Security
Security You Can Inspect, Not Just Trust.
Most platforms ask you to take their word for it. We would rather show the work: what is live today, how keys stay with you on a non-custodial path, and how to report a vulnerability.
The key model
Designed so Prospr is not in the custody path.
The product being built is a non-custodial interface. You connect a wallet you already control, you hold the keys, and Prospr sits outside the custody path entirely.
- 01
Prospr does not hold your keys
You connect an external wallet you already control. No Prospr-held key share. We cannot withdraw on your behalf. If you lose the wallet, we cannot restore it.
Specified - 02
Off-platform moves need your signature
A withdrawal is a normal non-custodial send, presented in the app. It should fail closed unless you approve it in the wallet.
Specified - 03
Fiat, if offered, is a partner’s rail
Buying or selling for fiat is intended to run through a licensed partner. That partner is not named until contracted. Their licence is not ours, and their KYC is theirs.
Planned
Why there is no reserve proof
Proof of reserves is a custodial tool. This is not a custodial product.
Reserve proofs exist to show a platform still holds what it says it holds. On this path Prospr is not holding your assets, so there is nothing honest to attest in that form.
What you can inspect instead is the wallet you connected, the transaction hash on a withdrawal, and, when they exist, the audits of any Prospr contracts that sit in the path. Until those audits exist, we will not pretend they do.
If we do not hold it, we will not publish a proof that we do.
Wallet and session controls
Controls that match a connected wallet, not a custodial login.
These controls are specified for launch. The prototype may only model them. Live enforcement arrives with a real wallet connection, not before.
- 01
Connect wallet
The live product is intended to start with an external wallet you already control. Connecting it is the entry action. Prospr does not hold that wallet’s keys.
- 02
Disconnect and session end
You can disconnect the wallet. Closing the session, or disconnecting from the wallet app itself, is intended to end the link. A stale “connected” state should not survive a real disconnect.
- 03
Withdrawal signature
Sending assets off-platform is intended to require a fresh confirmation in your wallet. Trading inside the app may use a permission you already granted. Withdrawing should not.
- 04
Official channels
Prospr communicates only from prospr.co addresses. We will not DM you first, ask for your seed phrase, or ask you to send funds to “verify” an account.
Controls reduce risk. They do not eliminate it. A signed transaction you did not mean, or a seed phrase you lose, is not something Prospr can undo.
Infrastructure
Unglamorous, load-bearing.
Items marked planned are commitments scheduled before launch, not live controls.
- 01
Encryption in transit
All production traffic is served over TLS.
- 02
Least-privilege access
Internal access is scoped to what a role needs. Company treasury movements are designed to require more than one person. That is about Prospr’s own funds, not yours.
- 03
Rate limiting & monitoring
Public endpoints are rate limited and monitored for abuse patterns, with alerting on anomalies.
- 04
Minimal data by design
Today we hold at most your email address. Preferences like theme stay in your browser. Data we do not collect cannot leak.
- 05
Independent review — planned
External penetration testing and code review are planned before launch, then on a recurring cycle. No formal security certification is held today, and we will name one only when it is held.
- 06
Public incident record — planned
A public status page with uptime and incident history is planned for launch, and will be the record we use to disclose anything that affects users.
Responsible disclosure
Found something? Tell us.
Coordinated disclosure is welcomed. Email security@prospr.co with reproduction steps and we will respond, keep you updated, and credit you if you would like.
Please avoid accessing other users' data or degrading the service while testing. Good-faith research conducted that way will not be met with legal threats. We do not run a paid bug bounty yet. A funded program is planned and budgeted ahead of launch.
Read /.well-known/security.txtOfficial channels
Impersonation is the cheapest attack there is. Prospr communicates only from prospr.co addresses. We will not DM you first, ask for your password, seed phrase, or 2FA codes, or ask you to send funds to "verify" an account.
Prospr is pre-launch: the product is a demonstration, no customer funds are held, and no licences or registrations are held today. Nothing on this page is a claim of current regulation or a guarantee of security outcomes. See our Risk Disclosure.
Keep inspecting
Security is one surface. Diligence is the rest.
Review regulatory status and the legal library on their own pages.