Platform security
- Non-custodial by design — we never hold your private keys and cannot move your assets.
- Encryption in transit and at rest, with session and device controls on every account.
- Server-side secrets only; no sensitive keys ever reach the browser.
- Hardened HTTP security headers (HSTS, frame-ancestors none, nosniff, strict referrer and permissions policies).
- Single-use sign-in nonces and signed, tamper-evident sessions.
- Smart contracts for drops and memberships are designed to be audited before deployment.
Your part
- Use a hardware or reputable self-custody wallet.
- Verify every transaction before you sign — signatures are final.
- Never share your seed phrase; OnyxOne will never ask for it.
Reporting
Found a vulnerability? See our Bug Bounty policy and report it responsibly.