No private keys
Wallet keys and seed phrases are not required for public-chain monitoring or payment matching.
Security
The public security model starts with a narrow responsibility boundary and verifiable events.
Wallet keys and seed phrases are not required for public-chain monitoring or payment matching.
Webhook deliveries include an HMAC signature so an integration can verify the sender before processing an event.
Test keys issue sandbox invoices, keeping integration traffic separate from real payment flows.
Responsible reporting
Email hello@cryptanio.com with the subject “Security report”. Describe the affected URL or API area, impact and safe reproduction steps.
Do not access other users’ data, disrupt the service, move funds or include credentials in the first message. We will arrange a safer channel when needed.