Security & Trust

Your Account. Locked Down.

We never see your private keys, never sell your data, and treat every endpoint like it's already under attack. Here's exactly how.

Never
Private keys
 
AES-256
Encryption
 
TOTP
2FA available
 
Zero
Custody
Read-only integrations
Security Pillars

Six Layers. Defense in Depth.

Each pillar is independently reviewed. Compromising one shouldn't compromise the others — that's how we design every system.

Authentication

How we keep your account yours.

  • Bcrypt password hashing (cost factor 12)
  • Optional TOTP-based 2FA via authenticator apps
  • JWT access tokens with refresh-token rotation
  • Aggressive rate-limiting on auth endpoints
  • Suspicious-login email alerts with IP geolocation
  • Session invalidation on password change

Data Protection

In transit and at rest, end to end.

  • TLS 1.3 for all client connections
  • AES-256 at-rest encryption (PostgreSQL TDE)
  • API keys hashed with HMAC-SHA256 before storage
  • Sensitive fields (2FA secrets, API keys) encrypted per-row
  • Daily encrypted backups with 30-day retention
  • Right-to-deletion within 30 days per GDPR

Wallet Safety

We never see your private keys. Ever.

  • Read-only wallet integrations — addresses only
  • No private keys, seed phrases, or signing rights
  • Tracked wallets stored as public addresses only
  • Exchange API connections use READ-only permissions
  • No custody — we never hold your tokens
  • Withdrawal/trade permissions explicitly disabled

Infrastructure

Hardened from day one.

  • Linux servers with restrictive firewall + fail2ban
  • Auto-updated OS-level security patches
  • Isolated Docker containers for scanner workers
  • No public access to DB / Redis / internal services
  • CloudFlare WAF + DDoS protection at edge
  • Daily vulnerability scans on dependencies

Compliance

Standards we follow.

  • GDPR-compliant data processing (EU users)
  • CCPA-compliant data sale opt-out (CA users)
  • PSD2-aligned payment handling via Stripe
  • No selling of user data — ever
  • Cookie consent banner with granular opt-in
  • Privacy Policy & Terms reviewed quarterly

Monitoring

24/7 watch on every layer.

  • All requests logged with anomaly detection
  • Failed-login pattern recognition + auto-lockout
  • API key usage analytics with abuse heuristics
  • PagerDuty alerts for security incidents
  • Weekly internal security review
  • Third-party pentest annually
Bug Bounty

Found Something? Get Paid.

We pay for verified security issues. Disclose responsibly and we'll respond within 24 hours.

Severity Tiers

Critical$5,000 – $10,000

RCE, auth bypass, mass data exposure

High$1,000 – $5,000

Privilege escalation, persistent XSS

Medium$250 – $1,000

CSRF, IDOR, reflected XSS

Low$50 – $250

Information disclosure, rate-limit bypass

Out of Scope

  • Issues requiring physical access to a victim's device
  • Social engineering, phishing, or pretexting attacks
  • DoS / DDoS attacks against our infrastructure
  • Vulnerabilities in third-party services we don't control
  • Best-practice violations without exploit chain
  • Content-spoofing without script execution
Disclose responsibly
Subprocessors

Who We Trust

Third-party services that may process your data, with their purpose and jurisdiction. We publish updates here within 30 days of any change.

AW
AWS
US / EU

Cloud infrastructure & object storage

Cl
Cloudflare
US

CDN, WAF, DDoS protection

St
Stripe
US / EU

Payment processing

Se
Sentry
US

Application error tracking

Se
SendGrid
US

Transactional email delivery

Po
PostgreSQL
EU

Primary database (self-hosted)

Security questions? We answer them.

Responsible disclosure and enterprise questionnaires go to [email protected]. Ready to run the desk? Start a 7-day Pro trial.