Security

How Bitdash protects your account and your data.

What we will never do

  • Request your seed phrase or private key
  • Store seed phrases or private keys on your behalf
  • Promise guaranteed recovery of blockchain assets
  • Fabricate transactions or pretend unverifiable activity is real

Authentication

Email and password authentication via Supabase Auth, with email verification and optional time-based two-factor authentication.

Access controls

Row Level Security policies isolate every user’s data. Administrative access is role-controlled and enforced in the database.

Audit logging

Security-relevant actions — logins, MFA changes, wallet verifications, recovery updates — are recorded in an audit trail.

Sessions & backup codes

Review and revoke active sessions, sign out everywhere, and manage one-time backup codes for account recovery.

Wallet verification

Wallets are verified by signing a random challenge message with the wallet itself — proving control of the address without exposing anything secret.

Recovery honesty

Recovery cases are reviewed by humans using legitimate ownership-verification workflows. We will not claim an asset is recoverable when it is not.