Transparency about our security practices, audit status, and risks.
Last updated: December 2025
Mr Haven is designed with multiple layers of protection including non-custodial architecture, industry-standard vault contracts, and resilient execution. This page outlines our security practices and remaining risks. A formal third-party audit is planned for Late Q1 2026.
Public Beta
Mr Haven is currently in public beta. While core functionality is live, we continue to refine the system and complete a third-party security audit.
Comprehensive internal security review completed December 2025. A third-party audit is not yet complete.
Once completed, a public summary will be published here.
Findings shown here are based on our internal testing and review. A third-party security audit is planned for Late Q1 2026.
The system is live and publicly verifiable. All plan executions are recorded on-chain and can be independently verified.
✓ Live Execution Dashboard
View all automated plan executions with on-chain proof via BaseScan.
View Proofs →Internal Review Scope: Smart contracts, backend services, API security, authentication flows, rate limiting, and on-chain interactions.
High-Level Outcomes: No critical or high-severity issues identified. Medium-severity findings documented and remediated. Low-severity items tracked for future hardening.
Remediation: All identified issues are tracked in our internal changelog. Material changes are reflected in the version history.
Note: This is an internal timeboxed review, not a formal third-party audit. A comprehensive external audit is planned for Late Q1 2026.
Mr Haven is administered by a multisig wallet requiring multiple signatures for any protocol changes. Smart contracts enforce strict limits on what administrators can do.
✓ Your Funds Are Protected
What administrators can do:
All constraints above are enforced by smart contracts. The multisig cannot bypass these limits.
Mr Haven is built on proven, battle-tested infrastructure. Learn how it works.
Using Mr Haven involves risks. Please understand these before depositing funds:
Smart contracts may contain bugs or vulnerabilities. While we have conducted internal testing, no external audit has been completed. Code defects could result in loss of funds.
Yield is generated through Aave. If Aave experiences issues, exploits, or becomes unavailable, it could affect your deposited funds.
Plan execution relies on Chainlink Automation. While there is a fallback mechanism allowing public execution after ~1 hour, automation delays or failures could affect timing.
Mr Haven operates on Base (Ethereum L2). Network congestion, outages, or issues with the underlying blockchain could affect service availability.
As with any smart contract system, only deposit funds you're comfortable managing on-chain. Review our terms of service for complete legal details.
| Fee Type | Amount |
|---|---|
| Funding fee (on deposit) | 0.25% |
| Execution fee (scheduled plans) | 0.55% |
| Execution fee (inactivity plans) | 1.0% |
APY varies based on Aave market conditions. Past performance does not guarantee future returns.
Plan execution is automated through Chainlink Automation, a decentralized network of node operators.
Fallback mechanism: If Chainlink is unavailable, plan execution becomes publicly callable after exactly 1 hour (grace period). Public executors receive a 0.1% reward as incentive for maintaining protocol liveness. This backup path helps ensure your plans can still execute even if the primary automation is temporarily unavailable.
Note: Extreme network congestion could still affect timing.
If you discover a security vulnerability, please report it responsibly:
Email: security@mrhaven.io
Please include detailed steps to reproduce the issue. We aim to respond to security reports within 48 hours.
For more detail, see our complete guide, legal documentation, or contact us with questions.
Questions? Contact us at security@mrhaven.io