> For the complete documentation index, see [llms.txt](https://docs.trevee.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.trevee.xyz/trevee-earn/sonic-scassets/security-framework-and-audits.md).

# Security Framework and Audits

## Audits

Trevee Earn **is built on the** [**Veda**](https://veda.tech/) **BoringVaults and its tokenomics are a fork of** [**Thena**](https://thena.fi/)**’s ve(3,3) model.**

* **Veda Boring Vault audited by** [**Spearbit and 0xMacro**](https://github.com/Se7en-Seas/boring-vault/tree/main/audit)**.**

{% hint style="info" %}
The Veda Boring vault has already secured more than $3 billion in TLV in products such as EtherFi's Liquid and Lombard's LBTC.
{% endhint %}

* **THENA V2 has been audited by** [**OpenZeppelin**](https://blog.openzeppelin.com/retro-thena-audit)**.**

{% hint style="info" %}
Only the delegation of voting power and a simplified gauge system (limiting gauge recipient to one) are used from the Thena codebase.
{% endhint %}

## Safety Measures

### Veda Boring Vault Protocol Whitelisting Criteria

* Only integrate fully audited protocols
* Minimum requirements: $100M+ TVL and 6+ months since deployment
* No experimental or high-risk strategies

### **Safety Mechanisms**

* 5-day cooldown for scAsset redemptions
* 24h timelock delays for protocol changes

### **Risk Management**

* Vault deposits capped at:
  * 10% of a protocol's TVL on Ethereum
  * 25% of a protocol's TVL on Sonic

{% hint style="success" %}
These measures ensure the protection of underlying assets on Ethereum and of scAssets in the Sonic ecosystem, prioritizing user safety and protocol stability.
{% endhint %}
