WalletDNA

Trust & Security

What we do with your data, and what we do not.

This page exists so you can evaluate WalletDNA without a sales call. It links to the underlying documents rather than paraphrasing them, and it states the things we do not have as plainly as the things we do.

The company

Operator
Enbits Technologies, Inc., a California corporation, trading as WalletDNA. It is the contracting party under the Terms of Use and the data controller under the Privacy Policy.
Where we operate
United States. WalletDNA is not available in the European Union, the United Kingdom and its Crown Dependencies, the European Economic Area, Switzerland, or jurisdictions under comprehensive US sanctions. Requests from those regions are refused at the edge.
Contact
Use the contact form on any page. Security reports go to security@walletdna.com, covered below.

Where your data lives

Database
Neon, in the United States.
Application hosting
Vercel, in the United States, with a global edge network.
Authentication
Clerk, in the United States. Passwords and authentication factors are held by Clerk, not by us.
Payments
Stripe. Card details are handled by Stripe and never reach our servers.
AI summaries
Anthropic's Claude API. Wallet addresses and analytical data only. No account information, name, email or payment data is sent.
Blockchain data
Analyzing an address requires fetching its public transaction history, so the address is sent to block explorers and chain data services. They receive the address and nothing identifying you.
Full list
Every processor, with what each one receives, is in Privacy Policy section 5.1.

Protections

In transit
TLS 1.2 or higher for everything to and from the platform.
At rest
Encrypted in the database. Stored third-party credentials, such as SMTP settings, are separately encrypted at the application layer.
Access control
Limited to personnel who need it for their role. See the honest note below on what that means at our size.
Second factor
Required, and enforced by the platform rather than by policy, on any account with a verified .gov or .mil address, on every plan including the free tier.
Report privacy
Reports created on a government account are private to that account by default rather than readable by anyone holding the link.
Transport headers
HSTS, a no-referrer policy so report URLs are never leaked to third parties, frame denial, and MIME sniffing disabled.

What we do not do

Model training
We do not use your data to train AI models, and the data we send to Anthropic is not used to train theirs. Anthropic retains it only as needed to run the service and detect abuse, typically up to 30 days.
Publishing
Nothing derived from customer activity is published. Our monthly threat report is built only from public sanctions list changes and from community submissions that were already public. What you screen is never an input to it.
Selling data
We do not sell personal information or share it for cross-context behavioral advertising.

Retention and deletion

Periods
Stated per data category in Privacy Policy section 8, not as a vague maximum.
Deleting a report
Permanent and immediate. It also removes the review share links you created for it and the record of who opened them, ownership attestations, and valuations.
The association
Where the report you delete is the last one you hold for an address, we also strip that address, the originating IP and the risk score from our security logs, keeping only that an analysis ran on that chain at that time.
Everyone
These practices apply on every plan. We do not offer stronger deletion to some customers than to others.

Reporting a vulnerability

Email security@walletdna.com. Please include enough detail to reproduce the issue. We aim to acknowledge within three business days and to tell you what we intend to do about it.

In scope

walletdna.com, its API, and the reports and share links it generates.

Out of scope

Findings in services we do not run, including Clerk, Stripe, Vercel and Neon, which should go to those vendors. Also out of scope: denial of service, social engineering of our staff or customers, physical attacks, and scanner output with no demonstrated impact.

Safe harbour

If you make a good faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat it as authorized. In return: do not access, modify or retain data belonging to anyone else, do not degrade the service for others, stop as soon as you have confirmed a finding, and give us reasonable time to fix it before disclosing publicly.

We do not currently run a paid bug bounty. We will credit you if you want to be credited. Machine-readable pointer: /.well-known/security.txt.

What we do not have

No SOC 2, ISO 27001 or equivalent certification. We have not been through an independent audit, and we are not going to imply otherwise with a badge.

Named individuals have production database access. WalletDNA is a small team. Access is limited to those who need it to operate the service, but it is not limited by an access-management system with separation of duties, and you should assume a named person can read what you store.

No independent testing of our analytical output. Our accuracy claims are our own. The methodology documents how scores are produced and grades our attribution confidence, so you can judge it, but no third party has verified it.

If your security review needs more than this, tell us what it needs and we will tell you honestly whether we can meet it. We would rather say no than discover the gap during onboarding.

Changes

Every material change to our Terms and Privacy Policy is recorded, dated and described in plain language on our public changelog, including the ones that correct something we got wrong. Entries are appended and never rewritten.