Security
Last updated: 31 July 2026
1. Your connection to this site
All traffic between your browser and this site travels encrypted with TLS. You can check it in the address bar: the address begins with `https://` and your browser shows the secure-connection indicator.
The site is served with security headers that limit what may execute on the page and where content may be loaded from, so that a third party cannot inject code or foreign resources.
2. No third parties
This site loads no scripts, fonts or resources from third-party servers, and uses no cookies. That narrows the attack surface to what we control: every third-party script is a door somebody else can open.
3. The Xatoxi network
The security of this website and that of the Xatoxi network are different things. The network uses Cuetum, our cryptographic layer, aligned with NIST's final post-quantum standards — FIPS 203 — and with HQC, selected in 2025.
The secure channel between nodes performs key exchange on that basis and renews keys continuously (*forward secrecy*), so that compromising one key does not allow the earlier history to be decrypted.
You can read a full explanation in the Quantum 101 module of the Learn section.
4. What we will never ask you for
We will never ask you by email, message or phone for your password, your private key, your recovery phrase or any verification code.
Nobody from Xatoxi will ever ask you for remote access to your device, or to install software to “fix an incident”. If you receive such a request it is fraudulent: do not respond, and let us know.
Our official domain is xatoxi.com. Be wary of any link taking you to a different address, however similar it may look.
5. Reporting vulnerabilities
If you have found a vulnerability in this site or in any of our systems, we want to hear about it. We ask that you report it privately before making it public, and that you give us a reasonable period to fix it.
You can reach us through the contact form on this site, stating that it is a security matter. Responsible reports are appreciated.
6. Your part
Keep your browser and operating system up to date, do not reuse passwords across services, and turn on two-step verification wherever it is available.
And remember something cryptography cannot solve for you: in a decentralized system there is no administrator who can give you back a lost key. Keep your keys and recovery phrases the way you would keep the deeds to your house.