Trust & Safety

Security Overview

Frontdeploy is a non-custodial Chrome extension. We never hold your private keys, never move your funds, and never sign transactions without your explicit approval.

Non-Custodial

Your private key never leaves your wallet. Frontdeploy builds unsigned transactions and sends them to Phantom, Solflare, or Backpack — you approve each one manually in the wallet popup.

Read-Only Intelligence

All intel features (rug scan, flow radar, KOL alerts, CA check) only read public on-chain data via Solana RPC and the X/Twitter public API. No write access to your funds.

User Approval Required

Every on-chain action — token creation, dev buy — requires your explicit approval in a wallet popup. There is no auto-sign, no silent signing, no background transactions.

Local Activity Log

The “Activity” tab in the extension logs every action you take — locally in chrome.storage.local. This data is never sent to our servers.

Signing Flow

How a token launch works — your private key never leaves your wallet.

1
You Initiate Action

You click “Fast Launch” or “Dev Buy” in the extension.

2
Frontdeploy Builds Transaction

We prepare the transaction data (UNSIGNED) via PumpPortal API.

3
Your Wallet Prompts Approval

Phantom, Solflare, or Backpack opens and asks you to review and sign.

Private key never leaves your wallet
4
Solana Network

The signed transaction is broadcasted securely to the blockchain.

Read-Only Intelligence Flow
Public Data Access Only

Modules like Rug Scan, KOL Alerts, and Flow Radar only read from Solana RPC and X API. They never request signatures or write access.

Data We Send

Transparent list of every data point that leaves your device.

DataDestinationReason
Wallet address (public key)Our backendVerify $FDP holder tier
Token metadata (name, symbol, description, image)Pinata or Pump.fun IPFSUpload token metadata for launch
Public key + token parametersPumpPortal APIBuild unsigned create/buy transaction
User-configured Pinata JWTPinata APIAuthenticate your personal IPFS uploads (your own key)

What We Never Send

  • Private key or seed phrase
  • Wallet balance or token holdings
  • Activity log (stored locally only)
  • Any data without your action triggering it

Chrome Permissions

Every permission we request and why.

storage

Save your settings, wallet session, and activity log locally.

sidePanel

Show the Frontdeploy side panel when you click the extension icon.

scripting

Inject the wallet relay content script into pump.fun to forward signing requests to your wallet.

tabs

Open pump.fun/create and communicate with the relay tab during a launch.

notifications

Alert you when a KOL event is detected (optional).

alarms

Schedule periodic background checks (e.g. for new KOL events).

What Frontdeploy CANNOT Do

Move your funds

We cannot initiate any transfer without your approval in your wallet.

Access your private key or seed phrase

We never request these. Signing happens inside your wallet software.

Sign transactions silently

Every transaction shows a confirmation prompt in your wallet.

Operate without your wallet connected

All launch features require you to connect your wallet first.

Report a Vulnerability

Found a security issue? Please report it responsibly via X DM to @frontdeployx before public disclosure. We will respond promptly.