Security
Last updated: 9 August 2026
The strongest security decision we made was architectural: there is almost nothing here worth stealing. No custody, no private keys, no exchange connections, no card numbers, no identity documents. A breach of Cryp2Nova cannot drain a wallet, because Cryp2Nova cannot reach one.
What the platform never holds
- No private keys or seed phrases. There is no field for one anywhere in the product.
- No exchange API keys. We do not connect to trading accounts at all.
- No card or bank details. Subscriptions settle in stablecoins, so payment instruments never enter the system.
- No identity documents. Nothing to lose in a leak, because nothing was collected.
- No withdrawal path. There is no mechanism by which funds can leave anything — for us or for an attacker.
Accounts and sessions
- Sign-in is delegated to established providers, or to an email and password you set. We never see a provider password.
- Your session is proved by a signed token with a limited lifetime, held in your browser's own storage rather than a cookie — so it is not attached automatically to cross-site requests.
- Every session can be invalidated at once. If you suspect a device is compromised, signing out everywhere makes every previously issued token useless immediately.
- Account events — sign-in, plan change, order created — are recorded, so a disputed action can be checked against a trail.
Payments
- Checkout happens on cryp2nova.com. You are not redirected to a third-party branded page, and the address you are shown is generated for your order alone.
- Payment confirmations reaching our service are cryptographically signed and verified before anything is activated. A forged "payment complete" message does not activate a plan.
- An unfinished order reopens at the same address rather than issuing a second one, which is what stops the most common payment-support mistake from becoming a lost transfer.
Infrastructure
- All traffic is served over TLS.
- The data service is separated from the interface, and access to production systems is restricted to the people who operate them.
- The installable app caches the interface for offline use but never caches market data or API responses — nothing sensitive or stale is kept on your device.
- Dependencies and infrastructure are updated as security fixes are published.
Your part
- Use a unique password if you sign in with one, and protect the account of whichever provider you sign in through — it is the key to this one.
- Sign out everywhere if you lose a device.
- Reach the platform through cryp2nova.com. Check the domain before entering anything.
- Never send funds anywhere except the address shown on the checkout page at the moment you pay. Not an address from an email, a chat message, a screenshot, or a "support agent".
We will never ask for your private key, seed phrase or exchange API key. Ever. We will never ask you to send funds to verify, unlock or claim anything. Our only contact address is [email protected] — anything else claiming to be us is an impersonation attempt.
Reporting a vulnerability
If you find a security issue, tell us before you tell anyone else: [email protected] with "security" in the subject.
- Give us enough to reproduce it, and give us reasonable time to fix it before disclosing.
- Do not run destructive tests, do not touch other people's accounts or data, and do not degrade the service for others.
- We will confirm receipt, keep you updated, and credit you if you want the credit.
If something goes wrong
If a breach ever affects your data, we will tell you what happened, what was exposed, and what to do — directly and without waiting for it to be discovered elsewhere. No system is perfectly secure, and a platform that claims otherwise is telling you something about itself.
الأمان
آخر تحديث: ٩ أغسطس ٢٠٢٦
أقوى قرار أمني اتّخذناه كان معماريًّا: لا يكاد يوجد هنا ما يستحقّ السرقة. لا حفظ أصول، ولا مفاتيح خاصّة، ولا ارتباط بمنصّات، ولا أرقام بطاقات، ولا وثائق هويّة. واختراق Cryp2Nova لا يستطيع استنزاف محفظة، لأنّ Cryp2Nova لا تصل إلى محفظة أصلًا.
ما لا تحمله المنصّة أبدًا
- لا مفاتيح خاصّة ولا عبارات استرداد. لا يوجد حقل لها في أي موضع من المنتج.
- لا مفاتيح واجهات منصّات. لا نتّصل بحسابات التداول إطلاقًا.
- لا تفاصيل بطاقات أو بنوك. فالاشتراكات تُسوّى بالعملات المستقرّة، وأدوات الدفع لا تدخل النظام.
- لا وثائق هويّة. فلا شيء يُفقد في تسريب لأنّ شيئًا لم يُجمع.
- لا مسار سحب. لا توجد آليّة تخرج بها أموال من أي شيء — لا لنا ولا لمهاجم.
الحسابات والجلسات
- الدخول مفوَّض إلى مزوّدين معروفين، أو ببريد وكلمة مرور تضبطها أنت. ولا نرى كلمة مرور مزوّد قطّ.
- تُثبَت جلستك برمز موقَّع محدود العمر، محفوظ في تخزين متصفّحك لا في ملفّ ارتباط — فلا يُرفَق تلقائيًّا بالطلبات العابرة للمواقع.
- يمكن إبطال كل الجلسات دفعةً واحدة. فإن شككت في جهاز، جعل «الخروج من كل الأجهزة» كل رمز أُصدر سابقًا عديم الفائدة فورًا.
- تُسجَّل أحداث الحساب — الدخول وتغيير الخطّة وإنشاء الطلب — ليُتحقَّق من أي تصرّف متنازَع عليه بمراجعة الأثر.
المدفوعات
- الدفع يجري على cryp2nova.com. لا تُحوَّل إلى صفحة تحمل علامة طرف ثالث، والعنوان المعروض لك مولَّد لطلبك وحده.
- تأكيدات الدفع الواصلة إلى خدمتنا موقَّعة تشفيريًّا ويُتحقَّق منها قبل تفعيل أي شيء. ورسالة «اكتمل الدفع» المزوَّرة لا تفعّل خطّة.
- الطلب غير المكتمل يُعاد فتحه على العنوان نفسه بدل إصدار عنوان ثانٍ، وهذا ما يمنع أشيع خطأ في دعم المدفوعات من أن يصير تحويلًا ضائعًا.
البنية التحتيّة
- كل الحركة تُقدَّم عبر TLS.
- خدمة البيانات منفصلة عن الواجهة، والوصول إلى أنظمة التشغيل مقصور على من يشغّلونها.
- التطبيق القابل للتثبيت يخزّن الواجهة للعمل دون اتّصال لكنّه لا يخزّن بيانات السوق ولا استجابات الواجهة البرمجيّة أبدًا — فلا يبقى على جهازك شيء حسّاس ولا قديم.
- تُحدَّث الاعتماديّات والبنية التحتيّة مع صدور الإصلاحات الأمنيّة.
دورك أنت
- استعمل كلمة مرور فريدة إن دخلت بواحدة، واحمِ حساب المزوّد الذي تدخل عبره — فهو مفتاح هذا الحساب.
- اخرج من كل الأجهزة إن فقدت جهازًا.
- ادخل المنصّة من cryp2nova.com، وتحقّق من النطاق قبل إدخال أي شيء.
- لا ترسل أموالًا إلى أي عنوان سوى العنوان المعروض في صفحة الدفع لحظة دفعك. لا عنوانًا من بريد ولا من رسالة ولا من لقطة شاشة ولا من «موظّف دعم».
لن نطلب منك مفتاحك الخاص ولا عبارة الاسترداد ولا مفتاح منصّتك. أبدًا. ولن نطلب منك إرسال أموال للتحقّق أو الفتح أو الاستلام. وعنوان تواصلنا الوحيد [email protected] — وما عداه ممّا يدّعي أنّه نحن فمحاولة انتحال.
الإبلاغ عن ثغرة
إن وجدت مشكلة أمنيّة فأخبرنا قبل أن تخبر غيرنا: [email protected] وضع كلمة «security» في العنوان.
- أعطنا ما يكفي لإعادة إنتاجها، وامنحنا وقتًا معقولًا لإصلاحها قبل الإفصاح.
- لا تُجرِ اختبارات مدمّرة، ولا تمسّ حسابات غيرك ولا بياناتهم، ولا تُضعف الخدمة على الآخرين.
- سنؤكّد الاستلام ونُطلعك أوّلًا بأوّل وننسب الفضل إليك إن أردت.
إن وقع خطب
إن أثّر اختراق يومًا في بياناتك، أخبرناك بما جرى وبما انكشف وبما ينبغي فعله، مباشرةً ودون انتظار أن يُكتشف الأمر من مكان آخر. فلا نظام آمن تمامًا، والمنصّة التي تدّعي غير ذلك تخبرك بشيء عن نفسها.