VARA compliance
Dubai VASP licensing readiness. Hackerbane audits your technology, information security, and custody controls against VARA's Rulebooks and prepares the security evidence your licence application and ongoing supervision require.
What VARA is
The Virtual Assets Regulatory Authority is the regulator for virtual asset activity in the Emirate of Dubai, outside the financial free zone. It licenses virtual asset service providers, supervises them, and publishes the Rulebooks they must follow. The rules that matter most to engineering teams sit in the Technology and Information Rulebook and the Compliance and Risk Management Rulebook: technology governance, information security, custody of client assets, business continuity, and independent testing.
A licence application asks you to show that these controls exist and work. Supervision after licensing asks you to keep showing it.
Who it applies to
- Exchanges and broker-dealers serving Dubai clients.
- Custodians and wallet providers holding client virtual assets.
- Lending, staking, and virtual asset management or investment services.
- Issuers of tokens and stablecoins that fall within VARA's activity list.
What Hackerbane does
- Gap assessment: we map your technology governance, information security, and custody controls to the Rulebook requirements and list what your application cannot yet evidence.
- Smart contract audit of the tokens, vaults, and on-chain logic your service depends on, with proof for serious findings.
- Custody and key-management audit: how keys are generated, stored, and used; who must approve a signature; how hot and cold balances are segregated and reconciled.
- Penetration testing of the exchange, wallet, API, and back-office systems that touch client assets, and review of any AI components that can act on them.
- Business continuity and incident handling: we test the plans against the scenarios VARA expects you to withstand.
- Remediation and licensing support: fixes are retested, the evidence is assembled in the form your application needs, and we answer the regulator's technical questions with you.
What you get
- A gap report mapped to the Rulebook clauses, with priorities and owners.
- Audit reports for the smart contracts, custody systems, and applications in scope, in a format you can attach to the application.
- An evidence pack for the technology and information security sections of the submission.
- Verified remediation and updated reports once fixes land, and a retest cadence for ongoing supervision.
Who signs off
VARA issues the licence and decides whether your application meets the Rulebooks. Hackerbane prepares the security audits and evidence the application and ongoing supervision ask for, and stands behind them when the regulator asks questions.
Questions
- Does VARA require a smart contract audit?
- VARA expects licensed providers to show that the technology behind their service has been independently tested and that risks are managed. Where your service issues or relies on smart contracts, an audit report is the standard evidence for that, and it is what the regulator will ask to see.
- Do you provide proof of reserves?
- Proof of reserves is a separate attestation. Our custody audit covers key management, signing controls, segregation of client assets, and the reconciliation logic, which is the technical evidence a reserves attestation rests on. We can work alongside the firm that issues it.
- Can you support the application itself?
- We prepare the technology, information security, and custody sections and the audit reports behind them, and we answer the regulator's technical questions with you. Legal structuring, fit-and-proper filings, and the rest of the application stay with your counsel.
Next step
Request an audit
Tell us which VARA licence category you are applying for or hold, which systems hold client assets, and where you are in the application. We will propose the audits and evidence your submission needs, with an estimate.