SECURITY

Simple for groups. Serious underneath.

These are architectural commitments for the product under development—not a claim that unreleased financial systems have completed review.

Passkey-first access

The planned default uses platform passkeys and device verification rather than passwords or consumer-managed seed phrases.

Private expense records

Group details, receipts, participants, and ordinary splits stay off-chain and are restricted to authorized membership.

Explicit authority

Individual, admin, and group-controlled actions have separate permission models. High-risk group actions require member approvals.

Immutable accounting

Financial balances are designed around double-entry journal records, idempotent workflows, and reconciliation—not direct balance mutation.

Provider isolation

SocketFi, card, funding, CCTP, and wallet capabilities sit behind narrow interfaces so one provider does not own core accounting logic.

Safe observability

Structured logs, request IDs, metrics, and audit records are designed to redact credentials, card data, private keys, and KYC documents.

Responsible vulnerability disclosure

Email security@paktly.io with a description, affected URL or component, reproduction steps, and impact. Do not access another person’s data, move funds, degrade availability, use social engineering, or publish details before we have had a reasonable opportunity to investigate.

We will acknowledge good-faith reports when operationally possible. This page does not create a bug-bounty promise, safe-harbor agreement, or authorization to test third-party providers.

Before any real money