Security
Non-custodial by architecture
Hexiora never holds your keys or your funds. There’s no honeypot to breach because we’re not in the value path.
Encryption everywhere
Data is encrypted in transit and at rest. Secrets are managed, rotated, and never logged.
Least-privilege access
Scoped, short-lived credentials and no standing admin. Every grant is the smallest one that works.
Continuous monitoring
We watch the rails the way we ask you to watch yours — with alerts, traces, and a public status page.
Isolated environments
Production is segregated from everything else, with strict boundaries between tenants and stages.
Vendor diligence
The few providers we rely on are vetted and bound by contract to protect your data.
Responsible disclosure
Found something? Tell us.
We welcome reports from security researchers and operate in good faith. If you believe you’ve found a vulnerability, email security@hexiora.dev with steps to reproduce. We’ll acknowledge quickly, keep you updated, and credit you if you’d like.
Give us reasonable time to investigate and fix before disclosing publicly.
Don’t access or modify data that isn’t yours, and avoid degrading the service for others.
Acting in good faith under these guidelines, we won’t pursue legal action — consider it safe harbor.
Compliance
Where we are.
We welcome reports from security researchers and operate in good faith. If you believe you’ve found a vulnerability, email security@hexiora.dev with steps to reproduce. We’ll acknowledge quickly, keep you updated, and credit you if you’d like.
Give us reasonable time to investigate and fix before disclosing publicly.
Don’t access or modify data that isn’t yours, and avoid degrading the service for others.
Acting in good faith under these guidelines, we won’t pursue legal action — consider it safe harbor.

