We take security seriously — and we describe it plainly, without marketing seals we don't hold. Here is exactly what we do, and how you can verify it yourself.
A check needs only a public wallet address. We never ask for your seed phrase, private key or a wallet connection (WalletConnect), never call smart contracts and never request a transaction signature. We only read public blockchain data — taking your funds is technically impossible.
object-src 'none'.Our emails (login codes, notifications) are signed and protected from spoofing: SPF, DKIM and
DMARC are configured for amlconsensus.com. This reduces the risk of phishing in our name.
Our only official address is support@amlconsensus.com.
Balance top-ups go through a crypto payment provider (CryptoBot). We do not process or store bank card data — PCI DSS scope does not apply to us.
We follow recognized information-security and secure-development practices: ISO/IEC 27001 (information-security risk management), OWASP ASVS/Top 10 (web app security), least-privilege and data-minimization principles.
⚠️ To be clear: this means we follow these principles. We do not claim to hold an ISO/SOC certificate — if and when we complete a formal audit, we'll post the accredited body's confirmation here, not a made-up seal.
If you found a vulnerability, please tell us — we'll be grateful. Contact and policy: /.well-known/security.txt or email support@amlconsensus.com. Please give us reasonable time to fix before public disclosure.