Security First.
How we protect your data and your funds.
Our approach
One simple principle.
We should never be able to touch your funds, and we should collect as little sensitive information as possible in the first place.
Non-custodial by design
- We never take custody of, or have access to, your crypto funds.
- We never ask for your private key or seed phrase, under any circumstances.
- Connecting a wallet only requests a free "sign this message" confirmation to prove ownership. It cannot move funds or approve a transaction.
Data handling
- Wallet lookups use public blockchain data, the same information anyone can see on a public block explorer.
- Encrypted reports are locked with a unique key before storage. Only a verified owner (via wallet signature) can retrieve it.
- Guest usage requires no account or personal information at all.
- Traffic is encrypted in transit (HTTPS/TLS).
Account security
- Registered accounts are protected by standard password hashing. We do not store passwords in plain text.
- A human-verification check at sign-up reduces automated abuse.
Beware of scams. If anyone claiming to represent 2RUMint or XiMoor.io ever asks you for a private key or seed phrase, it is a scam.
Responsible disclosure
Found a vulnerability?
If you believe you have found a security vulnerability in our application, please report it to us privately so we can investigate and address it before any public disclosure. We ask that you avoid accessing, modifying or exfiltrating data that isn't your own while investigating an issue.
Report privately to: Security contact email coming soon
This page describes our security practices in plain language. It is not a certification, warranty or audit attestation.