Infrastructure and applications
Internal and external VA/PT across the licence perimeter, admin panels, APIs, cloud accounts, and vendor integrations on Critical or Important Functions.
Part I of the Technology & Information Rulebook (current version effective mid-2025) expects qualified, independent vulnerability assessment and penetration testing, at least annually, and before new systems, applications, or products go live, with results available to the Authority on request. Where it matters to the VA Activities, that includes smart contracts.
A public-site scrape and a scanner export do not cover custody UIs, signing workflows, cloud IAM, or the path that moves client assets. If those were out of scope, the brochure was tested, not the VASP.
Internal and external VA/PT across the licence perimeter, admin panels, APIs, cloud accounts, and vendor integrations on Critical or Important Functions.
Quorum, recovery, policy-change paths, and whether a single compromise is enough to move client Virtual Assets. Part I.D is explicit on this.
Rule I.E.1 pulls in effectiveness, enforceability, and robustness of contracts tied to the VA Activities, including upgrades and keepers, not only launch-week bytecode.
What was tested, when, by whom, against which systems, with what results, plus owners and a remediation trail. A vendor slide deck is not an inspection pack.
We start from inventory: systems, apps, cloud accounts, custody stack, contracts, and third parties on Critical or Important Functions. Scope is written against that list, not a generic network range.
ADGM FSRA work uses the same method when the perimeter sits there. This is a security engagement, not licensing advice, and not a claim that AN3 is a VARA-appointed auditor.
Briefs: typically one business day. Active incidents: ir@an3.io, 24/7.