Trust Pillars
Non-custodial
Your private keys never leave your wallet. We cannot access your funds.
Client-side signing
All transactions are signed in your browser. We never see your seed phrase.
Transparent fees
Every fee is shown before you sign. No hidden charges.
No data collection
No PII, no trackers, no cookies. See our Openistic Pledge below.
Verified RPCs
We use Helius, proxied server-side so API keys never reach your browser.
Arweave storage
Token metadata is stored permanently on Arweave via Irys.
Pledges & Frameworks
Openistic Pledge
No-save, no-sell, tracker-free, local-first.
Responsible Disclosure
Report vulnerabilities to security@createsolana.com. Safe harbor for good-faith researchers.
SEAL Whitehat Safe Harbor
Framework for whitehat intervention during active exploits.
OpenSSF Baseline Level 1
OpenSSF Best Practices Badge — Baseline Level 1 achieved (100%).
Security Measures Implemented
- Strict-Transport-Security (HSTS) enforced
- X-Frame-Options: DENY (clickjacking protection)
- X-Content-Type-Options: nosniff
- Content-Security-Policy (CSP) headers
- Referrer-Policy: strict-origin-when-cross-origin
- Permissions-Policy restricting camera, microphone, geolocation
- Rate limiting on sensitive endpoints
- Input validation on all transaction parameters
- Transaction simulation before signing
- Fee wallet verification on every transaction
- npm audit in CI for known vulnerabilities
- No third-party trackers or analytics
How Transactions Work
You connect your wallet (Phantom, Solflare, or Coinbase). The wallet stays in your browser.
You fill in the tool form. CreateSolana builds the transaction locally and shows you a preview (fee, accounts, amounts).
CreateSolana simulates the transaction before asking you to sign. If simulation fails, you are warned.
Your wallet asks you to approve. The signing happens in your wallet — CreateSolana never sees the private key.
The signed transaction is broadcast to Solana. CreateSolana shows you the signature and a link to Solscan.
Found a Vulnerability?
Report it responsibly and we will fix it fast. See our Responsible Disclosure Policy.
security@createsolana.com