Security

Security practices for controlled engineering delivery and responsible disclosure.

DappWeb designs access, review, release, and operating controls around the agreed project risk. Public inquiry channels must never be used for secrets or production signing material.

DappWebHong Kong
Legal entityDAPPWEB LIMITED
Company no.78331916
Incorporated18 June 2025
DeliveryRemote service for global teams

01

Delivery security controls

Controls are selected for the engagement risk and documented in scope and handoff evidence.

Access

Client-owned and least privilege

Use organization-owned repositories, cloud accounts, domains, wallets, and deployment identities. Grant only required access, prefer temporary credentials, and revoke access after handoff.

Engineering

Traceable review and release

Bind scope to repository paths and commits, test in reproducible environments, review privileged actions, and separate build, deployment, route verification, and production acceptance.

Operations

Monitoring and response

Define logs, alerts, operating owners, escalation paths, rollback steps, incident evidence, and post-release support before production handoff.

02

Secret and asset handling

DappWeb standard technical services do not require custody of client assets.

Never use the public form for secrets

Do not submit private keys, seed phrases, production credentials, signing shares, API secrets, or recovery codes through the website, email, Telegram, WhatsApp, WeChat, or LinkedIn.

Production authority remains client-owned

Clients should retain production wallets, cloud organizations, DNS, app-store accounts, and final deployment authority. Access arrangements are agreed only when technically necessary.

Security review is scoped

An audit or review covers only the named repositories, commits, contracts, programs, interfaces, environments, assumptions, and dates. Material changes require review of the changed scope.

No unsupported certification claims

This page describes operating practices, not a claim of a specific security certification. Procurement questionnaires and engagement-specific controls can be reviewed during qualification.

03

Responsible disclosure

Report a suspected vulnerability privately so it can be reproduced, contained, and remediated.

How to report

Email admin@dappweb.ai with the affected URL or component, reproduction steps, impact, evidence, and a safe contact method. Use the subject “Security disclosure”.

Safe research expectations

Avoid accessing unrelated data, disrupting services, moving assets, escalating beyond the minimum proof, or publishing details before DappWeb confirms a remediation and disclosure plan.

Send project brief