Security
Current security posture and pre-launch control commitments.
MoonTap uses email-first authentication, role-based access control, merchant-scoped database policies, service-role-only privileged writes, signed wallet challenges, rate limits, security headers, encrypted provider secrets, and audit events. Production payment and refund switches remain disabled until acceptance controls pass.
Access follows least privilege. Owner and administrator permissions are not interchangeable with developer, support, or viewer access, and sensitive production actions require authenticated, authorized server-side paths.
MoonTap never needs a user's wallet private key or seed phrase. Wallet proofs are signed messages or user-approved transactions. Provider and webhook secrets must remain encrypted and must not appear in logs, support tickets, source control, or browser code.
Suspected unauthorized access, secret exposure, cross-merchant data access, or incorrect payment/refund state is a highest-severity incident. MoonTap's runbook requires containment, evidence preservation, credential rotation, reconciliation, documented recovery, and legally required notices without unreasonable delay.
Independent monitoring, alert routing, vulnerability reporting contact details, periodic access reviews, and funded payment acceptance remain launch gates. This page must not be read as a certification, warranty, bug-bounty offer, or promise that every control is already operational.
