At SantaFi, we take security seriously. This document outlines our security practices and how to report vulnerabilities.
- β We NEVER store private keys
- β We NEVER request seed phrases
- β We NEVER access your wallet without explicit permission
- β All transactions require YOUR approval in your wallet
- β We only store public wallet addresses
- β We track usage count for credit system
- β We do NOT store personal information
- β We do NOT sell or share your data
- β All SOL transfers go to verified treasury wallet
- β All transactions are on-chain and verifiable
- β No hidden fees or unauthorized transfers
- β You maintain full custody of your assets
{
"wallet_address": "ABC...XYZ", // Public information
"connected_at": "timestamp" // For session management
}
{
"wallet_address": "ABC...XYZ",
"transaction_signature": "...", // Public, on-chain
"credits_purchased": 50,
"timestamp": "..."
}
{
"wallet_address": "ABC...XYZ",
"used_count": 1, // Increment counter
"timestamp": "..."
}
We do NOT collect:
- β Private keys
- β Seed phrases
- β Email addresses (unless you provide for support)
- β IP addresses (beyond standard server logs)
- β Browser fingerprints
- β Your generated images (processed in memory, not stored)
- β Helius RPC: Enterprise-grade Solana RPC with 99.9% uptime
- β Supabase: SOC 2 Type II certified database
- β Vercel: Edge network with DDoS protection
- β HTTPS: All traffic encrypted with TLS 1.3
- β TypeScript: Type-safe code to prevent runtime errors
- β Input Validation: All user inputs sanitized
- β Rate Limiting: Protection against abuse
- β Environment Variables: Secrets never in code
- β Standard Wallet Adapter: Using official Solana wallet adapter
- β No Custom Signing: We don't implement custom transaction signing
- β User Approval: Every transaction requires explicit user approval
- β Transaction Transparency: All transaction details visible before signing
We appreciate responsible disclosure of security vulnerabilities.
Preferred Method:
- π§ Email:
security@santafi.xyz - π Use PGP if sensitive (key available on request)
Alternative:
- π¦ Twitter DM: @SantaFiXYZ
- π¬ Discord: DM to
@admin(coming soon)
Please provide:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Suggested fix (if you have one)
- Your contact info for follow-up
- β±οΈ Initial Response: Within 48 hours
- π Investigation: We'll verify and assess the issue
- π οΈ Fix: Critical issues patched within 7 days
- π Recognition: Public acknowledgment (if you want)
- π° Bounty: Case-by-case basis for critical findings
We follow responsible disclosure practices:
- β We won't take legal action against good-faith security research
- β We'll work with you to understand and fix the issue
- β We'll keep you updated on our progress
- β We'll publicly acknowledge your contribution (with permission)
- β Give us reasonable time to fix before public disclosure
- β Don't exploit the vulnerability beyond proof-of-concept
- β Don't access or modify user data
- β Don't perform DoS attacks
- β Code review completed: December 2024
- β Wallet integration verified
- β Payment flow tested
- β No private key storage confirmed
- β³ Planned for Q1 2025
- π Scope: Wallet integration, payment flow, smart contracts (if any)
- β³ Coming soon
- π° Rewards based on severity
- π Terms to be announced
- β Use Hardware Wallet: Ledger or similar for large amounts
- β Verify Transactions: Always check transaction details before signing
- β
Check URLs: Ensure you're on
santafi.xyz(not phishing site) - β Keep Software Updated: Update your wallet extension regularly
π© NEVER share your seed phrase - we will NEVER ask for it π© NEVER sign transactions you don't understand π© NEVER connect to suspicious websites π© NEVER download wallet software from unofficial sources
- π Stop immediately - Don't proceed with the transaction
- π§ Contact us - security@santafi.xyz
- π Disconnect wallet - Revoke connection if needed
- π¦ Report - Help protect the community
- π§ Email: security@santafi.xyz
- π¦ Twitter: @SantaFiXYZ
- β±οΈ Response Time: Within 48 hours
- π Website: santafi.xyz
- π¬ Community: Discord (coming soon)
This security policy may be updated periodically. Major changes will be announced via:
- π¦ Twitter @SantaFiXYZ
- π§ Email (if you're subscribed)
- π Website announcement
Last Updated: December 22, 2024
Your security is our priority π