Trust · Security

Security & Responsible Disclosure

CryptoScanPro is built as a read-only risk-analysis product. This page explains user-safety boundaries and how to report a potential vulnerability responsibly.

Last updated · 6 September 2026
01

Read-only product boundary

Running a CryptoScanPro scan does not require a wallet connection, transaction signature, token approval, seed phrase or private key. Crypto checkout is a separate payment flow and does not change the read-only nature of scanning.

02

What we will never ask for

CryptoScanPro support will never ask you to send:

  • A wallet seed phrase or recovery phrase.
  • A private key.
  • Remote access to your device or wallet.
  • A token approval or arbitrary transaction merely to verify your account.
03

Responsible vulnerability reporting

If you believe you found a vulnerability in CryptoScanPro, report it privately through the official CryptoScanPro support channel on Telegram (@CryptoScanSupport). Include clear reproduction steps, affected URL or component, expected impact and any non-sensitive evidence that helps reproduce the issue.

Please avoid accessing data that does not belong to you, degrading service availability, modifying other users' data, social engineering, physical attacks or public disclosure before there has been a reasonable opportunity to investigate.

04

Security research boundaries

Testing should use the minimum access necessary to demonstrate a potential issue. Do not attempt to extract production secrets, payment credentials, private user data or cryptographic material beyond what is strictly necessary to establish the vulnerability.

05

Phishing and impersonation

Use the official CryptoScanPro domain and Telegram bot links shown by the product. Treat unsolicited requests for wallet secrets, remote-access software or emergency transfers as suspicious.

06

Incident response

Security reports are triaged according to potential impact and exploitability. Where a security incident creates legally reportable obligations, the operator should follow the applicable notification and remediation requirements.

07

Machine-readable contact

The website publishes /.well-known/security.txt so automated security tools and researchers can locate the current reporting channel.