1. Overview
Security is a product feature, not a policy page. This document describes the controls that protect accounts, funds and data on the Crypthax platform.
2. Identity and sessions
Passwords are hashed with bcrypt at cost 12 and are never logged or stored in plain text. Sessions are HS256-signed JWTs delivered in httpOnly, sameSite=Lax cookies, expiring after 14 days.
Every sign-in and sign-out records IP address, browser, operating system and device class, and you can review your access history from the dashboard.
3. Funds
Crypto intake is handled by Paymento using single-use deposit addresses per order. We never request seed phrases or private keys and never accept them if offered.
Customer balances are tracked in a dedicated ledger with an append-only event log. Payout funds are never commingled with operating capital.
4. Data
All traffic is encrypted in transit with TLS 1.3 and HSTS is enforced. Payout details are encrypted at rest and are only readable by the payout desk during settlement.
5. Monitoring
Authentication anomalies, payout detail changes and unusual order patterns generate alerts that are reviewed by our operations team. Rate limiting protects the authentication and order endpoints.
6. Responsible disclosure
Report vulnerabilities to support@crypthax.com. We acknowledge within 24 hours, keep you updated, and will never pursue good-faith research that respects our safe-harbour terms.
Questions about this document?
support@crypthax.com