CryptoMetric AI Security Notice — counsel-review draft
Evidence-bounded description of security responsibilities and reporting; it is not a certification or guarantee.
Draft status and assurance boundary
This notice was drafted on 20 September 2026 and is not effective. It describes intended and repository-evidenced controls, which require deployment verification. It is not an independent audit, assurance report or regulatory authorization.
Application controls
The application is designed to use cookie-based browser sessions, anti-forgery checks, origin checks for browser connections, optional time-based one-time-password authentication, authorization checks and security event records. Delivery automation includes dependency and container checks. Effectiveness depends on correct deployment, monitoring and maintenance.
Exchange credentials
Exchange API credentials are intended to be encrypted at rest and excluded from responses and logs. Users must provide trade-only credentials without withdrawal permission, use exchange allow-listing where available, keep independent account access and revoke a credential after suspected compromise.
Security limitations
No internet service can eliminate every vulnerability, outage, credential theft, supply-chain event or human error. Security controls reduce risk but can fail. Public descriptions intentionally omit operational detail that would materially increase attack risk.
Reporting a vulnerability
Report a suspected vulnerability privately to [PENDING monitored security contact and public-key or secure-reporting channel]. Do not access another person's data, degrade the service, use social engineering, demand payment through coercion, or publish exploitable detail before a reasonable remediation opportunity.
[PENDING safe-harbor terms, acknowledgement target, severity/response targets and coordinated-disclosure timeline].
Incident handling
Reports are triaged, contained, investigated and remediated according to severity. Credentials may be revoked and access restricted to protect users. Notification commitments depend on verified facts and applicable law; [PENDING incident contacts, escalation ownership and contractual notification periods].
Standards and evidence
OWASP ASVS and applicable legal security duties may be used as control references. Control mapping is not equivalent to independent certification. [PENDING approved assurance scope, test cadence, vulnerability-management service levels and evidence owner].