Trust & Security
What we do with your data, and what we do not.
This page exists so you can evaluate WalletDNA without a sales call. It links to the underlying documents rather than paraphrasing them, and it states the things we do not have as plainly as the things we do.
The company
Where your data lives
Protections
What we do not do
Retention and deletion
Reporting a vulnerability
Email security@walletdna.com. Please include enough detail to reproduce the issue. We aim to acknowledge within three business days and to tell you what we intend to do about it.
In scope
walletdna.com, its API, and the reports and share links it generates.
Out of scope
Findings in services we do not run, including Clerk, Stripe, Vercel and Neon, which should go to those vendors. Also out of scope: denial of service, social engineering of our staff or customers, physical attacks, and scanner output with no demonstrated impact.
Safe harbour
If you make a good faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat it as authorized. In return: do not access, modify or retain data belonging to anyone else, do not degrade the service for others, stop as soon as you have confirmed a finding, and give us reasonable time to fix it before disclosing publicly.
We do not currently run a paid bug bounty. We will credit you if you want to be credited. Machine-readable pointer: /.well-known/security.txt.
What we do not have
No SOC 2, ISO 27001 or equivalent certification. We have not been through an independent audit, and we are not going to imply otherwise with a badge.
Named individuals have production database access. WalletDNA is a small team. Access is limited to those who need it to operate the service, but it is not limited by an access-management system with separation of duties, and you should assume a named person can read what you store.
No independent testing of our analytical output. Our accuracy claims are our own. The methodology documents how scores are produced and grades our attribution confidence, so you can judge it, but no third party has verified it.
If your security review needs more than this, tell us what it needs and we will tell you honestly whether we can meet it. We would rather say no than discover the gap during onboarding.
Changes
Every material change to our Terms and Privacy Policy is recorded, dated and described in plain language on our public changelog, including the ones that correct something we got wrong. Entries are appended and never rewritten.