No seed phrases
CrediFi will never request a wallet seed phrase or private key through this website, email, social media, or support.
CrediFi's website uses no third-party analytics scripts, never asks for a seed phrase, and is designed to keep sensitive financial data off public blockchains.
CrediFi will never request a wallet seed phrase or private key through this website, email, social media, or support.
The public site ships without ad networks, analytics pixels, remote font services, or third-party JavaScript dependencies.
The Connect Wallet flow requests only the selected public address. The scoring tool does not request a transaction signature, spending approval, seed phrase, or private key.
Chain provider requests are made by the scoring service so production RPC credentials can remain in server environment variables rather than browser code.
The scoring API accepts only valid EVM address input, applies short-lived caching, and includes request throttling in the bundled Node runtime.
The deployment pack includes Content Security Policy, HSTS, frame blocking, MIME protections, referrer controls, and restrictive permissions headers.
The contract address displayed across this site is loaded from one configuration source. Before any transaction, compare the full address and network with the verified address published on credfi.us.
TBA
If you believe you found a security vulnerability in a CrediFi web property, email security@credfi.us. Include a clear description, affected URL or component, reproduction steps, and the potential impact. Do not access data that is not yours, disrupt services, or use social engineering.
CrediFi will evaluate good-faith reports intended to improve security. A reward or bug bounty is not promised unless a separate written program states otherwise.
Official website: credfi.us. Official X profile: @CrediFiScore.