Security
How Awaken protects your data, your credentials, and your privacy.
Our commitment
You trust Awaken with a detailed picture of your financial life, and we take that responsibility seriously. Security is one of the largest investments we make each year, funding independent audits, professional testing, and the tooling that protects your data around the clock.
Your wallet stays yours
Awaken works from your transaction history, so read access is all we ever need. That principle shapes everything about how the product connects to your accounts.
We never ask for your keys
Private keys and seed phrases have no place in Awaken. No screen, email, or support conversation will ever request them.
We never ask you to sign
Awaken will never ask you to sign a transaction with your wallet. Connecting a wallet means sharing an address, nothing more.
We can never move funds
Nothing you connect to Awaken gives us the ability to move assets or place trades. We only ever see what happened, not control what happens next.
How your data is protected
Everything moving between you and Awaken is encrypted in transit, and everything we store is encrypted at rest. The most sensitive information gets a second layer of encryption at the application level using AES-256, the same standard banks rely on.
| What we hold | How it is protected |
|---|---|
Exchange credentials | Encrypted the moment they arrive, never stored or logged in plain text |
Personal details | Encrypted at rest, and we only collect what the product actually needs |
Tax reports and files | Each file is individually encrypted before it is stored |
Awaken API keys | Your key is shown once, then even we cannot recover it |
Deleted accounts | Your personal information is anonymized and removed when you delete your account |
Network protection
Our infrastructure sits behind layered firewalls that block everything except the traffic our products actually need. The internal services that hold our most sensitive credentials run on a private network with no route to the public internet, and even our own application servers must authenticate to reach them. Rate limiting and bot detection protect any public facing infrastructure.
A small, trusted team
Most security incidents start with a person, not a server, and attackers know it. So we treat our team as part of the security perimeter, not an exception to it.
Small by design
We keep the team deliberately small, so access to your data stays in the hands of a few highly trusted people.
Background checks
Everyone who joins Awaken completes a background check before they touch anything.
Need to know access
Each person can reach only the systems and information their role actually requires. Nobody has access simply because they work here.
Independent validation
We do not grade our own homework. Awaken maintains SOC 2 compliance, which means an independent auditor regularly examines our security controls and how consistently we follow them. We also run recurring penetration tests against our systems, and we fix what they find.
For that offensive testing we partner with Groom Lake, a firm whose operators come out of intelligence, military, and defense environments where the adversaries are far more serious than the average attacker. Those backgrounds shape what they look for and how hard they push, and it is exactly why we chose them.
How changes ship
Awaken changes every day, so the process that moves code into production is a security control in itself.
Reviewed by a person
Like most modern teams, we use AI to help write code. A real engineer reviews and tests every change before it reaches production.
Proven before production
Every change has to survive a rigorous suite of automated tests.
Scanned automatically
Every change is scanned for security related findings before it ships. We use multiple scanners including modern AI powered security tools that catch the subtle issues traditional scanners miss.
How to protect your account
We handle the infrastructure, but a few habits on your side make your account far harder to attack.
A second factor means a stolen password alone is not enough to get in. Enable it in your account settings.
Let a password manager generate and remember it. A password reused from another site is only as safe as that site.
Create read-only keys by default and reach for write access only when a task truly needs it, always with an expiration date. Revoke any key you no longer use.
Double check links and sender addresses claiming to be Awaken. Remember, we will never ask for your password, private keys, or seed phrase.
If a message feels off or you are unsure whether something is really from us, reach out before acting. We would much rather answer a false alarm than miss a real one.
Questions or concerns
If you have a security question, or believe you have found a vulnerability, contact us through the support page and mention security. Alternatively message @andrew_duca on Telegram.