Security & Disclosure | Coinsclone
Coinsclone Contact Us
Coinsclone
Exchange
View Exchange overview →
DEX
View DEX overview →
Wallets
View Wallets overview →
Payments
View Payments overview →
NFT
View NFT overview →
Markets
View Markets overview →
Tokens
View Tokens overview →
Tokenization
View Tokenization overview →
Company
View Company overview →
Get a Free Live Demo
Home/Security & Disclosure
Trust & policies

Security & Responsible Disclosure

How we secure our own systems and client work, and how to report a vulnerability to us. If you have found something, please read the reporting section first.

Last reviewed: date

On this page
01Reporting a vulnerability02What to include in a report03Safe harbour04Out of scope05How we secure our own work06If you are a client with an incident

Reporting a vulnerability

Report security issues here rather than through the general contact form, so they reach the right people immediately.

Security contact
[email protected] — confirm address
PGP key
Publish a key fingerprint and link if you support encrypted reports
Acknowledgement
Within X business days of receipt
Initial assessment
Within X business days, including our severity view
Resolution target
State target windows by severity, e.g. critical within X days
Credit
We credit reporters publicly unless you prefer otherwise

What to include in a report

  • The affected system, URL or contract address.
  • A clear description of the issue and its potential impact.
  • Reproduction steps, and a proof of concept where you have one.
  • Any logs, requests or transaction hashes that help us verify quickly.
  • How you would like to be credited, or that you prefer anonymity.

Safe harbour

We will not pursue legal action against researchers who follow this policy in good faith. To stay within it, please:

  • Do not access, modify or delete data belonging to anyone else.
  • Do not degrade service availability — no denial-of-service or volumetric testing.
  • Do not use social engineering, physical intrusion or credential stuffing against staff or clients.
  • Stop testing as soon as you have confirmed a vulnerability, and report it.
  • Give us reasonable time to remediate before any public disclosure.

If you operate a bug bounty with rewards, state the scope and reward ranges here. If you do not pay bounties, say so plainly — researchers prefer clarity over ambiguity.

Out of scope

  • Findings from automated scanners without a demonstrated exploit path.
  • Missing security headers with no proven impact.
  • Vulnerabilities in third-party services we do not control.
  • Issues requiring physical access to a user unlocked device.
  • Social engineering of our staff or clients.
  • Client production systems, unless that client has separately authorised testing.

How we secure our own work

Independent audits
Every value-holding contract path is reviewed by a third party, remediated and retested before mainnet.
Penetration testing
Application, API and infrastructure testing before go-live on platforms we deliver.
Key management
HSM or MPC signing, multisig treasury control, documented rotation and recovery procedures.
Access control
Least-privilege access to client systems, role-based permissions and logged administrative actions.
Encryption
In transit and at rest, with no plaintext secrets in source control or configuration.
Client handover
Incident runbooks and disclosure procedures transferred with the platform, not retained by us.

If you are a client with an incident

Contact the emergency contact you want published rather than the general security address, and mark it urgent. Incident runbooks delivered with your platform include the escalation path and the decisions that need making in the first hour.

Clients on a support retainer have a separate escalation route agreed in their contract, which takes precedence over this page.

Found something?

Report it to our security contact and you will hear back with an acknowledgement and a severity assessment.

Report a VulnerabilityOr contact us directly
Live AMM DEX demo, your branding applied
Get Demo
Free live demo

Get a Free Live Demo

Tell us what you need and we will walk you through a working platform with your branding applied.

Request received

A solution architect will reply within one business day. We sign an NDA before any technical discussion.

NDA signed before technical discussion. No obligation.

Technical call

Talk to a DEX Architect

A solution architect who has built these platforms, not a sales rep. We sign an NDA before getting into specifics.

Call request received

An architect will confirm a slot in your preferred window within one business day, with an NDA attached.

No obligation, no sales script. NDA signed before technical discussion.

Live demo

Configure Your Live Demo

Tell us what to set up and we will walk you through the platform with your own configuration applied.

Demo request received

We will confirm a walkthrough slot within one business day with your configuration applied.

NDA signed before technical discussion. No obligation.

Launch plan

Get Your Launch Plan

We will send a prioritized build plan for your scope, sequenced by what has to exist before launch.

Launch plan on the way

Expect a prioritized plan within one business day, sequenced by launch dependency.

NDA signed before technical discussion. No obligation.

Scoped proposal

Request a Scoped Proposal

Share your scope and we will come back with architecture, compliance requirements, delivery phases and a timeline.

Proposal request received

A solution architect will reply within one business day with a scoped proposal and an NDA.

NDA signed before technical discussion. Full confidentiality.

Quick enquiry

Send a Quick Enquiry

Two fields. We will reply on whichever channel you prefer.

Enquiry received

We will reply within one business day on the channel you gave us.

NDA signed before technical discussion.