Security

Control stays with the user.

This page describes the security principles guiding Cantumi's development. Product, wallet, agent-connection, approval, and transaction features are not yet publicly available, and these statements are not a certification or guarantee of deployed controls.

Last updated August 10, 2026

Design principles

  • Private signing keys should remain under user control rather than being exposed to Cantumi or an AI agent.
  • Agent requests should require explicit user review before any transaction is signed or submitted.
  • Approvals should be bound to the exact transaction data shown to the user.
  • Connections and transaction lifecycle states should be visible and revocable where applicable.
  • Prompts and model outputs should remain off-ledger.

These are development objectives for planned product functionality, not claims that those controls are currently available on the public website.

Pre-launch safety

While Cantumi remains in pre-launch, the public website will not ask you to connect a wallet, approve a transaction, or provide a password, private key, seed phrase, session token, or verification code.

  • Use only pages served from cantumi.cc.
  • Do not send secrets or funds in a support message.
  • Treat any request claiming to offer early wallet or transaction access with caution.

Responsible disclosure

If you believe you found a security vulnerability, email support@cantumi.cc with the subject “Security report.” Include a concise description, affected page or component, reproducible steps, impact, and any safe proof of concept.

Do not include private keys, seed phrases, passwords, session tokens, personal data, or funds in a report.

Safe research

  • Test only systems you own or are explicitly authorized to test.
  • Avoid privacy violations, social engineering, denial of service, destructive tests, automated high-volume traffic, and access to other users' information.
  • Stop testing and report the issue if you encounter sensitive information or can affect another user.
  • Give Cantumi a reasonable opportunity to investigate before public disclosure.

Helpful reports

Reports are most useful when they clearly describe the affected page or component, reproducible steps, expected and observed behavior, and concrete security impact. If the impact is unclear, send the available context and avoid further risky testing.

For general website or project questions that are not security reports, email support@cantumi.cc.