Project
Use the scanner securely
Understand the read-only boundary and the information a report can contain.
The public flow is read-only
PeelSignal accepts a public contract address and reads supported sources. It does not ask you to connect a wallet, sign a message, approve a token, deposit funds or submit a recovery phrase.
A receipt link never requires a payment or signature to validate its contents.
Input and source boundaries
The address field accepts a contract address. It does not accept a URL for the server to fetch. Explorer and market requests use fixed provider endpoints. Project identity reads only the reviewed website and GitHub endpoints for an exact profile match.
Discovered website and social links remain unreviewed output. The scanner does not fetch them. Token metadata and source text are untrusted; they cannot change the policy or supply executable page markup. Requests have time and response-size limits and do not follow redirects. Provider secrets belong on the server.
Request controls
The service validates requests and bounds upstream work. Timeouts and source failures remain visible instead of producing a healthy default. Read-only requests can still be rate limited.
A failed request does not establish that a token is malicious. See Source outages.
Report a problem without sharing secrets
When reporting incorrect evidence or a security problem, include the public receipt URL, affected page and enough detail to reproduce the issue. Never include private keys, recovery phrases or identity documents.
A source dispute should identify the authoritative document and contract involved. Corrections affect new observations while the original receipt remains available.
Contact peelsignal@proton.me . Include a public receipt link and reproduction steps; leave secrets out.
Security scope
The scanner is not an exhaustive audit of token code, issuer operations or every connected service. Its supported checks and unknowns are listed in the report and Coverage.