Skip to content

CryptoMetric AI Security Notice — counsel-review draft

Evidence-bounded description of security responsibilities and reporting; it is not a certification or guarantee.

Draft status and assurance boundary

This notice was drafted on 20 September 2026 and is not effective. It describes intended and repository-evidenced controls, which require deployment verification. It is not an independent audit, assurance report or regulatory authorization.

Application controls

The application is designed to use cookie-based browser sessions, anti-forgery checks, origin checks for browser connections, optional time-based one-time-password authentication, authorization checks and security event records. Delivery automation includes dependency and container checks. Effectiveness depends on correct deployment, monitoring and maintenance.

Exchange credentials

Exchange API credentials are intended to be encrypted at rest and excluded from responses and logs. Users must provide trade-only credentials without withdrawal permission, use exchange allow-listing where available, keep independent account access and revoke a credential after suspected compromise.

Shared responsibility

Syscobyte AB is responsible for reasonable safeguards within systems it controls. Users are responsible for secure devices, unique passwords, authentication factors, correct recipients, exchange configuration and prompt incident reports. Exchanges, networks and hosting providers control their own systems and risks.

Security limitations

No internet service can eliminate every vulnerability, outage, credential theft, supply-chain event or human error. Security controls reduce risk but can fail. Public descriptions intentionally omit operational detail that would materially increase attack risk.

Reporting a vulnerability

Report a suspected vulnerability privately to [PENDING monitored security contact and public-key or secure-reporting channel]. Do not access another person's data, degrade the service, use social engineering, demand payment through coercion, or publish exploitable detail before a reasonable remediation opportunity.

[PENDING safe-harbor terms, acknowledgement target, severity/response targets and coordinated-disclosure timeline].

Incident handling

Reports are triaged, contained, investigated and remediated according to severity. Credentials may be revoked and access restricted to protect users. Notification commitments depend on verified facts and applicable law; [PENDING incident contacts, escalation ownership and contractual notification periods].

Standards and evidence

OWASP ASVS and applicable legal security duties may be used as control references. Control mapping is not equivalent to independent certification. [PENDING approved assurance scope, test cadence, vulnerability-management service levels and evidence owner].

Primary sources