The checklist tells you what to look for. This article tells you where to find it. For each of the six due diligence dimensions, there is a specific data source — on-chain, regulatory, or off-chain — that provides verifiable evidence. Marketing materials are not sources. Use these.
Legal Structure: Where to Verify
SEC EDGAR (sec.gov/edgar). For US-registered offerings, search the issuer name. A Reg D offering should have a Form D filing. A Reg A+ offering has a full offering circular. If the issuer claims SEC registration or exemption and has no EDGAR filings, that is a red flag.
FINRA BrokerCheck (brokercheck.finra.org). If the offering is being sold by a broker-dealer, the broker must be FINRA-registered. BrokerCheck shows registration status, licenses held, and any disciplinary history.
State securities regulators (NASAA.org). Some smaller offerings are state-registered. The NASAA directory links to all 50 state securities regulators.
International equivalents: FCA Register (fca.org.uk/register) for UK, MAS Register (eservices.mas.gov.sg) for Singapore, ASIC Connect for Australia.
Asset Custody: Where to Verify
Auditor reports. Regulated custodians holding tokenized assets are typically subject to SOC 2 Type II audits. These reports are not always public, but legitimate custodians will provide them to investors on request. BNY Mellon (BUIDL), State Street, and Coinbase Custody all have documented custody frameworks.
On-chain reserve attestations. Several tokenized asset platforms publish regular reserve attestations — typically monthly reports from an accounting firm confirming that the on-chain token supply matches the off-chain asset holdings. Ondo Finance publishes monthly attestations for USDY. Franklin Templeton publishes attestations for BENJI. If a platform does not publish attestations and claims to hold real assets, ask why.
Block explorer + issuer disclosures. Cross-reference the total token supply on the block explorer with the reported AUM in the issuer's disclosures. If BUIDL reports $2 billion AUM and there are 2 billion BUIDL tokens at $1 each on Etherscan, the math checks. If they do not match, ask why.
Smart Contract Security: Where to Verify
Block explorers. Etherscan (etherscan.io) for Ethereum, Polygonscan for Polygon, Arbiscan for Arbitrum. Paste the contract address. "Contract" tab shows whether source code is verified. "Read Contract" shows current state. "Write Contract" shows available functions — including freeze, pause, and clawback if they exist.
Audit firm websites. Reputable firms publish all completed audits publicly: Trail of Bits (trailofbits.com/audits), OpenZeppelin (blog.openzeppelin.com), Certik (certik.com/projects), Quantstamp (quantstamp.com/audits). If the claimed auditor does not list the project on their public audit page, the audit claim is unverified.
DeFiSafety (defisafety.com). Scores DeFi protocols on process quality including documentation, testing, and audit completeness. Not comprehensive but useful as a quick-screen for DeFi-adjacent RWA platforms.
Redemption Mechanics: Where to Verify
Offering documents. The redemption terms must be in the legal offering documents — not just described on the website. For Reg D offerings, the Private Placement Memorandum (PPM). For Reg A+, the offering circular. For funds, the fund prospectus or offering memorandum. If the redemption terms are only on the website and not in a legal document, they are not contractually binding.
Smart contract events. Redemption events are recorded on-chain. On Etherscan, the "Events" tab for a token contract shows Mint and Burn events. A fund that claims daily redemptions should show daily Burn events. A fund that shows no Burn events for 90 days is not processing redemptions at the frequency advertised.
Yield Source: Where to Verify
Federal Reserve H.15 (federalreserve.gov/releases/h15). Current Treasury bill rates. Any tokenized Treasury product paying significantly more than the current T-bill rate needs to explain where the excess comes from.
Bloomberg Terminal / FRED (fred.stlouisfed.org). Historical yield data for any asset class. FRED is free. If a platform claims historical returns on a specific asset, you can verify the underlying asset's actual historical yield against their claimed performance.
Platform fee disclosures. The net yield = gross yield minus fees. Management fees, performance fees, protocol fees, and gas costs all reduce net yield. A platform advertising "4.8% yield" on a Treasury product when T-bills yield 4.5% and the management fee is 0.5% is paying 4.0% net — which is below the T-bill rate. Read the fee table.
Team Verification: Where to Verify
LinkedIn. Verify claimed employment history. Look for connections to verifiable institutions. Check whether colleagues at claimed previous employers can be found who overlap with the person's claimed tenure. A CEO claiming Goldman Sachs experience should have Goldman connections on LinkedIn.
SEC EDGAR enforcement actions. Search the SEC's enforcement page (sec.gov/divisions/enforce/enforcements.htm) and litigation releases for any team member's name. This surfaces fraud cases, cease-and-desist orders, and bars from the securities industry.
Court records. PACER (pacer.gov) for federal court records. Many states have free online court record search. A team member with a fraud judgment or securities violation in their background does not disqualify a project automatically, but it is information you should have before investing.
- SEC EDGAR — Form D filings, offering circulars, enforcement actions
- FINRA BrokerCheck — Broker-dealer registration and disciplinary history
- Etherscan — Contract verification, token supply, Mint/Burn events
- FRED (St. Louis Fed) — Historical yield data for any asset class
→ DYOR Part 1: The Checklist — six dimensions, 36 questions
→ Block Explorer Guide — step-by-step contract verification
→ Full Due Diligence Framework — the complete six-dimension methodology