Is your data safe with us?

Effective Date: June 2026

We take privacy and security seriously. We do not ask for or store crypto private keys or seed phrases, and we do not sell personal information. Risk analysis primarily uses public website and blockchain data; account and operational data are processed as described in our Privacy Policy.

Where your checks run

We deliberately never store private keys or seed phrases, and TrustSniffer does not take custody of crypto assets. Analysis is divided across dedicated application and worker processes.

Web analysis uses isolated browser contexts that are destroyed after a scan. Selected capture workloads can use restricted containers when that deployment mode is enabled; other analysis runs in bounded worker processes. We do not claim that every workload is containerized.

Public requests pass through a TLS-terminated gateway, and application routes enforce authentication and role-based access where required.

Data Encryption

In Transit

Production web traffic is served over HTTPS and HTTP Strict Transport Security (HSTS) is enabled with a one-year max-age. Transport behavior can also depend on the deployed edge and client.

At Rest

Access to stored account, analysis, and operational data is limited through application authentication, scoped permissions, and server-side access controls. We do not publish a universal at-rest encryption or hardware-key claim without deployment-level verification.

Compliance & Certifications

  • SOC 2 Type II — Audit in progress. Expected completion Q3 2026.
  • ISO 27001 — Readiness assessment complete. Formal certification planned Q4 2026.
  • Privacy rights — Request channels and currently described controls are documented in our Privacy Policy. Regulatory compliance depends on the applicable legal and contractual context.
  • Sale of personal information — We state that we do not sell personal information; applicable access and deletion requests are described in our Privacy Policy.

Vulnerability Reporting & Bug Bounty

We welcome responsible security research. If you discover a vulnerability in our platform, please disclose it responsibly:

Email: security@trustsniffer.com

PGP Key: Available on request

Scope: API, WebSocket, and web application vulnerabilities

We commit to acknowledging reports within 48 hours and providing a resolution timeline within 5 business days. Critical vulnerabilities in production are eligible for monetary reward under our private bug bounty program.