Back to Approval Layer

Security Information

Security Information

Operational security guidance for phishing prevention, device compromise, unauthorized approvals, QR login risks, vulnerability reporting and user-protection procedures.

Effective version

Mainnet readiness version — user security policy

1. General security rule

Never approve a request that you do not recognize.

Never share your Approval Password, Anti-Phishing Code, private keys, seed phrases or device unlock codes.

Use only official SkodriNΩN, NexusNON.ID and non.ID communication channels.

2. Phishing risks

Phishing attempts may imitate login pages, QR codes, support messages or approval requests.

Users should verify domains, request details and Anti-Phishing information before approving anything.

Suspicious requests should be denied and reported to security@skodrinon.com.

3. Social engineering

Attackers may attempt to pressure users into approving requests quickly.

Support will never ask a user to approve an unknown request.

Users should slow down, verify context and deny requests that do not match their own action.

4. Unauthorized approvals

An approval made on the user's registered device may be treated as authorization by the user.

If a user believes an approval was unauthorized, the incident should be reported immediately.

Include Capsule ID, request ID if available, approximate time and device information.

5. Device compromise

If a phone is lost, stolen, malware-infected or accessed by another person, approval access may be at risk.

Users should begin recovery or device replacement and report the issue.

Removing local app data does not delete the Capsule Identity.

6. Vulnerability reporting

Security researchers and users should report suspected vulnerabilities to security@skodrinon.com.

Reports should include a clear description, affected component, reproduction steps if safe and contact information.

Do not exploit, access or damage other users' Capsules or systems.

Official communication channels

Use only official SkodriNΩN communication channels for support, verification, recovery, legal, security or incident-related matters.