Security

An honest account of what is protected today, and what must exist before real money moves.

ICO will never ask for your seed phrase or private key

Not by email, chat, support or any form on this site. Anyone asking is trying to steal from you.

Current boundaries

Account authentication

Works today

Sign-in, password storage, password reset and sessions are handled by our backend's authentication service. ICO never sees or stores your password in readable form.

Data access rules

Works today

Every database table has row-level access rules. Your drafts, portfolio and reports are readable only by you. Public data is limited to published offerings and profiles.

Tamper-proof positions

Works today

Users cannot write commitment, allocation or portfolio records. Only a future indexer reading confirmed chain transactions will.

Custody and escrow

Planned

There is none. ICO holds no SOL, no tokens and no keys. Contributions are disabled until an on-chain escrow program exists.

Smart contract audit

Planned

No contract is deployed, so none has been audited. Before mainnet, the program will be tested and independently audited, and the report published here.

No audit badges

ICO has not been audited by anyone. If you see an "audited by" claim about ICO, it is false.

Protect yourself

  • Use a unique password and keep your email account secure.
  • Only trust links on icodot.fun. Check the address bar.
  • Creator links are not verified — be careful what you click.
  • Report suspicious offerings or profiles using Report.

Responsible disclosure

If you find a security issue, please report it privately and give us reasonable time to fix it before disclosure. Do not access other users' data or disrupt the service while testing.

A dedicated security contact is being set up

We have not published a security address yet. It will appear here. We do not run a bug bounty.

Read more in Docs: Security model.