Security baseline
- OWASP ASVS 5.0 Level 2 verification target for the web platform.
- Passkey/WebAuthn authentication for member and administrator access.
- Role, policy and jurisdiction checks enforced server-side.
- Maker-checker approval for high-impact administrative actions.
- Tamper-evident audit events for material workflow changes.
- Encrypted transport, secrets separation and minimum data collection.
Production activation
Financial activation is blocked until penetration testing, dependency and container scanning, backup restoration, incident exercises, provider webhook verification, key rotation and privileged-access review have produced accepted evidence.
Responsible disclosure
Report a suspected vulnerability through the contact form and begin the message with “SECURITY”. Do not include personal data, wallet secrets or exploit other users. A dedicated security mailbox and encryption key must be published before wider public testing.
Current status
The public website baseline is available for review. Identity, account, wallet and administrator authentication remain intentionally unavailable until their production providers and origins are verified.