Protected where it counts. Honest about the rest.
This page lists exactly what is implemented in the Axiora codebase today. Anything not listed here is not claimed.
Implemented
Email + password authentication with mandatory email verification. Unverified sessions cannot reach the application — middleware redirects them to verification.
Supabase Auth sessions carried in HTTP-only cookies, refreshed per request. Passwords are never stored, logged, or displayed by Axiora code.
No private keys or seed phrases exist anywhere in the product. Withdrawals target saved addresses only, draw from available balance, and are state-tracked end to end.
Every private table is gated by auth.uid() row-level security: users can only read their own profiles, deployments, transactions, trades, referrals and notifications.
Security response headers (content-type protection, frame denial, strict referrer policy), no privileged credentials in client bundles, server-side validation on every financial mutation.
Deployment activation re-quotes server-side and records idempotency keys, so double-submits cannot create duplicate deployments. Financial amounts are stored as NUMERIC, never float.
Exposure caps, correlation checks and drawdown guards sit between consensus decisions and execution. Risk can veto any trade.
Not implemented (not claimed)
Authenticator-based 2FA is not available in this release. Email-verified sessions and address verification carry withdrawal protection instead.
No third-party security audit, penetration test, or compliance certification has been performed. Do not treat this build as audited.
Your responsibilities
Use a unique password, keep your email account secure, and sign out on shared devices.
Always verify destination addresses before withdrawing. Transactions on public networks cannot be reversed.
Create a secured account
Email verification is required before any account can reach the application.