Security at Wallion

Your security.
In your hands.

Ownership comes with choices. Understand the protection around your wallet, the access you give and the decisions that stay with you.

Know your protection
An open blue and white vault with a key shaped around Wallion’s opposing brackets.

International standards

Security and privacy.
Clear standards for both.

A-LIGN ISO 27001 Certified

ISO/IEC 27001

Information security
management.

Our information security management system is certified to ISO/IEC 27001. The standard connects the people, processes and technology behind Wallion.

Explore the ISO standard

Identify the risks.

Assess information security risks and decide how to address them.

Make ownership clear.

Define responsibilities and document the controls that support them.

Keep improving.

Review the system as threats, technology and organizational needs change.

A-LIGN ISO 27701 Certified

ISO/IEC 27701

Privacy information
management.

Our privacy information management system is certified to ISO/IEC 27701. The standard addresses how organizations manage personal information and take responsibility for its processing.

Explore the ISO standard

Understand the data.

Identify personal information, the purpose for processing it and the privacy risks involved.

Define responsibilities.

Set clear duties for the people and organizations handling personal information.

Review privacy practices.

Maintain and improve the management system as data use and organizational needs evolve.

Three kinds of access

Different layers.
Clear boundaries.

A device lock, a recovery method and a service permission each have a different job. Knowing the difference helps you stay in control.

01

The device
you use.

Your configured lock protects access to the wallet on that device. It is the boundary around your everyday interaction with the app.

Local access

A device password and a recovery secret serve different purposes.

02

Your way
back in.

Your recovery method lets you restore access to the same wallet. Prepare the required backup privately, before you need to rely on it.

Wallet recovery

Support cannot recreate missing private keys or a lost recovery secret.

03

The access
you allow.

A connection or approval defines how a service can interact with your wallet. Understand its scope before letting an app act on your assets.

Service permissions

Disconnecting a website does not automatically revoke a token allowance.

Before you approve

A moment to check.
A clearer decision.

Match the actual request to what you came to do. A familiar name or a convincing screen is only the beginning.

Understand transactions
  1. Check the destination.

    Verify the full address through a trusted source. Confirm the asset, network and any required memo.

  2. Read what you authorize.

    Check the amount and spender. A transfer, a token allowance and a message signature can give different kinds of authority.

  3. Follow the result.

    A pending transaction may still complete. A failed one may still use gas. Check the network result before deciding what to do next.

If something changes

Find the issue.
Take the right step.

A lost device, an exposed secret and an unwanted approval need different responses. Start with the access that may be affected.

You no longer have the device.

Use your existing recovery plan on a trusted device, then verify the restored accounts. Consider whether someone could access the original device. Recovery depends on having the required backup.

Recovery information was exposed.

Treat the wallet’s authority as compromised. Changing an app password does not invalidate a copied secret. Plan a move to an independently secured wallet; support cannot reverse completed transfers.

A service has too much access.

Identify the network, token and spender. Review and revoke the relevant allowance where supported, allow for the network fee and verify the result.

How token revocation works

Before installing

Start with the source.
Keep the checks.

An app’s name and icon are easy to copy. Open the publisher’s website through a source you already trust, then check where its download link leads. Treat an installer sent in a message as a separate trust decision.

Wallion download options

On macOS

Gatekeeper checks developer identification and whether downloaded software has been altered. Apple’s notarization adds checks for known malicious content. If macOS blocks an app, investigate the warning and the app’s origin before opening it.

Platform guidance: Apple’s guide to opening apps safely.

On Windows

Microsoft Defender SmartScreen evaluates the reputation of downloaded apps and files. Read a warning, verify the source and review your protection settings in Windows Security. A familiar filename alone does not establish who supplied the program.

Platform guidance: Microsoft’s app and browser controls.

Unexpected activity

What appears.
What you trust.

A public address can receive things you never requested. An entry in your history or collection does not establish a trusted relationship with its sender.

An NFT with a claim link.

An unsolicited NFT can carry a website address in its image or description. That site may ask for a secret or a harmful signature under the guise of claiming a reward. Do not follow claim, swap or burn instructions from an unexpected item.

How the pattern works: MetaMask’s NFT airdrop explanation.

A familiar-looking transfer.

Address poisoning places a lookalike address in transaction history, often through a tiny or zero-value transfer. The first and last characters can resemble a known contact while the middle differs. Get the destination from an independently verified record rather than copying the most recent history entry.

How the pattern works: MetaMask’s address-poisoning explanation.

Build your understanding

Your next step
starts with the basics.

Get to know self-custody, private keys and the role of recovery.

Explore self-custody