Solution & Security Brief
What it is
Venum is composable, self-hosted Solana execution infrastructure — RPC, real-time data, and multi-DEX swap routing in one backend, powering wallets, trading apps, and on-chain agents. Non-custodial, and operated in-house end to end.
Why it fits
- Ship wallet, swap, and on-chain features without a multi-month internal build or ongoing node operations.
- Self-hosted across US-East, Europe, and Asia (Singapore) — operated in-house on dedicated hardware.
- Smart routing across 11+ major Solana DEXes from one API, returning unsigned transactions you can inspect before signing.
- Flat-rate pricing — no per-call RPC billing.
Architecture
- Non-custodial by design — Venum builds transactions for client-side signing in your users' wallets; it never holds user keys or funds.
- Composable, inspectable transactions — every instruction is visible before it's signed.
- Multi-region, self-hosted RPC + real-time data streaming (SSE), with geo-routed load balancing.
- Stateless HTTP + SSE API; minimal integration surface.
Security
Security is a core priority, starting with architecture: Venum is non-custodial by design, so private keys and funds never reach our systems — a compromise cannot move user assets. Swap responses are signed and tamper-evident, every instruction is inspectable before signing, and the build path is deterministic. A secure Web RPC gateway lets clients connect without exposing API keys, with equivalent protection for the core API planned. Production access is least-privilege and audit-logged; API keys are high-entropy random secrets, never logged or echoed to clients; and traffic is TLS-encrypted by default. Origin allowlists and layered edge abuse filtering protect frontends. Account access uses passwordless email authentication, with stronger MFA planned for 2026 and SSO/SAML and role-based access scoped for enterprise engagements. We run an incident response process with breach notification and a disclosure channel (security@venum.dev), and invest further — including independent penetration testing — as we grow.
Reliability
- Self-hosted, multi-region, with geo-routed load balancing.
- Live latency and service status published at venum.dev/analytics.
- Uptime and SLA commitments are made per contract.
- Support scoped per engagement.
Compliance, Legal & Data
Venum operates as a French company with professional and cyber liability insurance. We collect no KYC and never request private keys or seed phrases; processed data is limited to pseudonymous on-chain data (wallet addresses, balances), technical metadata (IP, API usage), and basic account details (email), per our Privacy Policy. A DPA is available and we act as a GDPR-compliant processor, with EU data residency on the roadmap. Formal certifications (ISO 27001 / SOC 2) are pursued as we scale, and requirements can be scoped per engagement.
Commercial
Managed subscription, scoped to the required support and compliance tier. Terms on request.
