Security & access

Private feeds, controlled access.

CoinPriceFeeds keeps client feeds and private inputs separate, limits who can change pricing state, and keeps management surfaces away from direct public access.

  • Client-specific feed and private-source isolation.
  • HTTPS dashboard with passwordless, time-limited sign-in.
  • Reader and writer roles for live pricing controls.

Isolate client feeds

Rules, quote state, private inputs, and dashboard permissions are kept per client feed.

Limit pricing actions

Viewing and state-changing permissions are separate.

Keep an audit trail

Login and privileged pricing or administrative actions are recorded.

Client-specific feed boundaries

Every client feed has its own pricing rules, quote state, persisted state, delivery configuration, dashboard, and monitoring identity.

Private liquidity and client-provided prices stay inside the account that owns them. Public reference sources may be shared efficiently, but client data is not treated as a common pool.

One feed’s configuration error is also contained as far as possible so it does not automatically stop every other client feed.

HTTPS dashboard access

Client dashboards are served over HTTPS. Certificate issuance and renewal are managed automatically for provisioned hostnames.

Management access is restricted separately from the public HTTPS dashboard path.

Client operational dashboards remain authenticated and excluded from public search indexing.

Passwordless sign-in

Dashboard users sign in with a time-limited email link. A redeemed link is single-use, and the resulting session works across the provisioned servers for that client.

There is no shared dashboard password for a team to distribute or forget to rotate when staff changes.

Access follows the sharing list of the client’s own pricing-rules sheet. A sharing change takes effect after dashboard permissions are next refreshed.

Reader and writer permissions

A reader can inspect quotes, source relationships, schedules, status, and the loaded configuration.

A writer can also perform actions that may affect live pricing, such as re-reading validated rules or clearing protected quote state.

This role split gives operations and management useful visibility without giving every viewer the ability to change the feed.

Protection for state-changing actions

Dashboard actions that change pricing state require an authenticated user with the appropriate role and are protected against unauthorized browser requests. Access sessions are time-limited.

Access remains resilient

Dashboard access does not depend on a live permissions-provider response for every request. During a temporary provider outage, the last successfully refreshed permission state can remain available instead of being replaced by an incomplete result.

Privileged actions are logged

Sign-in, sign-out, rules reloads, quote-state resets, and administrative changes are written to the operational log with the requesting user where applicable.

That provides a trace when a team needs to answer who requested a change and when it occurred.

What a security review should cover

A useful review follows the actual client connection rather than relying on a generic checklist. The public compatibility matrix identifies the connection categories; the private review should then confirm the boundaries that apply to the proposed scope.

Swipe or scroll horizontally to see all columns

Review areaPublic overviewConfirmed for a client scope
Data flowAuthorized sources enter a client-specific pricing layer and controlled outputs leave itExact source and destination owners, network direction, protocols, and environments
AccessDashboard readers and writers have separate capabilitiesNamed access owners, permission refresh, removal, and escalation process
IsolationPrivate inputs, pricing rules, quote state, and delivery configuration are separated by client feedThe feeds, shared public-reference inputs, and deployment boundaries in scope
Change controlValidated rules can be loaded and the active content fingerprint can be checkedWho may approve, apply, verify, and roll back a production change
MonitoringQuote activity, delay, consumers, invalid states, and endpoint agreement can be observedAlert recipients, thresholds, maintenance communication, and acceptance evidence
Third partiesSource providers and platforms remain under their own termsClient entitlements, required vendors, subprocessors where applicable, and responsibility boundaries

Production credentials, private hostnames, access lists, detailed topology, and client-specific evidence are not published on this website. They are exchanged with the authorized client team through an agreed private route when they are needed for review.

Procurement and contractual questions

Security questionnaires, data-processing requirements, support boundaries, maintenance communication, evidence requests, and availability terms depend on the service being proposed. This page does not claim a certification, audit report, DPA, SLA, or support response time that has not been agreed.

Start with the demo request form . Mandatory procurement documents and contractual requirements can then be listed in the written reply. CoinPriceFeeds can confirm what is available and what applies to that scope before either side treats it as a requirement.

Report a security concern

Email support@coinpricefeeds.com with the subject “Security report.” Do not include working credentials, private keys, personal data, or exploit details in that first message. A suitable private written route can then be established for the technical material.

A feed shaped around your setup

Start a written security and integration review.

Open the short form. We’ll ask by email about network direction, access roles, isolation needs, and any required private documentation.