Security

Protecting self-custody starts with clear boundaries.

Security depends on explicit user control, protected local authorization, careful transaction review, and responsible infrastructure operation.

Security model

Specific safeguards instead of absolute claims.

Wind products communicate what they control, what remains under the user’s control, and where third-party or public-network risk begins.

User controlled

Self-custody by design

Wisp keeps wallet credentials under the user's control and does not operate as a custodial exchange or account provider.

Verifiable

Public blockchain truth

Balances and transactions are resolved from supported blockchain networks, not from a private internal ledger.

Transparent

Open technical surfaces

Public endpoints, clear product boundaries, status visibility, and responsible security reporting support trust.

For Wisp users

  • Store recovery material offline and never share it.
  • Verify the network, destination, amount, and action before signing.
  • Use device security, a strong wallet password, and biometric authorization.
  • Install builds only from trusted Wind Crypto distribution channels.
  • Review and revoke dApp sessions you no longer use.

For developers

  • Request only the permissions and actions your dApp needs.
  • Present human-readable transaction intent before wallet handoff.
  • Use canonical signing requests and exact resolved transactions.
  • Treat wallet capability negotiation and origin validation as required.
  • Do not collect or request private wallet credentials.

Responsible disclosure

Report suspected vulnerabilities privately.

Send security reports to [email protected]. Include the affected product, version or endpoint, reproduction steps, observed impact, and a safe proof of concept when appropriate.

Please do
  • Act in good faith and avoid user harm.
  • Use test accounts and minimal data.
  • Allow reasonable time for investigation.
  • Keep exploitable details private during coordination.
Please do not
  • Access, alter, or retain another user’s data or assets.
  • Disrupt production services or perform denial-of-service testing.
  • Use social engineering, credential theft, or physical attacks.
  • Demand payment or threaten disclosure.
Email security team
No guaranteed security

No software, device, smart contract, blockchain network, or online service can be guaranteed free from every risk. Security information on this page describes design intent and recommended practice, not a warranty.