Security

Security at KOLHub

Trust is our product — here is how we protect funds, data and identities.

Escrow contracts

Deal budgets are held by the KolEscrow smart contracts on Base, BSC, Solana and Tron. Contracts follow checks-effects-interactions, use reentrancy guards and pausability, and every state change emits an on-chain event. An internal multi-track audit has been completed; an independent third-party audit is scheduled before mainnet.

No custodial funds

There is no platform wallet holding user money. Release paths are fixed in the contract: mutual approval, auto-release, mutual cancellation or an arbiter ruling. Platform service fees for optional plans are simple wallet-to-address transfers, verified on-chain.

Data protection

Hidden-profile identities are masked server-side and never sent to the client. Sensitive documents — KYB files, dispute evidence, message attachments — live in private storage, reachable only through short-lived signed URLs. Exchange API keys are stored encrypted with AES-256-GCM and are never displayed after entry.

Platform hardening

All inputs are schema-validated server-side; every API route enforces authentication, role checks and rate limits. Anti-scraping protections — request throttling, enumeration quotas and canary profiles — guard the creator directory.

Found a vulnerability? We appreciate responsible disclosure — contact us.

Security at KOLHub · KOLHub