The shortest possible answer to 'is SpotX safe to plug into my desk?' — yes, because we're a read-only data service that never touches keys, funds, or signatures.
No custody, ever
SpotX never requests, receives, or holds customer keys, funds, or wallet signatures.
Public data only
We exclusively process on-chain data that is publicly available and broadcast.
Hardened infrastructure
AWS GovCloud-equivalent posture: VPC isolation, KMS encryption at rest, mTLS internally.
Independent audit on roadmap
We're building toward a third-party security audit. Until then, our posture, sub-processors and incident history are documented openly below.
Data minimization
We collect the minimum customer data required (email, billing). No tracking, no third-party advertising pixels.
Responsible disclosure
Security researchers: security@tryspotx.com · PGP key on request · 30-day disclosure window.
Availability
Ingest runs on a multi-vendor RPC mesh with active failover on every supported chain, so a single provider outage degrades freshness rather than dropping your feed. We are pre-GA on formal uptime commitments: we do not yet publish a contractual SLA, and we would rather say so than quote a number we can't evidence. Desk-tier agreements can include a negotiated availability target.
Sub-processors
AWS (compute, storage), Cloudflare (edge), Stripe (payments), Postmark (transactional email). Full DPA on request.