Security is the foundation, not an afterthought.
Handling other people's generosity is a responsibility we take seriously. Here's how we approach it.
Multi-signature custody
Funds in transit are held under multi-signature control rather than a single point of failure, before being converted and disbursed.
On-chain transparency
Every donation is a public, verifiable transaction. Nothing about where funds moved is hidden from donors or nonprofits.
Least-privilege access
Internal systems that touch donation data are scoped tightly, logged, and reviewed — no standing access by default.
Independent review
We treat security as an ongoing practice, not a one-time checkbox, and welcome responsible disclosure from researchers.
Found a vulnerability?
If you believe you've found a security issue, please report it privately to support@cryptokasih.xyz rather than filing a public issue. We commit to acknowledging reports promptly and will work with you on responsible disclosure.