Security
Your security is our top priority. Here's how we protect your data and maintain the highest standards of security.
Zero-Knowledge Architecture
We never have access to your private keys or seed phrases. Our service operates on a read-only basis using public blockchain data. You maintain complete control over your assets at all times.
End-to-End Encryption
- All data transmission uses TLS 1.3 encryption
- Sensitive data encrypted at rest using AES-256
- Encrypted backups with customer-managed keys available
Read-Only Access
Pragma operates exclusively with read-only access to public blockchain data. We cannot:
- Execute transactions on your behalf
- Move or access your funds
- Modify your approvals without your signature
- Access your wallet's private keys
Infrastructure Security
- SOC 2 Type II compliant infrastructure
- Regular third-party security audits
- 24/7 monitoring and incident response
- DDoS protection and rate limiting
- Geographically distributed servers for redundancy
Authentication & Access Control
- Two-factor authentication (2FA) available
- Session management with automatic timeout
- IP-based access restrictions available
- Audit logs for all account activities
Incident Response
In the unlikely event of a security incident:
- Immediate notification to affected users
- Transparent communication about the incident
- Rapid mitigation and resolution
- Post-incident analysis and improvements
Security Best Practices for Users
- Enable two-factor authentication on your Pragma account
- Use a unique, strong password
- Verify all security alerts before taking action
- Keep your email account secure
- Report suspicious activity immediately
Responsible Disclosure
We welcome security researchers to help us maintain the highest security standards. If you discover a vulnerability, please report it to:
security@pragma.rip
We offer bug bounties for qualifying vulnerabilities. Please allow us reasonable time to address issues before public disclosure.
Compliance & Certifications
- GDPR compliant for EU users
- CCPA compliant for California residents
- Regular penetration testing by independent firms
- Continuous security monitoring and improvement