Security & access
Private feeds, controlled access.
CoinPriceFeeds keeps client feeds and private inputs separate, limits who can change pricing state, and keeps management surfaces away from direct public access.
- Client-specific feed and private-source isolation.
- HTTPS dashboard with passwordless, time-limited sign-in.
- Reader and writer roles for live pricing controls.
Isolate client feeds
Rules, quote state, private inputs, and dashboard permissions are kept per client feed.
Limit pricing actions
Viewing and state-changing permissions are separate.
Keep an audit trail
Login and privileged pricing or administrative actions are recorded.
On this page
Client-specific feed boundaries
Every client feed has its own pricing rules, quote state, persisted state, delivery configuration, dashboard, and monitoring identity.
Private liquidity and client-provided prices stay inside the account that owns them. Public reference sources may be shared efficiently, but client data is not treated as a common pool.
One feed’s configuration error is also contained as far as possible so it does not automatically stop every other client feed.
HTTPS dashboard access
Client dashboards are served over HTTPS. Certificate issuance and renewal are managed automatically for provisioned hostnames.
Management access is restricted separately from the public HTTPS dashboard path.
Client operational dashboards remain authenticated and excluded from public search indexing.
Passwordless sign-in
Dashboard users sign in with a time-limited email link. A redeemed link is single-use, and the resulting session works across the provisioned servers for that client.
There is no shared dashboard password for a team to distribute or forget to rotate when staff changes.
Access follows the sharing list of the client’s own pricing-rules sheet. A sharing change takes effect after dashboard permissions are next refreshed.
Reader and writer permissions
A reader can inspect quotes, source relationships, schedules, status, and the loaded configuration.
A writer can also perform actions that may affect live pricing, such as re-reading validated rules or clearing protected quote state.
This role split gives operations and management useful visibility without giving every viewer the ability to change the feed.
Protection for state-changing actions
Dashboard actions that change pricing state require an authenticated user with the appropriate role and are protected against unauthorized browser requests. Access sessions are time-limited.
Access remains resilient
Dashboard access does not depend on a live permissions-provider response for every request. During a temporary provider outage, the last successfully refreshed permission state can remain available instead of being replaced by an incomplete result.
Privileged actions are logged
Sign-in, sign-out, rules reloads, quote-state resets, and administrative changes are written to the operational log with the requesting user where applicable.
That provides a trace when a team needs to answer who requested a change and when it occurred.
What a security review should cover
A useful review follows the actual client connection rather than relying on a generic checklist. The public compatibility matrix identifies the connection categories; the private review should then confirm the boundaries that apply to the proposed scope.
Swipe or scroll horizontally to see all columns
| Review area | Public overview | Confirmed for a client scope |
|---|---|---|
| Data flow | Authorized sources enter a client-specific pricing layer and controlled outputs leave it | Exact source and destination owners, network direction, protocols, and environments |
| Access | Dashboard readers and writers have separate capabilities | Named access owners, permission refresh, removal, and escalation process |
| Isolation | Private inputs, pricing rules, quote state, and delivery configuration are separated by client feed | The feeds, shared public-reference inputs, and deployment boundaries in scope |
| Change control | Validated rules can be loaded and the active content fingerprint can be checked | Who may approve, apply, verify, and roll back a production change |
| Monitoring | Quote activity, delay, consumers, invalid states, and endpoint agreement can be observed | Alert recipients, thresholds, maintenance communication, and acceptance evidence |
| Third parties | Source providers and platforms remain under their own terms | Client entitlements, required vendors, subprocessors where applicable, and responsibility boundaries |
Production credentials, private hostnames, access lists, detailed topology, and client-specific evidence are not published on this website. They are exchanged with the authorized client team through an agreed private route when they are needed for review.
Procurement and contractual questions
Security questionnaires, data-processing requirements, support boundaries, maintenance communication, evidence requests, and availability terms depend on the service being proposed. This page does not claim a certification, audit report, DPA, SLA, or support response time that has not been agreed.
Start with the demo request form . Mandatory procurement documents and contractual requirements can then be listed in the written reply. CoinPriceFeeds can confirm what is available and what applies to that scope before either side treats it as a requirement.
Report a security concern
Email support@coinpricefeeds.com with the subject “Security report.” Do not include working credentials, private keys, personal data, or exploit details in that first message. A suitable private written route can then be established for the technical material.
A feed shaped around your setup
Start a written security and integration review.
Open the short form. We’ll ask by email about network direction, access roles, isolation needs, and any required private documentation.