Security Practices

Last updated: January 1, 2026

This page describes the security controls that are live in Axxion Wallet today and the shared responsibilities between us and you. It is maintained by the Axxion Wallet team and is not an independent audit or certification.

Keys stay on your device

Axxion Wallet is non-custodial. Recovery phrases and private keys are generated on your device and stored in your device's local secure storage. They are never transmitted to our servers, never included in backups we hold, and never visible to our staff. No Axxion employee can move your funds or restore your wallet for you.

Account protection

  • Biometric app lock. Face ID, Touch ID or Android biometrics unlock the app using your device's platform authenticator; the biometric itself never leaves the device and is never sent to us.
  • Auto app lock. Configurable idle timeout that re-locks the app and requires biometrics or your account password.
  • Two-factor authentication. Time-based one-time codes (TOTP) from any authenticator app, enrolled and verified inside Settings.
  • Breach checks. Passwords are hashed and never stored in plain text.

Platform and data protection

  • All traffic is encrypted in transit with TLS 1.2+
  • Data at rest is encrypted by our managed cloud infrastructure provider
  • Row-level access rules ensure each account can only read and write its own records
  • Support attachments live in private storage reachable only via short-lived signed links
  • Administrative access is limited to named staff and logged

Your responsibilities

  • Store your 12-word recovery phrase offline; never type it into any website or chat
  • Enable app lock and two-factor authentication
  • Keep your device OS and Axxion Wallet up to date
  • Review token approvals in Settings and revoke anything you no longer use
  • Treat unexpected DMs, giveaways and "support agents" as scams — we never DM first

Responsible disclosure

Found a vulnerability? Email security@axxionpocket.com with steps to reproduce. We acknowledge reports within 72 hours, will not pursue legal action against good-faith research, and ask that you avoid accessing other users' data or degrading the service while testing.

Incident response

If an incident affects your personal data, we notify affected users and applicable regulators without undue delay and within the timelines required by law, and publish remediation steps.

Related: Privacy Policy, Account & Data Deletion, Child Safety Standards.