Solution & Security Brief
What it is
Venum is composable, self-hosted Solana execution infrastructure — RPC, real-time data, and multi-DEX swap routing in one backend, powering wallets, trading apps, and on-chain agents. Non-custodial, and operated in-house end to end.
Why it fits
- Ship wallet, swap, and on-chain features without a multi-month internal build or ongoing node operations.
- Self-hosted across US-East, Europe, and Asia (Singapore) — operated in-house on dedicated hardware.
- Smart routing across 11+ major Solana DEXes from one API, returning unsigned transactions you can inspect before signing.
- Flat-rate pricing — no per-call RPC billing.
Architecture
- Non-custodial by design — Venum builds transactions for client-side signing in your users' wallets; it never holds user keys or funds.
- Composable, inspectable transactions — every instruction is visible before it's signed.
- Multi-region, self-hosted RPC + real-time data streaming (SSE), with geo-routed load balancing.
- Stateless HTTP + SSE API; minimal integration surface.
Security posture
- No custody of user keys or funds; private keys never reach the API.
- Secrets stay server-side and are never echoed to clients; API keys hashed at rest; TLS on all traffic.
- Origin allowlists and layered edge abuse filtering protect frontends.
- Deterministic, inspectable transaction-build path.
Reliability
- Self-hosted, multi-region, with geo-routed load balancing.
- Live latency and service status published at venum.dev/analytics.
- Uptime and SLA commitments are made per contract.
- Support scoped per engagement.
Compliance & data
- No KYC; private keys and seed phrases are never collected.
- Venum processes pseudonymous on-chain data (wallet addresses, balances), technical metadata (IP, API usage), and account details (email, optional name) — as set out in our Privacy Policy.
- EU data residency on the roadmap.
- DPA available; GDPR processor terms and formal certification (ISO 27001 / SOC 2) scoped during contracting.
Commercial
Managed subscription, scoped to the required support and compliance tier. Terms on request.
