ChainVerify
SECURITY

Security is part of the proof layer.

ChainVerify is designed for workflows where evidence, reviewability, and trustworthy system behavior matter. We use practical safeguards to reduce risk across the website, API, and payment flow.

Core practices

  • HTTPS/TLS is used for the public website and supported API traffic.
  • Access to production systems and administrative functions is limited to authorized operators and service accounts.
  • Secrets and credentials should not be embedded in customer-submitted content or public requests.
  • Verification records are designed to preserve traceability through identifiers, timestamps, and structured evidence.
  • Security controls are reviewed as the product and infrastructure evolve.

Payments

ChainVerify uses Stripe-hosted Checkout for supported purchases. Payment-card entry is handled by Stripe rather than by ChainVerify's own checkout form. ChainVerify may receive transaction and billing metadata needed to identify a purchase, but does not need full card numbers to operate the service.

Responsible disclosure

If you believe you found a security issue, email proof@chainverify.org with “Security Report” in the subject. Include enough detail to reproduce the issue, the affected URL or endpoint, and the potential impact.

Please do not access data that is not yours, degrade service availability, run destructive testing, or publicly disclose an unresolved issue before we have had a reasonable opportunity to investigate.

No certification claim

This page describes general security practices. It does not claim that ChainVerify is certified under SOC 2, ISO 27001, PCI DSS, or any other framework unless a separate current document expressly says so.