Security

Security starts with minimizing what must be trusted.

CrediFi's website uses no third-party analytics scripts, never asks for a seed phrase, and is designed to keep sensitive financial data off public blockchains.

01

No seed phrases

CrediFi will never request a wallet seed phrase or private key through this website, email, social media, or support.

02

Minimal third parties

The public site ships without ad networks, analytics pixels, remote font services, or third-party JavaScript dependencies.

03

Read-only wallet connection

The Connect Wallet flow requests only the selected public address. The scoring tool does not request a transaction signature, spending approval, seed phrase, or private key.

04

Server-side chain access

Chain provider requests are made by the scoring service so production RPC credentials can remain in server environment variables rather than browser code.

05

Validated scoring requests

The scoring API accepts only valid EVM address input, applies short-lived caching, and includes request throttling in the bundled Node runtime.

06

Strict browser headers

The deployment pack includes Content Security Policy, HSTS, frame blocking, MIME protections, referrer controls, and restrictive permissions headers.

Verify before interacting with $CREDIFI

The contract address displayed across this site is loaded from one configuration source. Before any transaction, compare the full address and network with the verified address published on credfi.us.

$CREDIFI contract

TBA

Responsible disclosure

If you believe you found a security vulnerability in a CrediFi web property, email security@credfi.us. Include a clear description, affected URL or component, reproduction steps, and the potential impact. Do not access data that is not yours, disrupt services, or use social engineering.

Good-faith research

CrediFi will evaluate good-faith reports intended to improve security. A reward or bug bounty is not promised unless a separate written program states otherwise.

Official channels

Official website: credfi.us. Official X profile: @CrediFiScore.