Orixa

Orixa Security

Orixa applies layered controls to its AI crypto security platform, account system, Smart Contract Scanner, monitoring workflows, and billing integrations. Security controls reduce risk, but no internet service or blockchain analysis can guarantee complete protection.

Account and access protection

Application and transport security

Production deployment is configured for HTTPS, HSTS, restrictive browser security headers, canonical-host redirects, and protected internal APIs. Content Security Policy limits executable and embedded resources while retaining compatibility with Google Sign-In and approved analytics.

Billing and integrations

Payment credentials remain server-side. Billing webhooks are authenticated before they can modify plan entitlements. Provider keys and operational secrets are loaded from the deployment environment rather than exposed to the browser.

Security of analysis results

Token Risk Analysis, Rug Pull Detection, and crypto scam detection are evidence-based assessments, not guarantees. Missing or degraded blockchain providers are treated as unavailable evidence instead of being silently converted into safe signals.

Responsible vulnerability reporting

Send a clear description, affected endpoint, reproduction steps, and expected impact to [email protected]. Do not access other users’ data, disrupt production, or include live credentials, private keys, or seed phrases.

For account incidents, revoke active sessions where possible, change your password, enable two-factor authentication, and contact Orixa support.