Developer Preview. Sendy-Wave is currently developing software architecture for conditional trade settlement. The platform is in active development and not yet available for commercial transactions. See current status.
Sendy Wave Bond

Security Review

Security

Architecture review posture and vulnerability reporting process.

Scope

The only asset in scope is this website: a static site served by Cloudflare Pages, plus a single serverless function that forwards contact form submissions to an email address. There is no live production application, database of user records, authentication system, or active API currently deployed.

Current posture

In its current specification stage, this static site is intentionally minimal with no active user accounts, databases, or third-party tracking scripts to eliminate attack surface. Formal independent code audits and security reviews will precede any live or connected software release.

The site is served over HTTPS only, with HSTS and modern Content Security Policies. It loads no analytics, no tracking pixels, no advertising, and no third-party libraries. The interactive simulator runs client-side in the browser and transmits no data.

Reporting a vulnerability

Email support@sendy-wave.bond with enough detail to reproduce the issue. A machine-readable version of this contact is published at /.well-known/security.txt per RFC 9116.

We acknowledge valid security inquiries within five business days. We will not pursue legal action against anyone who reports an issue in good faith, and we are glad to credit you publicly for responsible disclosures.

Please do not run high-volume automated vulnerability scanners against this informational site.