Docs

DevOps, Observability & Audits

Pipeline, monitoring, audits and responsible disclosure.

CI/CD

Commit → PR → Review → Lint → Unit → Static analysis → Secret scan → Dependency scan
→ Integration → Crypto tests → Build → Security tests → Staging → Manual approval → Production

Observability

  • OpenTelemetry traces, structured logs, metrics
  • RPC health, API, transaction-failure and provider availability monitors
  • Security alerting and crash reporting with secret redaction

Audits before launch

  • Wallet core, mobile apps, extension
  • Backend & infrastructure
  • Swap, bridge and any smart contracts

Bug bounty

  • security@wafiwallet.com security contact
  • Disclosure policy and safe harbour
  • Severity: Critical (fund loss) / High / Medium / Low
  • Acknowledge within 48 h, triage within 5 days

Items marked NATIVE must be implemented as audited native code (Swift, Kotlin, Rust or C++), not in the web app.