adytus

Security

Last updated: July 11, 2026

Draft for review — this document is a template and requires review by qualified legal counsel before launch.

Keeping your account, your money, and your data safe is central to how ADYTUS is built. This page summarizes the measures we use. It is written to be truthful and conservative; where a control is still being finalized we say so.

1. Your money

  • Real money moves in only two places — a flat, published entry fee in, and fixed rank-based prizes out. Everything inside a contest uses play credit with no cash value.
  • Entry fees are held pending settlement in a manner intended to keep them separate from our operating funds. [ESCROW / TRUST ARRANGEMENT — TBD BY COUNSEL]
  • Payments are processed by established third-party providers. We do not store your card details, and card data is handled under the providers’ PCI-DSS obligations.
  • Prizes are paid only to the identity-verified winner.

2. Your account

  • Passwords are stored only in hashed form by our authentication provider — never in plain text.
  • Two-factor authentication (an authenticator-app code) is available and can be enabled under your settings.
  • You can send yourself a secure password-reset link at any time, and manage active security settings from your account.

3. Your data

  • Traffic to the Service is encrypted in transit using TLS.
  • Access to personal and financial data is restricted on a least-privilege basis, and money records are held under strict, server-enforced access controls.
  • Encryption at rest and retention are handled by our infrastructure providers. [ENCRYPTION-AT-REST / PROVIDER CERTIFICATIONS — TBD]
  • How we collect and use personal data is described in the Privacy Policy.

4. Identity and anti-fraud

We verify identity before paying prizes, screen against sanctions lists, and monitor for fraud, multi-accounting, and manipulation. See the AML & Identity Verification Policy and the fair-play rules in the Terms of Service.

5. Integrity of results

Contests are scored by an automated evaluator that runs deterministically and is replayable, under a rubric fixed before the round. This design lets a result be re-verified rather than taken on trust, and lets us detect and reject attempts to manipulate scoring.

6. Reporting a vulnerability

If you believe you have found a security issue, please email security@adytus.com with enough detail to reproduce it. Please do not publicly disclose it until we have had a reasonable chance to respond. We do not pursue good-faith security research that respects user privacy and avoids service disruption. [COORDINATED-DISCLOSURE / BUG-BOUNTY TERMS — TBD]