Security First
At Matchr, security isn’t an afterthought—it’s foundational. We handle sensitive financial data and user funds, so we’ve built our infrastructure with security at every layer.Non-Custodial by Design — We never have access to your funds. Your assets are held in your own Safe smart contract wallet.
Wallet Security
Safe Smart Contracts
Your trading wallet is a Safe (formerly Gnosis Safe), the most battle-tested smart contract wallet in crypto.$100B+ Secured
Safe secures over $100 billion in digital assets across the ecosystem.
Audited
Multiple security audits by top firms including OpenZeppelin.
Proxy Architecture
Upgradeable contracts allow security patches without fund migration.
Self-Custody
Only you control your Safe. We cannot access your funds.
Your Keys, Your Coins
Authentication
Privy Integration
We use Privy for secure authentication, supporting:- Social Login — Twitter, Discord, email with secure embedded wallets
- External Wallets — MetaMask, Coinbase Wallet, Rainbow, WalletConnect
Session Security
- JWT tokens with short expiration
- Secure HTTP-only cookies
- Automatic session invalidation on suspicious activity
- Multi-device session management
Wallet Verification
Every action requiring authentication verifies wallet ownership:API Security
Authentication
All API requests require authentication via:- API Keys — For server-to-server communication
- Bearer Tokens — For user-authenticated requests
Rate Limiting
Aggressive rate limiting prevents abuse:| Endpoint Type | Rate Limit |
|---|---|
| Public | 100/min |
| Authenticated | 1,000/min |
| Agent | 10,000/min |
| Trading | 100/min per market |
Input Validation
All inputs are validated and sanitized:- SQL injection prevention via parameterized queries
- XSS prevention via output encoding
- Request body size limits
- Type validation on all parameters
Infrastructure Security
Architecture
Hosting & Network
- Vercel — Enterprise-grade hosting with automatic scaling
- Supabase — SOC2-compliant database hosting
- Cloudflare — DDoS protection and WAF
- VPC isolation — Backend services in private networks
Data Encryption
| Data Type | Encryption |
|---|---|
| In Transit | TLS 1.3 |
| At Rest | AES-256 |
| API Keys | Argon2 hashed |
| Secrets | Encrypted environment variables |
Smart Contract Security
Polymarket Integration
We integrate with Polymarket’s audited contracts:- CTF Exchange — Conditional token framework
- CLOB — Central limit order book
- Proxy Wallets — Safe-based trading wallets
Our Contracts
Any smart contracts we deploy undergo:- Internal Review — Code review by multiple engineers
- External Audit — Third-party security audit
- Bug Bounty — Public bounty program
- Staged Rollout — Testnet → Limited mainnet → Full release
Operational Security
Team Practices
- Principle of Least Privilege — Minimal access by default
- Multi-Factor Authentication — Required for all team accounts
- Hardware Security Keys — For critical infrastructure access
- Regular Access Reviews — Quarterly permission audits
Incident Response
We have documented procedures for:- Detection — Automated monitoring and alerting
- Containment — Immediate isolation of affected systems
- Investigation — Root cause analysis
- Recovery — Service restoration
- Post-Mortem — Public disclosure (when appropriate)
Monitoring
- 24/7 Uptime Monitoring — Automatic alerts on anomalies
- Security Event Logging — All access attempts logged
- Anomaly Detection — ML-based unusual activity detection
- Regular Penetration Testing — External security assessments
User Responsibilities
While we implement robust security, users should also follow best practices:Protect Your Wallet
Never share your seed phrase or private keys. We will never ask for them.
Verify URLs
Always access Matchr via matchr.xyz. Bookmark it and check for HTTPS.
Review Transactions
Before signing, verify the transaction details match your intent.
Secure Your Email
Use a strong, unique password and 2FA on your email (if using email login).
Phishing Prevention
We will never:- Ask for your seed phrase or private key
- Send unsolicited DMs asking you to connect your wallet
- Offer airdrops that require wallet connections
- Ask for payments to “unlock” features
Bug Bounty
Program Overview
We reward security researchers who responsibly disclose vulnerabilities.| Severity | Reward |
|---|---|
| Critical | 25,000 |
| High | 5,000 |
| Medium | 2,000 |
| Low | 500 |
In Scope
- matchr.xyz web application
- api.matchr.xyz endpoints
- Smart contracts deployed by Matchr
- Authentication and session management
Out of Scope
- Third-party services (Polymarket, Kalshi, Privy)
- Social engineering attacks
- Denial of service attacks
- Issues requiring physical access
Reporting
Report vulnerabilities to security@matchr.xyz with:- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any proof-of-concept code
Compliance
Data Protection
- GDPR Compliant — EU user data rights respected
- Data Minimization — We only collect necessary data
- Right to Deletion — Request account and data deletion anytime
- Transparent Privacy Policy — Clear explanation of data use
Financial Regulations
- We operate as a technology provider, not a financial institution
- We do not provide financial advice
- We comply with applicable laws in our operating jurisdictions
- Users are responsible for their own tax obligations
