Security
Last updated: 13 September 2026
Shingan is a security tool, so it is built to hold as little power over your funds as possible. Here is exactly what that means, and where the limits are.
The core promise
- Non-custodial. We never ask for, receive or store private keys or seed phrases.
- Read-only. Shingan observes public chain data. It cannot sign, send or move anything.
- You sign everything. Any revoke is prepared for you and executed by your own wallet.
What Shingan can do
- Read the public addresses you connect and the activity on them.
- Alert you on Telegram, and help you build revocation transactions.
- Store your Telegram ID, connected addresses, detected events and plan records.
What Shingan cannot do
- Access or move your funds.
- Sign a transaction on your behalf.
- Give you back a Telegram account you have lost.
Threat model
We design against: an attacker who compromises our servers (they should gain no keys, because we hold none); a malicious or compromised dapp you interact with (Shingan surfaces the approval and scores the spender); and a drainer that moves funds (Shingan alerts on the outflow).
We do not claim to prevent every loss. Monitoring is best-effort and can be delayed or incomplete. See the Risk Disclosure.
Data & privacy
Minimal by design: a Telegram ID and public addresses. No KYC, no email required, no tracking cookies. See the Privacy Policy.
Dependencies
The service relies on external providers — Telegram (messaging), blockchain data providers, threat intelligence, and an LLM for the assistant. Their outages can interrupt or degrade the service.
Report a vulnerability
If you believe you have found a security issue, please contact us via the bot before disclosing it publicly. We take reports seriously and will credit responsible disclosure.
