Trust & Assurance

Security

Conxian Labs applies institutional-grade security engineering across all production surfaces. Our infrastructure is built for auditability — every component is open-source, every build is reproducible, and every deployment is verifiable.

Security Architecture

Non-Custodial by Design

Conxian Labs never takes custody of user assets or signing control. All key material remains under user sovereignty. The SDK enforces this at the cryptographic boundary.

Reproducible Builds

All production artifacts are built deterministically. Any party can verify that deployed binaries match published source code. Build pipelines are public and auditable.

Formal Verification

Critical cryptographic paths undergo formal verification. Protocol state transitions are modeled and verified against specification before deployment.

Hardware Security Modules

Enterprise deployments leverage Android StrongBox, Apple Secure Enclave, and dedicated HSM infrastructure for key generation and signing operations.

Supply Chain Integrity

Dependency trees are pinned, hashed, and reviewed. All third-party code is vendored and audited before integration. SBOMs are published with every release.

Incident Response

Dedicated security response team with defined SLAs. Critical vulnerabilities are addressed within 24 hours of confirmed report.

Bug Bounty Program

We maintain a public bug bounty program for responsible disclosure of security vulnerabilities across all Conxian Labs infrastructure.

Scope

All public repositories under github.com/Conxian, the conxian-labs.com domain, and published SDK binaries are in scope.

Reporting

Submit findings to [email protected]. Please include reproduction steps affected component, and impact assessment.

Response SLA

Initial acknowledgment within 48 hours. Triage and severity assessment within 5 business days. Critical fixes deployed within 24 hours of confirmed report.

Audit Reports

Independent security audits are commissioned for all major protocol components and infrastructure releases.

Audit reports are published to github.com/Conxian alongside each major release. For the latest audit artifacts, refer to the relevant repository's /audits directory.

Responsible Disclosure

If you discover a security vulnerability, please report it responsibly:

  1. Email [email protected] with detailed findings
  2. Allow 90 days for remediation before public disclosure
  3. Do not exploit the vulnerability beyond what is necessary to demonstrate impact
  4. Do not access, modify, or delete user data without explicit authorization