Security
CLAYN security rests on a contract you can inspect, written rules, and limits on admin authority. We do not make claims we cannot prove.
Funds in the contract, not with admins
When the buyer funds a deal, USDT goes into the escrow contract. The contract releases funds only through written paths: buyer approval, auto-release after the review window, a refund, or a dispute decision. No function lets the contract owner move user funds outside those rules, and this is verified automatically on every code change.
Deliverable files
Files are stored encrypted (AES-256-GCM) with a per-file key. A SHA-256 hash is recorded as proof. On verified deals, the buyer can only open files after the deal is verified.
Limited admin roles
Admins only verify deliverables (when requested) and resolve disputes. Admin actions are signed from the admin wallet in the browser — the server never holds keys. Every action is recorded in a hash-chained audit log, and a verifier may not arbitrate a deal they verified.
Audit status
The contract has passed automated static analysis and fuzz/invariant testing. An external audit and a bug bounty program will be announced on this page with a link to the report once complete. Until then, we do not call this contract audited.