Security

Last updated: 22 September 2026

Never enter a seed phrase, private key, recovery phrase, or a wallet or exchange password or recovery code. CryptoPreflight will never ask for any of them. Signing in to your own CryptoPreflight account is separate, and only needed to save a record.

CryptoPreflight will never request

Seed phrases or recovery phrases
Private keys
Wallet or exchange passwords
Wallet or exchange credentials, 2FA codes or recovery information
Social Security or national ID numbers
Account balances or statements
Permission to move your funds

What we do not do

CryptoPreflight never connects to a wallet, never takes custody of cryptocurrency and never signs, sends, cancels or reverses a transaction. Wallet connections are deliberately out of scope.

It does not screen for scams or sanctions, does not verify who controls an address, and never tells you a transfer is safe.

Accounts and data isolation

We never ask for wallet or exchange passwords, credentials or recovery information. Separately, saving a preflight requires your own CryptoPreflight account — an email address with a password you choose here, or Google sign-in. Each preflight, its checks, confirmation links, test transactions, acknowledgements and receipts belong to the account that created them, and database access rules block every other signed-in user from reading or changing them.

Check results are written by the server. The browser cannot mark a check as passed; it can only submit details and request that the checks be recomputed.

Confirmation links

A recipient confirmation link is a single-use, 256-bit random token generated with the platform's cryptographic random source. Only its SHA-256 hash is stored, so the link cannot be recovered from the database. It expires after 72 hours, stops working once answered, can be revoked by you, invalidates itself if the transfer details change, locks after ten openings or three submissions, and is rate limited per connection.

The recipient never sees your entries. They type the asset, network, address and any memo or destination tag from their own deposit screen; the comparison runs on the server and the response reports only which fields matched. A wrong answer therefore reveals nothing about the right one. This compares typed details — it is not identity verification.

What we have tested, and what we have not

On 22 September 2026 we ran 55 test cases against the running application, using throwaway accounts and synthetic details, and all 55 behaved as expected. They covered: a second signed-in account being unable to read, change or delete another account's preflights, checks, links, responses or receipts; a browser being unable to write or alter a check result, because check rows are written only by the server after ownership is proven; an account being unable to give itself administrator rights or switch a check off; confirmation links being refused after reuse, revocation, expiry or a change to the transfer details; the recipient page and every response it receives containing none of the sender's details; guessed links returning a plain invalid-link page, with rate limits on repeated requests and a lock after repeated openings; no address, token or transfer detail appearing in page addresses, in recorded usage events or in the browser console; and deleting a preflight removing its checks, links, responses, test transactions, acknowledgements and receipt.

That is our own internal testing, on the version of the site deployed that day. We have not had an independent penetration test, security audit or certification, and we do not claim one. Nothing here is a guarantee against every attack, and the disclaimers on this site do not remove our responsibilities to you.

Third parties and blockchain lookups

Address format and checksum validation runs offline in your browser. When you submit a test-transaction hash we query free public blockchain sources, sending only the hash. No paid risk provider, scam database or sanctions list is connected, and we do not imply one is.

Analytics

We record only which steps happened — a preflight started, a result category, a demo opened. Addresses, tags, amounts and email addresses are stripped before any event is recorded, and events stay in your browser session.

Encryption and testing status

Data is held by our managed database platform and travels over HTTPS. We make no claim about application-level encryption at rest, because none is implemented. No independent penetration test or security review has been carried out yet; treat the product as in testing.

Deleting your data

Delete a preflight from its page to remove its details, checks, links, test transactions, acknowledgements and receipts. For account deletion or any other request, email hello@cryptopreflight.app. Deleted rows may persist in our database platform's routine backups for a short period before those backups roll over; we do not restore deleted records into the live product.