ISO/IEC 27001: certification in progress

Your funds, your control.

Standard cryptography, tested code, and a payment that moves through an order and out to your address instead of sitting somewhere waiting to be lost.

Straight to your wallet

Your funds move through the network, not through our accounts. We hold nothing between transactions: no central pool, no balance sitting in our name.

  • Encrypted in transit and at rest

    Every connection is encrypted. Sensitive fields are stored encrypted. Logs roll on a fixed schedule so your data doesn't outlive its purpose.

  • Isolated signing

    Signing keys are held in an isolated environment, separated from our public systems. They are never exposed to the internet and never leave that environment.

  • Signed webhooks

    Every event we deliver to your server carries a signature tied to your key. Verify it before acting: that's the only way to confirm the event came from us.

  • Compliance screening

    Transactions are checked before execution. Flagged ones are held for manual review, not silently passed through. We cooperate with legitimate law enforcement.

  • Scoped API keys

    Each key carries only the permissions you granted it. Lock it to your server's IP, revoke it any time: the scope of a compromised key is bounded by design.

Where your funds go

Deposit, Check, Swap, Payout. At every step there's a person watching and automated controls helping. That's it.

  1. Deposit We detect your transaction the moment it hits the network.
  2. Check Funds pass automated controls before execution starts.
  3. Swap Your exchange runs without manual intervention.
  4. Payout Funds arrive at the address you specified. Nothing held.

Verifying it's really us

SwapSS communications come from these channels only:

  • Email: support@swapss.lol (DKIM/DMARC verified)
  • Telegram: only via your cabinet's "Connect Telegram" flow. We never message you first
  • In-cabinet notifications and signed webhook events

If someone claims to represent SwapSS through any other channel (DM on social media, phone call, third-party "support" website), it's not us. Forward suspicious contact to support and we'll investigate.

Found a vulnerability?

Report it through our support page. We treat every security report seriously and respond promptly.