Yes, you understood correctly. Our API will have access to the wallet and the funds inside it, but only when the user activates it. The seed phrase will be stored in encrypted operational memory, and if the user stops the service, the decrypted seed phrase is not saved anywhere.
This is a problem because at some point a third party has access to the assets. Users need to trust you as beginners and hope that nothing will go wrong.
You will probably have to open the source code in order to test it and confirm that there is nothing malicious inside. For me, this is a red flag
If the check indicates that the funds are problematic, we notify the user, and the funds remain in the transit wallet.
What is a transit wallet? Shouldn't funds be returned to the user if they don't meet your platform's criteria?
As we mentioned to examplens, we are currently a startup, which is why our website and logo are still under development. Our goal is to find our first clients whom we will serve for free, tailoring our product to their needs for improvement.
It is unclear why you rushed to present an incomplete platform, even though you did not correct the obvious flaws. How can we be sure that you haven't made similar mistakes where it's even more important, wallet code, API... Quite an amateur start.
Thank you for your detailed feedback. We appreciate the opportunity to clarify these issues.
We strive to create a platform that meets the highest standards of security and reliability. Your input is crucial in this process. As LinkedIn co-founder Reid Hoffman said, "If you are not embarrassed by the first version of your product, you've launched too late."
1. **Access to Wallet and Funds**:
- As mentioned earlier, you can set up a co-signer on your side. In this case, we will not have access to the seed phrase at all. All transactions will be signed on your side, allowing the client to verify and confirm each transaction independently. We will only provide notifications about incoming transactions and the results of AML checks. However, since this might not be convenient for everyone due to the need for an additional server on the client’s side, we offer the client the choice.
2. **Transit Wallet**:
- The transit wallet is derived from the client's seed phrase and is under their control. If funds are found to be problematic, we simply provide the information, and the client decides whether to return the incoming funds to their sender or hold them. We do not hold any funds on our side at all.
3. **Startup Development Stage**:
- As a startup, we are in the early stages of our journey. We chose to present our platform to gather feedback and continuously improve it. While our website and logo are still under development, our core functionalities are robust and secure.
- We take all feedback seriously and strive to address any identified flaws promptly. Our goal is to build a secure and reliable platform, and we are continuously working to enhance our services.
Thank you for your patience and understanding as we work to improve our platform.