Non-Custodial by Design
Conxian Labs never takes custody of user assets or signing control. All key material remains under user sovereignty. The SDK enforces this at the cryptographic boundary.
Conxian Labs applies institutional-grade security engineering across all production surfaces. Our infrastructure is built for auditability — every component is open-source, every build is reproducible, and every deployment is verifiable.
Conxian Labs never takes custody of user assets or signing control. All key material remains under user sovereignty. The SDK enforces this at the cryptographic boundary.
All production artifacts are built deterministically. Any party can verify that deployed binaries match published source code. Build pipelines are public and auditable.
Critical cryptographic paths undergo formal verification. Protocol state transitions are modeled and verified against specification before deployment.
Enterprise deployments leverage Android StrongBox, Apple Secure Enclave, and dedicated HSM infrastructure for key generation and signing operations.
Dependency trees are pinned, hashed, and reviewed. All third-party code is vendored and audited before integration. SBOMs are published with every release.
Dedicated security response team with defined SLAs. Critical vulnerabilities are addressed within 24 hours of confirmed report.
We maintain a public bug bounty program for responsible disclosure of security vulnerabilities across all Conxian Labs infrastructure.
All public repositories under github.com/Conxian, the conxian-labs.com domain, and published SDK binaries are in scope.
Submit findings to [email protected]. Please include reproduction steps affected component, and impact assessment.
Initial acknowledgment within 48 hours. Triage and severity assessment within 5 business days. Critical fixes deployed within 24 hours of confirmed report.
Independent security audits are commissioned for all major protocol components and infrastructure releases.
/audits directory.If you discover a security vulnerability, please report it responsibly: