Security

Never share a private key. Anyone with it can take the funds. Onboard cannot recover a wallet if you lose the key after revealing it.

What we store

Encrypted private keys only. The encryption key is not in PostgreSQL. Keys are never logged, never sent to analytics, and never returned from ordinary API responses.

What we cannot do

After a Pons launch, the creator recipient is on-chain. Onboard cannot secretly redirect those rewards. Verify addresses on the explorer. Use a hardware or software wallet after import if you want that extra control.

Pons audits

Pons V2 reviews were still in progress at integration time. Treat the protocol as you would any early mainnet system.