Security First, Always
Permara combines zero-knowledge cryptography, multi-layer defense, and autonomous monitoring to create a security system that protects your assets without compromising your privacy.
Our Security Principles
Five core principles guide every security decision we make.
Zero-Knowledge by Default
Sensitive data never leaves user control. We use ZK proofs for verification without exposing raw data.
Defense in Depth
Multiple security layers at every level - from smart contracts to infrastructure to user authentication.
Autonomous Monitoring
AI-powered threat detection monitors transactions 24/7 for unusual patterns and anomalies.
Privacy-Preserving Compliance
Regulatory compliance without data exposure. KYC verification without storing sensitive documents.
User Sovereignty
You maintain full control of your assets. Non-custodial architecture means your keys, your crypto.
Comprehensive Protection
Multiple layers of security protect every aspect of the platform.
Smart Contract Security
- Formal verification of critical logic
- Role-based access control (RBAC)
- Emergency pause mechanisms (circuit breakers)
- Reentrancy protection
- 48-hour timelock for upgrades
Wallet Security
- Three-factor authentication (device, PIN, biometric)
- Secure Enclave / KeyStore key storage
- HD wallet with BIP-39 recovery
- Social recovery options
- Transaction signing with biometric confirmation
Infrastructure Security
- DDoS protection via Cloudflare
- Web Application Firewall (WAF)
- TLS 1.3 with certificate pinning
- AES-256 encryption at rest
Privacy Protection
- Zero-knowledge proofs for verification
- No storage of personal documents
- Encrypted database fields
- GDPR and CCPA compliant
- Right to erasure supported
Responsible Disclosure
We welcome reports from security researchers and respond to every submission. A formal bug bounty program with published reward tiers is planned; until then, rewards for significant findings are handled case by case.
Report vulnerabilities to security@permara.com
Security Best Practices
Follow these guidelines to keep your account secure.
Do
- Enable biometric authentication
- Keep recovery phrase offline
- Use a strong, unique PIN
- Verify transaction details before confirming
- Keep the app updated
- Enable all security features
Don't
- Share your recovery phrase with anyone
- Use public WiFi for large transactions
- Disable security features
- Install unofficial or modified apps
- Ignore security alerts
- Reuse passwords across services
Security Questions?
Our security team is available to answer any questions about how we protect your assets.