reachability.

AC Access Control
DARC1

MFA everywhere (no SMS), password manager, full-disk encryption, auto-lock, 24-hour offboarding, no shared credentials.

DARC2

Hardware security keys for critical accounts, least privilege, quarterly access reviews, phishing simulations, malware protection, MDM.

SD Secure Development
DARC1

Branch protection, signed commits, automated secret scanning, dependency pinning, no production credentials in dev environments.

DARC2

Multi-party code review, SAST in CI/CD, isolated dev environments, dedicated secrets management, staging before production.

SC Smart Contract Ops
DARC1

One external audit before mainnet, all critical findings resolved, verified deployed bytecode matches audited source, privileged functions documented.

DARC2

Two+ audits for core contracts, timelocks on privileged ops, pause mechanism, bug bounty, re-audit triggers, remediation tracking.

IM Incident Management
DARC1

Named incident owner, emergency contact list, written response plan (contain, scope, notify), incident channel known to all.

DARC2

IR team with defined roles, per-scenario playbooks, 24/7 monitoring with paging, tamper-evident logs, post-incident reviews.

TM Treasury Management
DARC1

Multisig treasury wallets, company funds segregated from user funds, test transactions, basic spend approval policies.

DARC2

Custody model documented, risk classification per wallet, fund allocation limits, video-call verification for large transfers, monitoring.

CM On-Chain Monitoring
DARC1

Monitor all treasury/multisig wallets, alerts on large transfers & signer changes, named alert reviewer with defined cadence.

DARC2

Smart contract monitoring, credential leak monitoring, DeFi attack pattern detection, severity-based escalation, on-call schedule.

SY Supply Chain Security
DARC1

Inventory of critical dependencies, official sources only, version pinning with lockfiles, automated vulnerability scanning in CI/CD.

DARC2

Vendor risk assessments, oracle architecture documented, RPC redundancy (2+ providers), SBOM, frontend build integrity verification.

FD Frontend & DNS Security
DARC1

Domain inventory, MFA on all registrars, auto-renewal, SPF/DKIM/DMARC configured, TLS certificate expiration tracking.

DARC2

DNSSEC, CAA records, registry locks, CT log monitoring, CSP headers, SRI for externally-loaded scripts on signing pages.

PS Physical Security
DARC1

Hardware wallets in locked storage, clear desk policy, visitor policy for signing areas, verified hardware supply chain.

DARC2

Physical access control with logging, cameras in secure areas, environmental protections, designated key ceremony areas.

View Full Standard

Three Levels of Protection

Certificate · DARC1
DARC Core
$1,000 / mo
$12,000 billed annually — save $3,000
DARC1 certification
88-control compliance framework
20 user seats
Team portal with role-based views
Real-time control monitoring
DARC Public Registry listing
Certificate · DARC3
DARC Enterprise
Custom pricing
Contact us for a tailored quote
Everything in DARC Proplus everything below
SEAL certification included
DARC3 certification
220-control framework
Unlimited seats
8 hours / month OpSec consultancy
Continuous dependency monitoring
Coming Soon
After DARC: Continuous Adversarial Testing
A continuous adversarial testing service combining AI and human red teams. We simulate real-world attacks against your organization on an ongoing basis to identify weaknesses before threat actors do. Available as an add-on to any DARC plan.

Ready to
Certify Your
Operations?

The Threat SEAL The Standard Plans