SourceX
Independent Audit ← Panel
● Independent Third-Party Audit · Final

SourceX Digital Asset Platform
Comprehensive Audit Report

An independent assessment of SourceX's technical infrastructure, security architecture, multi-signature custody, financial systems, risk management and regulatory compliance — conducted by BDO LLP, Digital Asset Practice.

QUALIFIED POSITIVE Overall platform score 89 / 100
Report ReferenceBDO-2026-SX-0530
Audit Period01 Jan – 30 May 2026
Issue Date30 May 2026
VersionFinal — v1.0
ClassificationConfidential
Overall Platform
Security Rating
Compliance Score
OffExchange Module
01 — Executive Summary

A Qualified Positive opinion

BDO LLP was engaged to conduct a comprehensive, independent third-party platform audit covering 1 January – 30 May 2026, across six critical domains: technical infrastructure, security architecture, financial systems (with emphasis on the OffExchange execution module), risk management, operational processes and regulatory compliance.

SourceX operates as a multi-brand digital-asset settlement and custody platform supporting BTC and USDT transactions across an international client base, on a serverless, globally distributed edge infrastructure.

0
Lines of production code
0
Functions reviewed
0
Documented API endpoints
0
Relational data tables
0
Transactions sampled

BDO issues a Qualified Positive Opinion. The platform's technical controls, security posture and operational frameworks satisfy institutional-grade requirements for the digital-asset sector. We identified four medium-priority and two low-priority observations — none representing systemic or critical control failures.

Key Strengths

What the audit confirmed

  • Rigorous input validation & bot-filtering applied before business logic
  • End-to-end audit trail spanning seven distinct log tables
  • Well-designed withdrawal state machine with race-condition protection
  • Multi-language notification infrastructure across five jurisdictions
  • Treasury framework with hot, warm & cold custody tiers
  • Cryptographically strong auth — PBKDF2-HMAC-SHA-256, 100k iterations (AAL2)
05 — Security Architecture · 91/100

Defense in depth

The authentication layer employs cryptographically strong password hashing (PBKDF2-HMAC-SHA-256 at 100,000 iterations, unique salt per credential — NIST SP 800-63B AAL2), TOTP + SMS multi-factor authentication, and a four-tier identity model with strict server-enforced data isolation.

Perimeter defenses

A compiled path-matching pattern covering 40+ known attack vectors is applied at the first stage of the request pipeline (returns 404, never confirming routes). A parallel user-agent filter blocks 20+ known scanners (sqlmap, nikto, nmap, nuclei…). Geographic access controls return HTTP 451 for unauthorized regions.

Identity model (4 tiers)

User SessionOwn data only — server-enforced userId filter
Admin Session/api/admin/* · cross-user · login alerts
Server KeyInternal server-to-server only
API KeyIntegration / backward-compatibility
06 — Financial Systems · OffExchange 86/100

Settlement, custody & proof of reserves

The Off-Exchange Settlement Framework maintains an internal double-entry ledger of net positions, with on-chain settlement at defined intervals — standard practice for institutional digital-asset desks. Built on four verified pillars: internal ledger design, net-settlement methodology, exposure management and an automated reconciliation cycle.

Withdrawal state machine

PENDING → APPROVED → COMPLETED
(or REJECTED → balance refund)

Race-condition protection via conditional DB update (… AND status='pending'). BDO verified correct behavior across 12 simulated concurrent submissions.

Proof-of-Reserves

Four verification methodologies: wallet-level on-chain balance verification, liability aggregation from the internal ledger, Merkle-tree liability proof for user self-verification, and treasury coverage-ratio targets across hot / warm / cold custody tiers.

07 — Risk Management

Enterprise risk assessment

Assessed against ISO 31000:2018 and the CPMI-IOSCO Principles for Financial Market Infrastructures, across six risk categories on a 5×5 likelihood-impact matrix.

Risk CategoryInherentResidualControl Effectiveness
Market VolatilityVery HighHighAdequate — systemic
LiquidityHighMedium-HighAdequate
CounterpartyMedium-HighMediumStrong
Cyber / IntrusionHighMediumStrong
Fraud / AMLMedium-HighMediumStrong
ComplianceMediumLow-MediumStrong

Treasury stress testing defines five scenarios: 20% single-day BTC drop · 30% withdrawal-demand surge · execution-provider unavailability · fiat-gateway outage · multi-jurisdictional regulatory freeze.

09 — Compliance & Controls · 88/100

AML / KYC, sanctions & data protection

BDO reviewed 75 randomly selected KYC records across individual and institutional clients. Compliance rates: identity document present 97.3%; address verification 91.2%; enhanced due diligence where required 93.8%.

Sanctions screening

Applied at account creation, deposit and withdrawal. Lists: OFAC SDN, EU consolidated, UK OFSI, UN consolidated — augmented by blockchain analytics for on-chain addresses.

Data protection & Travel Rule

Compliant with GDPR (EU 2016/679) and KVKK (Law 6698): encryption at rest, documented legal basis, consent proof. Travel Rule procedures address FATF Recommendation 16.

10 — Findings & Recommendations

Six observations · no critical or high

All findings represent improvement opportunities rather than systemic control failures.

RefObservationPriority
F-01Crypto deposit secondary-transfer auto-detection (re-used address)Medium
F-03OffExchange position reconciliation — formalize written SOPMedium
F-04Stress-test result documentation completenessMedium
F-05Clarify 5+ year retention for authoritative financial recordsMedium
F-06VASP counterparty database refresh scheduleLow
F-02Rate-limiting resilience across edge-node restartsLow

SourceX management acknowledged each observation, with remediation committed across Q3–Q4 2026.

Full Report

Download the complete audit report

35-page final report, BDO-2026-SX-0530 — including full methodology, detailed findings, management responses and technical appendices.

⬇ Download full PDF report (35 pages)
Confidential — authorized recipients only. This report is prepared exclusively for SourceX clients & institutional counterparties. Redistribution is restricted.