Security

Small inputs. Clear limits. Evidence you can inspect.

The public services are designed to reduce exposure before a scan, preflight, or business inquiry begins.

Last updated September 3, 2026

Service boundaries

  • The website scanner reads public pages only and rejects local or private-network targets.
  • The transaction pilot accepts unsigned intent only and never signs, broadcasts, or takes custody.
  • Wallet-secret-like material is rejected before an intake is stored.
  • Same-origin checks, bounded request bodies, rate controls, and baseline browser security headers protect public routes.

Report handling

Saved report and paid-order tokens have high entropy and only a cryptographic hash is stored. Report responses are marked private and no-store, report pages are excluded from search indexing, and links expire automatically. Delivered transaction reports contain sanitized evidence; the unsigned request is retained only for the order's bounded fulfillment period.

Credentials and payment

Service, payment, and email credentials remain server-side and are not returned to the browser. We will never ask for a private key, seed phrase, recovery phrase, or keystore password. Fixed prices are created on the server, checkout occurs on PayPal, and returned orders, captures, and signed payment events are verified against one internal order before fulfillment. This website does not collect card numbers.

What the controls do not prove

Automated checks do not establish complete website security, accessibility conformance, legal compliance, smart-contract safety, or future chain behavior. Reports describe the evidence available at the time and identify limitations where evidence is unavailable.

Report a concern

Send a concise description and affected URL to JerryRNapier@gmail.com. Do not include secrets, active exploit payloads, or personal data that is not necessary to understand the issue.