Security
Facts about how Pooli is designed. This is not a certification or a guarantee of uptime.
Security
- Non-custodial: Pooli does not hold seller funds and never stores seed phrases or private keys.
- Token contracts are allowlisted per network.
- Payable amounts use unique integer matching per destination, network, token, and active reservation.
- Only server-side verification can mark a payment Paid ✓.
- Chain event ingest is idempotent.
- Customer checkout data is scoped to the owning merchant (and admin support).
- Public endpoints are rate-limited.
Responsible disclosure
If you believe you found a security issue, email support@pooli.shop with enough detail to reproduce it. Include omid@pooli.shop as a secondary contact if support is unreachable. We aim to acknowledge new reports within 5 business days.