Back to Home

Security

Last updated: October 3, 2026

At SmartContractAuditor.ai, security is at the core of everything we do. As a platform dedicated to identifying vulnerabilities in smart contracts, we hold ourselves to the highest security standards to protect your code and data.

Data Encryption

In Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.3 with strong cipher suites.

At Rest

Sensitive data stored in our databases is encrypted using AES-256 encryption, the industry standard for data protection.

Authentication & Access Control

  • Secure Password Storage

    Passwords are hashed using bcrypt with strong work factors, making them impossible to reverse.

  • JWT Token Authentication

    Secure, time-limited tokens are used for session management with automatic expiration.

  • API Key Security

    API keys for IDE integrations are securely generated and can be rotated at any time.

  • Role-Based Access Control

    Fine-grained permissions ensure users only access what they're authorized to see.

Infrastructure Security

  • Secure Hosting

    Our infrastructure runs on Vercel and Neon, both of which hold SOC 2 Type II certifications as vendors.

  • Rate Limiting

    Aggressive rate limiting protects against brute-force attacks and API abuse.

  • Security Headers

    HSTS, a Content-Security-Policy that blocks framing by unapproved sites, plugins, and base-URI tampering, plus MIME-sniffing, referrer, and permissions policies.

  • DDoS Protection

    Built-in protection against distributed denial-of-service attacks.

Code Security

How We Handle Your Smart Contracts

  • Code is transmitted securely over HTTPS
  • Free scans (no account) run on our own pattern engine and the code is not saved
  • Signed-in scans are saved to your private history so you can reopen reports
  • Pro deep analysis sends code to Anthropic's API, which does not train on API data by default
  • Delete any scan, or your entire history, from the History tab at any time

Payment Security

All payment processing is handled by Stripe, a PCI-DSS Level 1 certified payment processor. We never store your credit card details on our servers. Stripe uses industry-leading security measures including tokenization and encryption to protect your payment information.

Vulnerability Disclosure

We take security vulnerabilities seriously. If you discover a security issue in our platform, please report it responsibly.

Responsible Disclosure Policy

  • • Report vulnerabilities to security@smartcontractauditor.ai
  • • Allow reasonable time for us to address the issue
  • • Do not exploit the vulnerability or access user data
  • • We will acknowledge your report within 48 hours

Compliance

We're a small team and take privacy seriously, though we haven't undergone a formal third-party compliance audit yet. Here's what we actually do:

  • Built with GDPR and CCPA principles in mind — see our Privacy Policy for exactly what we collect and how to request deletion
  • Data encrypted in transit and at rest (see Infrastructure Security above)
  • A responsible disclosure process for reporting security issues (see below)

Security Contact

For security-related inquiries or to report a vulnerability:

© 2026 SmartContractAuditor.ai. All rights reserved.