Security

How Awaken protects your data, your credentials, and your privacy.

Our commitment

You trust Awaken with a detailed picture of your financial life, and we take that responsibility seriously. Security is one of the largest investments we make each year, funding independent audits, professional testing, and the tooling that protects your data around the clock.

Your wallet stays yours

Awaken works from your transaction history, so read access is all we ever need. That principle shapes everything about how the product connects to your accounts.

We never ask for your keys

Private keys and seed phrases have no place in Awaken. No screen, email, or support conversation will ever request them.

We never ask you to sign

Awaken will never ask you to sign a transaction with your wallet. Connecting a wallet means sharing an address, nothing more.

We can never move funds

Nothing you connect to Awaken gives us the ability to move assets or place trades. We only ever see what happened, not control what happens next.

How your data is protected

Everything moving between you and Awaken is encrypted in transit, and everything we store is encrypted at rest. The most sensitive information gets a second layer of encryption at the application level using AES-256, the same standard banks rely on.

What we holdHow it is protected
Exchange credentialsEncrypted the moment they arrive, never stored or logged in plain text
Personal detailsEncrypted at rest, and we only collect what the product actually needs
Tax reports and filesEach file is individually encrypted before it is stored
Awaken API keysYour key is shown once, then even we cannot recover it
Deleted accountsYour personal information is anonymized and removed when you delete your account

Network protection

Our infrastructure sits behind layered firewalls that block everything except the traffic our products actually need. The internal services that hold our most sensitive credentials run on a private network with no route to the public internet, and even our own application servers must authenticate to reach them. Rate limiting and bot detection protect any public facing infrastructure.

A small, trusted team

Most security incidents start with a person, not a server, and attackers know it. So we treat our team as part of the security perimeter, not an exception to it.

Small by design

We keep the team deliberately small, so access to your data stays in the hands of a few highly trusted people.

Background checks

Everyone who joins Awaken completes a background check before they touch anything.

Need to know access

Each person can reach only the systems and information their role actually requires. Nobody has access simply because they work here.

Independent validation

We do not grade our own homework. Awaken maintains SOC 2 compliance, which means an independent auditor regularly examines our security controls and how consistently we follow them. We also run recurring penetration tests against our systems, and we fix what they find.

For that offensive testing we partner with Groom Lake, a firm whose operators come out of intelligence, military, and defense environments where the adversaries are far more serious than the average attacker. Those backgrounds shape what they look for and how hard they push, and it is exactly why we chose them.

How changes ship

Awaken changes every day, so the process that moves code into production is a security control in itself.

Reviewed by a person

Like most modern teams, we use AI to help write code. A real engineer reviews and tests every change before it reaches production.

Proven before production

Every change has to survive a rigorous suite of automated tests.

Scanned automatically

Every change is scanned for security related findings before it ships. We use multiple scanners including modern AI powered security tools that catch the subtle issues traditional scanners miss.

How to protect your account

We handle the infrastructure, but a few habits on your side make your account far harder to attack.

Turn on two-factor authentication

A second factor means a stolen password alone is not enough to get in. Enable it in your account settings.

Use a strong, unique password

Let a password manager generate and remember it. A password reused from another site is only as safe as that site.

Keep API keys read-only

Create read-only keys by default and reach for write access only when a task truly needs it, always with an expiration date. Revoke any key you no longer use.

Watch for phishing

Double check links and sender addresses claiming to be Awaken. Remember, we will never ask for your password, private keys, or seed phrase.

When in doubt, ask

If a message feels off or you are unsure whether something is really from us, reach out before acting. We would much rather answer a false alarm than miss a real one.

Questions or concerns

If you have a security question, or believe you have found a vulnerability, contact us through the support page and mention security. Alternatively message @andrew_duca on Telegram.