Data & safety
Data & Safety Statement
Web3 is full of drainer scams, so healthy skepticism is correct. Here — in plain language — is exactly what data we use, what we will never ask for, and how to remove yourself.
We will never ask for
No custody. No exceptions.
- A seed phrase or private key.
- A wallet signature or transaction that moves, approves, or spends funds.
- A token approval or contract interaction to "verify" or "unlock" anything.
- An upfront payment from an auditor to join or to be scored.
The only optional signature we support is a read-only wallet message to sign our public engagement agreement (EIP-191 personal_sign) — it authorizes nothing and moves no funds.
What data we use
Auditor scores are computed from public profiles only — the same pages anyone can open on Code4rena, Sherlock, Cantina, Immunefi and CodeHawks. Nothing private, nothing behind a login. Think DeFiLlama for auditor reputation.
- Public contest results, accepted findings, severities, placements, and payouts.
- Public handles and profile bios (used to verify you control the profile).
- For protocols and signed agreements: the wallet address you connect and the timestamp of your signature.
The bio phrase is removable — by design
To confirm you control a profile, we email a one-time code like vsec:xxxxxxxx and ask you to paste it into your public bio. We read it back with a read-only scrape to confirm ownership.
Reversible, non-custodial ownership proof
Your data, your call
Your reputation belongs to you. Claiming a profile lets you verify and correct it — it does not mean we own your score.
- Correction:if your score, findings, or tier look wrong, contact us and we'll review and re-score. See how scoring works.
- Deletion:request removal of your profile and associated data at any time and we'll action it. Details in the Privacy Policy.
- No spam: notifications are opt-in and we do not sell your data.