Security & risk
What we do to reduce risk, what we cannot control, and exactly what you are exposed to when you use DeFi tooling.
Risk disclosure
0
No custody, ever
0
Disabled in this build
0
Audit status below
Explicit only
One action, one prompt
Security center
The four controls that decide whether a Web3 session is safe. Each one is enforced by product design, not by a promise.
No private keys, ever
POEOS has no field, form or API that accepts a seed phrase or private key. Keys never leave your wallet.
Explicit wallet signing
One user action, one signature prompt. No background approvals, no blanket allowances, no silent re-signing.
Contract verification
Deployment checklists require verified source and a public list of every privileged function before launch.
Transaction simulation
Strategy and flash-loan flows are modelled and cost-checked before any execution path could ever be enabled.
Wallet security
- POEOS will never ask for your seed phrase or private key. Nobody legitimate ever will.
- Use a hardware wallet or multisig for anything holding meaningful value or admin authority.
- Keep a separate hot wallet for experimentation; never link your main treasury to a testing session.
- Read every signature request. If the summary does not match what you intended, reject it.
- Revoke stale token approvals regularly — an unlimited approval to a compromised router drains silently.
- Beware of look-alike domains. Bookmark poeos.tech and never reach it via a DM or ad.
Smart contract safety
- Generated code is unaudited. Treat it as a starting point that needs tests, review and an audit.
- Every owner-only function is a permanent trust assumption for holders. Document them publicly.
- Validate caller and initiator in any flash-loan receiver — unguarded callbacks are routinely drained.
- Prefer immutable contracts, or a timelock on upgrades so users can exit before a change lands.
- Test privileged flows on a testnet, including the failure paths, before mainnet.
- Verify source immediately after deployment so anyone can check what they are interacting with.
Audit status
Placeholders are shown honestly rather than implying coverage that does not exist.
| Scope | Status | Firm | Date |
|---|---|---|---|
| POEOS web platform | Internal review | — | Ongoing |
| Contract generator templates | Derived from audited upstream patterns | OpenZeppelin (upstream) | n/a |
| Flash-loan receiver template | Not audited | Placeholder | Not scheduled |
| Token factory contracts | Not deployed | Placeholder | Pre-audit |
| NFT launchpad contracts | Not deployed | Placeholder | Pre-audit |
Terms & privacy summary
POEOS provides software tooling, not investment services. We do not take custody of assets, do not manage portfolios and do not provide advice. Wallet addresses you connect are used to display read-only data; simulation configuration is stored locally in your browser in this build. Access to premium tooling is metered and may be represented as POE credits — a payment mechanism, not a security or a yield product.
Support & disclosure
Report a vulnerability or a suspected phishing site through the security contact at poeos.tech. Include reproduction steps and avoid testing against other users' assets. We respond to credible reports and will publish a disclosure once a fix is live. Support never asks for keys, seed phrases or screen sharing.
security@poeos.tech · support@poeos.tech
Placeholder contacts for this build.