Developer Preview. TradeWave is currently developing software architecture for conditional trade settlement. The platform is in active development and not yet open for commercial transactions. See current status.
TradeWave Bond

Security Review

Security

Architecture review posture and vulnerability reporting process.

Scope

The only asset in scope is this website: a static site served via Cloudflare Pages. There is no live production application, database of customer financial records, authentication system, or active custodial API currently deployed.

Current posture

In its current specification stage, this static site is intentionally minimal with no active user accounts, databases, or third-party tracking scripts to eliminate attack surface. Formal independent code audits and security reviews will precede any live or connected software release.

The site is served over HTTPS only, with HSTS and modern Content Security Policies. It loads no analytics, no tracking pixels, no advertising, and no third-party libraries. The interactive simulator runs client-side in the browser and transmits no data.

Reporting a vulnerability

Email management@tradewave.bond with enough detail to reproduce the issue. A machine-readable version of this contact is published at /.well-known/security.txt per RFC 9116.

We acknowledge valid security inquiries within five business days. We will not pursue legal action against anyone who reports an issue in good faith, and we are glad to credit you publicly for responsible disclosures.

Please do not run high-volume automated vulnerability scanners against this informational site.