Trust

Security

Last updated ·

How to report a security problem to us, who processes data on our behalf, and the security practices we can show. Every statement on this page was checked against the running configuration. Where we have nothing to show, we make no claim.

Responsible disclosure

If you find a security weakness in ByKaranteli, please tell us privately before anyone else. We would much rather hear about a problem from you than from an attacker.

  • Scope: bykaranteli.com and every page under it, the API under bykaranteli.com/api, and the hosted MCP server at mcp.bykaranteli.com. The services listed in the next section run their own reporting channels.
  • By design: the authorization server of the hosted MCP server accepts OAuth client registration without authentication (RFC 7591), because that is how MCP clients connect. Creating a client grants nothing. Access exists only after a signed-in member approves the app on our consent page, which shows the address the member is sent back to. Open registration on its own is therefore not a finding; a way around that consent step is.
  • How to report: email support@bykaranteli.com with the affected URL, the steps to reproduce and what an attacker could gain. The same address is published in our security.txt file.
  • What not to do: do not access, copy or change data that is not yours, do not degrade the service for others (load tests, denial of service, spam), and do not use another person's account. Test with an account you own and stop as soon as you have shown the problem.
  • Safe harbour: if you act in good faith and follow these rules, we will not take legal action against you for your research, and we will work with you to understand and fix the issue.
  • Response: we aim to reply within five business days, tell you whether we could reproduce the issue, and keep you informed until it is fixed. Please give us reasonable time to fix it before you disclose it publicly.
  • Recognition: there is no paid bounty programme; we credit reporters who want it.

Who processes data for us

The same third parties as in our Privacy Policy, in the same order. Each one sees only what its role needs.

  • Cloudflare, as CDN and security layer in front of the site. It processes IP addresses and request metadata for every visit.
  • Google Analytics 4, for aggregate traffic measurement, and only if you accept it in the consent banner.
  • Google, only if you choose to sign in with Google: your Google account identifier, your email address and whether Google has verified it.
  • Hostinger, our email provider, for verification, sign-in links, alerts and digests you have asked for. It sees your email address and the message.
  • Telegram, only if you link it: the alerts you set up are delivered to the chat you linked.
  • Your browser's push service, run by the browser vendor, only if you turn on push notifications: it relays the alert to your device.
  • Coinbase, if you buy USDC through Coinbase Onramp, and Coinbase Developer Platform as the facilitator of pay-per-call (x402) payments, which sees the paying address, the amount and the route paid for.
  • Blockchain RPC providers we query to confirm payments. They see the public addresses and transactions we look up, never your account.
  • GitHub, which stores our weekly database backups in a private repository. Each backup is encrypted on our server before upload (AES-256, key kept only on our server), so GitHub holds ciphertext it cannot read.
  • Market data sources such as exchanges and public data providers. They receive requests from our servers, not from your browser, so they see no personal data.

Practices we can show

  • HTTPS only. Plain HTTP requests are redirected, bykaranteli.com is on the HSTS preload list that browsers ship with, and every page is served with a Content Security Policy.
  • The origin server answers only Cloudflare: every HTTPS host on it requires Cloudflare's client certificate (mutual TLS), and it does not announce its software version.
  • Session tokens and API keys are stored only as SHA-256 hashes, so the value in your cookie or your key does not exist in our database. Passwords are hashed with argon2id.
  • Nothing here can trade for you: the product never asks for an exchange API key and holds no funds.
  • Email for bykaranteli.com is protected by DMARC at p=reject, MTA-STS in enforce mode and TLS reporting (TLS-RPT).
  • Internal security reviews of the code and the infrastructure on 16 August, 4 September, 17 September, 23 September and 26 September 2026. These are our own reviews, not external audits.
  • No container runs in privileged mode, and every application container drops all Linux capabilities and cannot gain new privileges.

What we do not hold

  • Exchange API keys. We never ask for them and there is nowhere in the product to enter one.
  • Custody of funds. We hold no assets on your behalf.
  • Card or bank details. Subscriptions settle on chain, so no payment card ever reaches us.
  • Your IP address inside product analytics. That table is deliberately IP-free.

Contact

Security reports and questions: support@bykaranteli.com. The machine-readable contact file is at https://bykaranteli.com/.well-known/security.txt.