Security

The service observes transactions. It does not control your funds.

The public security model starts with a narrow responsibility boundary and verifiable events.

No private keys

Wallet keys and seed phrases are not required for public-chain monitoring or payment matching.

Signed webhooks

Webhook deliveries include an HMAC signature so an integration can verify the sender before processing an event.

Sandbox separation

Test keys issue sandbox invoices, keeping integration traffic separate from real payment flows.

Found a security issue?

Email hello@cryptanio.com with the subject “Security report”. Describe the affected URL or API area, impact and safe reproduction steps.

Do not access other users’ data, disrupt the service, move funds or include credentials in the first message. We will arrange a safer channel when needed.