Security Policy
1. Data Protection
User data encrypted at rest (PostgreSQL pgcrypto) and in transit (HTTPS/TLS 1.3).
2. Authentication
Google OAuth + NextAuth. Wallet verification via Coinbase. Sessions JWT (short-lived).
3. Infrastructure
Vercel (edge network), Hetzner VPS (isolated), Postgres (connection pooled). OpenClaw agents sandboxed.
4. Encryption
- RSA-4096 for x402 signatures.
- AES-256 for sensitive fields.
5. Vulnerability Reporting
Report to security@aiindigo.com. Rewards for valid CVEs. 90-day disclosure.
6. Incident Response
24/7 monitoring. Breaches notified within 72h per GDPR.
Contact
security@aiindigo.com. Updated 2026-02-06.