Security

Built with the same evidentiary standard we apply to wallets.

VikingIntel handles investigation data for security teams, compliance teams, and protocols. The platform is built to a corresponding standard of access control and auditability.

Hashed API keys

API keys are hashed at rest. VikingIntel never stores or logs a usable copy of your key.

Centralized auth

Every API route authenticates through a single, centrally enforced request path — not per-route logic that can drift.

Access-scoped resources

Cases, watchlists, and saved queries are scoped to the account that created them, with ownership checked on every request.

Rate limiting

Usage is rate-limited atomically per key, so a spike in one integration can’t exhaust another tier’s throughput.

Evidence boundaries

How VikingIntel handles public-source evidence.

VikingIntel enriches investigations with publicly available information. This section explains how that evidence is handled.

VikingIntel collects evidence from publicly available sources — project websites, domain records, public repositories, and public platform profiles.
Every piece of evidence preserves its source, collection timestamp, and provenance. Staleness is flagged when data is more than 30 days old.
On-chain facts and public-source findings are kept separate. A website mention is not treated the same as a blockchain transaction.
VikingIntel does not expose private workspace information publicly. Cases, evidence, and investigations are scoped to the account that created them.
Responsible disclosure

Found a security issue?

Please report it privately rather than opening a public issue — email gets the fastest response. Include reproduction steps and affected URLs where possible; we investigate and respond to every credible report.

security@vikingintel.xyz

Questions about security?

Non-vulnerability questions about data handling, access control, or integration security — reach out before you integrate at scale.