Security
How TAIYO X protects your assets and your account — and what you can verify yourself, on-chain, right now.
Non-Custodial by Design
Your private keys never leave your wallet. Signing in is a free cryptographic signature — no email, no password, nothing for us to leak. Funds stay in your own wallet until you deposit.
Server-Side Signature Verification
Every login signature is cryptographically recovered and checked on our servers (ecrecover). A signature from the wrong account is rejected — nobody can sign in as you without your key.
Open, Verifiable Contract
The authorization contract's source code is published and verified on the block explorer. What you approve is exactly what the code says — read it yourself below.
Revocable at Any Time
Authorization is a standard token allowance — not a transfer. You can revoke it whenever you want from any allowance tool (e.g. revoke.cash) or your wallet's approval manager.
Hardened Infrastructure
Enforced HTTPS with HSTS, strict Content-Security-Policy, CSRF protection on every form, and rate limiting behind Cloudflare. Admin surfaces are isolated and invisible to the public.
Data Minimalism
No KYC documents, no ID uploads, no sensitive personal data stored. Your account is your wallet address — there is simply very little about you for anyone to steal.
Only ever approve these addresses. If a site or message asks you to authorize a different contract, it is not us.
Found a vulnerability?
We take reports seriously. Contact us through the Help Center with details and we will respond promptly. Please do not test against user funds.