Hi there 👋
Rather than making generic assurances, here is a transparent overview of what we do with your data and our product architecture, so you can assess our level of protection for yourself.
Data Management Policy
Waltio does not share or sell customer or user data to third parties. This is documented in our Terms of Service.
Product Architecture
Connection Security
The entire Waltio website and web application uses HTTPS protocol to encrypt data in transit.
Exchange Platform and Cold Wallet Connections
Two connection options are available:
File upload: you download your files directly from your exchanges or wallets and upload them to Waltio. We have no direct access to your accounts.
API connection: we request read-only access only (no transfer or withdrawal permissions). You control the permissions granted. API keys are stored in encrypted form in our database, with strictly controlled decryption access.
Hosting
Client files are stored on Amazon AWS/S3 (accessible only via AWS keys) and encrypted using Amazon KMS (encryption at rest). All servers operate within an isolated AWS Virtual Private Cloud. Data access is only possible through an Auth0-protected gateway.
Authentication
Waltio uses Auth0, a leader in authentication security, with OAuth2. Auth0 handles identity verification and password storage (inaccessible to Waltio). It also protects against credential stuffing, brute force attacks, and detects data breaches from other services.
Banking Data
Card payments are handled by Stripe. Waltio never has access to your banking information.
Anonymity
It is possible to use Waltio completely anonymously, from both Waltio and our partners (authentication, payment, hosting). Approximately 5% of our clients use our services anonymously.
To learn more: Being Anonymous
Questions or recommendations? Contact us at hello@waltio.com.
The Waltio Team.