Client-owned and least privilege
Use organization-owned repositories, cloud accounts, domains, wallets, and deployment identities. Grant only required access, prefer temporary credentials, and revoke access after handoff.
Submit Project Brief
Security
DappWeb designs access, review, release, and operating controls around the agreed project risk. Public inquiry channels must never be used for secrets or production signing material.
01
Controls are selected for the engagement risk and documented in scope and handoff evidence.
Use organization-owned repositories, cloud accounts, domains, wallets, and deployment identities. Grant only required access, prefer temporary credentials, and revoke access after handoff.
Bind scope to repository paths and commits, test in reproducible environments, review privileged actions, and separate build, deployment, route verification, and production acceptance.
Define logs, alerts, operating owners, escalation paths, rollback steps, incident evidence, and post-release support before production handoff.
02
DappWeb standard technical services do not require custody of client assets.
Do not submit private keys, seed phrases, production credentials, signing shares, API secrets, or recovery codes through the website, email, Telegram, WhatsApp, WeChat, or LinkedIn.
Clients should retain production wallets, cloud organizations, DNS, app-store accounts, and final deployment authority. Access arrangements are agreed only when technically necessary.
An audit or review covers only the named repositories, commits, contracts, programs, interfaces, environments, assumptions, and dates. Material changes require review of the changed scope.
This page describes operating practices, not a claim of a specific security certification. Procurement questionnaires and engagement-specific controls can be reviewed during qualification.
03
Report a suspected vulnerability privately so it can be reproduced, contained, and remediated.
Email [email protected] with the affected URL or component, reproduction steps, impact, evidence, and a safe contact method. Use the subject “Security disclosure”.
Avoid accessing unrelated data, disrupting services, moving assets, escalating beyond the minimum proof, or publishing details before DappWeb confirms a remediation and disclosure plan.