Trust & Safety
Security Overview
Frontdeploy is a non-custodial Chrome extension. We never hold your private keys, never move your funds, and never sign transactions without your explicit approval.
Non-Custodial
Your private key never leaves your wallet. Frontdeploy builds unsigned transactions and sends them to Phantom, Solflare, or Backpack — you approve each one manually in the wallet popup.
Read-Only Intelligence
All intel features (rug scan, flow radar, KOL alerts, CA check) only read public on-chain data via Solana RPC and the X/Twitter public API. No write access to your funds.
User Approval Required
Every on-chain action — token creation, dev buy — requires your explicit approval in a wallet popup. There is no auto-sign, no silent signing, no background transactions.
Local Activity Log
The “Activity” tab in the extension logs every action you take — locally in chrome.storage.local. This data is never sent to our servers.
Signing Flow
How a token launch works — your private key never leaves your wallet.
You click “Fast Launch” or “Dev Buy” in the extension.
We prepare the transaction data (UNSIGNED) via PumpPortal API.
Phantom, Solflare, or Backpack opens and asks you to review and sign.
The signed transaction is broadcasted securely to the blockchain.
Modules like Rug Scan, KOL Alerts, and Flow Radar only read from Solana RPC and X API. They never request signatures or write access.
Data We Send
Transparent list of every data point that leaves your device.
| Data | Destination | Reason |
|---|---|---|
| Wallet address (public key) | Our backend | Verify $FDP holder tier |
| Token metadata (name, symbol, description, image) | Pinata or Pump.fun IPFS | Upload token metadata for launch |
| Public key + token parameters | PumpPortal API | Build unsigned create/buy transaction |
| User-configured Pinata JWT | Pinata API | Authenticate your personal IPFS uploads (your own key) |
What We Never Send
- Private key or seed phrase
- Wallet balance or token holdings
- Activity log (stored locally only)
- Any data without your action triggering it
Chrome Permissions
Every permission we request and why.
What Frontdeploy CANNOT Do
We cannot initiate any transfer without your approval in your wallet.
We never request these. Signing happens inside your wallet software.
Every transaction shows a confirmation prompt in your wallet.
All launch features require you to connect your wallet first.
Report a Vulnerability
Found a security issue? Please report it responsibly via X DM to @frontdeployx before public disclosure. We will respond promptly.