Last updated: October 3, 2026
At SmartContractAuditor.ai, security is at the core of everything we do. As a platform dedicated to identifying vulnerabilities in smart contracts, we hold ourselves to the highest security standards to protect your code and data.
All data transmitted between your browser and our servers is encrypted using TLS 1.3 with strong cipher suites.
Sensitive data stored in our databases is encrypted using AES-256 encryption, the industry standard for data protection.
Passwords are hashed using bcrypt with strong work factors, making them impossible to reverse.
Secure, time-limited tokens are used for session management with automatic expiration.
API keys for IDE integrations are securely generated and can be rotated at any time.
Fine-grained permissions ensure users only access what they're authorized to see.
Our infrastructure runs on Vercel and Neon, both of which hold SOC 2 Type II certifications as vendors.
Aggressive rate limiting protects against brute-force attacks and API abuse.
HSTS, a Content-Security-Policy that blocks framing by unapproved sites, plugins, and base-URI tampering, plus MIME-sniffing, referrer, and permissions policies.
Built-in protection against distributed denial-of-service attacks.
All payment processing is handled by Stripe, a PCI-DSS Level 1 certified payment processor. We never store your credit card details on our servers. Stripe uses industry-leading security measures including tokenization and encryption to protect your payment information.
We take security vulnerabilities seriously. If you discover a security issue in our platform, please report it responsibly.
We're a small team and take privacy seriously, though we haven't undergone a formal third-party compliance audit yet. Here's what we actually do:
For security-related inquiries or to report a vulnerability:
Email: [email protected]
© 2026 SmartContractAuditor.ai. All rights reserved.