Docs
DevOps, Observability & Audits
Pipeline, monitoring, audits and responsible disclosure.
CI/CD
Commit → PR → Review → Lint → Unit → Static analysis → Secret scan → Dependency scan → Integration → Crypto tests → Build → Security tests → Staging → Manual approval → Production
Observability
- OpenTelemetry traces, structured logs, metrics
- RPC health, API, transaction-failure and provider availability monitors
- Security alerting and crash reporting with secret redaction
Audits before launch
- Wallet core, mobile apps, extension
- Backend & infrastructure
- Swap, bridge and any smart contracts
Bug bounty
- security@wafiwallet.com security contact
- Disclosure policy and safe harbour
- Severity: Critical (fund loss) / High / Medium / Low
- Acknowledge within 48 h, triage within 5 days
Items marked NATIVE must be implemented as audited native code (Swift, Kotlin, Rust or C++), not in the web app.

