AXIORA PROTOCOL
SECURITY

Protected where it counts. Honest about the rest.

This page lists exactly what is implemented in the Axiora codebase today. Anything not listed here is not claimed.

Implemented

Account security

Email + password authentication with mandatory email verification. Unverified sessions cannot reach the application — middleware redirects them to verification.

Authentication

Supabase Auth sessions carried in HTTP-only cookies, refreshed per request. Passwords are never stored, logged, or displayed by Axiora code.

Wallet security

No private keys or seed phrases exist anywhere in the product. Withdrawals target saved addresses only, draw from available balance, and are state-tracked end to end.

Data protection

Every private table is gated by auth.uid() row-level security: users can only read their own profiles, deployments, transactions, trades, referrals and notifications.

Infrastructure

Security response headers (content-type protection, frame denial, strict referrer policy), no privileged credentials in client bundles, server-side validation on every financial mutation.

Transaction security

Deployment activation re-quotes server-side and records idempotency keys, so double-submits cannot create duplicate deployments. Financial amounts are stored as NUMERIC, never float.

Risk controls

Exposure caps, correlation checks and drawdown guards sit between consensus decisions and execution. Risk can veto any trade.

Not implemented (not claimed)

No TOTP two-factor yet

Authenticator-based 2FA is not available in this release. Email-verified sessions and address verification carry withdrawal protection instead.

No external audit

No third-party security audit, penetration test, or compliance certification has been performed. Do not treat this build as audited.

Your responsibilities

Credentials

Use a unique password, keep your email account secure, and sign out on shared devices.

Addresses

Always verify destination addresses before withdrawing. Transactions on public networks cannot be reversed.

Create a secured account

Email verification is required before any account can reach the application.