VEYRNOX · Security

Security at Veyrnox

Security is not a feature we bolted on — it is the reason VEYRNOX exists. This page documents our security model, cryptography, audit status, bug bounty, disclosure policy, and threat model. If anything here is unclear, email security@veyrnox.com.

Security model

Cryptography summary

Third-party audit status

Audit in progress — coming ahead of Android launch. Contact security@veyrnox.com for status. We will publish the auditor, scope, and full report here when it is complete.

Bug bounty

Bug bounty program launching alongside Android release. Report security issues to security@veyrnox.com in the meantime — we acknowledge within 48 hours and credit responsible disclosure.

Scope

In scope: the Veyrnox iOS and Android wallet applications, on-device key management and Shamir-sharded backup flows, WalletConnect and dApp signature-request handling, transaction simulation, and the veyrnox.com marketing site.

Out of scope: third-party dApps, DEXs, bridges, and smart contracts you do not operate; blockchain networks themselves; social engineering or phishing of Veyrnox staff; and any issue requiring access to another user's device or data.

Rewards, eligibility, and severity tiers will be published with the formal program. Until then, all valid reports are credited.

Responsible disclosure policy

Threat model summary

In scope:

Out of scope:

AI Security Protection tier

AI Security Protection — $19.99/mo, coming soon — sits on top of the wallet's foundational security (Shamir + Secure Enclave + RASP) and adds transaction-level threat intelligence for the dApp, DEX, and cross-chain surface that the foundational layer intentionally treats as out of scope. Ten features ship in this tier and each is described in the honest tech that underlies it, not marketing language:

See Plans & pricing for the full tier.

Data handling

Related

See plans →

Frequently asked questions

Has Veyrnox been audited?

Audit in progress — coming ahead of Android launch. Contact security@veyrnox.com for status.

Does Veyrnox have a bug bounty?

Bug bounty program launching alongside Android release. Report security issues to security@veyrnox.com in the meantime — we acknowledge within 48 hours and credit responsible disclosure.

How do I report a vulnerability?

Email security@veyrnox.com, encrypted with our GPG key. We follow a 90-day coordinated disclosure window and credit reporters unless requested otherwise.

Where is my seed stored?

Default setup does not require a seed phrase. The seed is split via Shamir Secret Sharing into KEK-encrypted shards held on your device (Secure Enclave / StrongBox) and your personal cloud. Veyrnox holds no shard, and compatible seed import remains available when users need it.