Vari ("we", "us", "our") provides full-stack security reviews for crypto and DeFi projects. This policy covers varireview.com and its pages (the "Site"), including the request form and the Hash Verifier tool. Paid security-review engagements are additionally governed by the written agreement — and any NDA — we sign with each client; where that agreement is more specific about how we handle your code and materials, it controls.
When you submit the "Request review" form, we receive what you enter: your name or handle; your contact (email address or Telegram handle); your dApp URL; links to your dApp, smart-contract, and indexer repositories; the project profile you select; an optional confirmation that you invited our GitHub account to your repositories; and whatever you write in the free-text field. Everything in that box comes to us — share only what you're comfortable sending.
If you invite our GitHub account (VARI-Review) as a read-only collaborator, or otherwise share source code, configuration, deployment details, or documents, we access and analyze those materials to scope and perform your review. We treat them as confidential, use them only to do the work you asked for, and don't publish anything identifying you without your permission. You can revoke our repository access at any time.
As with any website, when you visit, our hosting and font providers receive standard technical data — your IP address, browser type, and the time of the request — in ordinary server logs, used only to serve the Site and keep it secure. We do not run analytics or advertising trackers, and we do not build a profile of you.
We store two small values in your browser's local storage: your light/dark theme preference and a one-time flag that skips the intro animation on repeat visits. These stay on your device, are never sent to us, and are not advertising cookies.
The Hash Verifier at /verify runs entirely in your browser. Anything you paste into it — transaction data, hashes, signing payloads — is processed locally on your device and is never transmitted to us or to anyone else. It works with your network disconnected.
We use what you give us to respond to your request and prepare a quote; to perform and deliver the review you engage us for; to communicate with you about the work; to keep records we need for legitimate business and legal purposes; and to comply with applicable law. We do not sell or "share" your personal information (as those terms are used under California law), and we don't use it for third-party advertising.
We keep this list short on purpose. The Site relies on these service providers ("subprocessors"), each processing data only to provide its function:
That is the whole list. There are no analytics vendors, ad networks, tracking pixels, or data brokers involved.
Our security-review methodology combines automated, AI-assisted analysis with human review — AI covers breadth, and a human validates every finding. This applies to the materials you provide once you engage us, not to visitors of this website: submitting the request form does not run your input through an AI model, and the Hash Verifier uses no AI at all.
When we perform a review, portions of your materials may be processed through AI-assisted tooling. Where that tooling is operated by a third-party model provider, that provider processes your materials solely to return analysis to us, under confidentiality terms, and does not use your materials to train its models. We do not use your code or materials to train any publicly available AI model. The specific tooling and providers used for your engagement are named in, and governed by, your engagement agreement — ask us and we'll tell you exactly what we use before you share anything sensitive.
We keep request-form submissions only as long as we need them to respond to you and, if you engage us, for the duration of the engagement plus a reasonable period for our records. Review materials are handled under your engagement agreement and returned or deleted on completion per that agreement. We don't keep personal information longer than we need it, and we'll delete your information on request (see Your rights).
You have the right to know what personal information we hold about you, to access it, to correct it, to delete it, and to opt out of the sale or sharing of your personal information. We do not sell or share personal information, so there is nothing to opt out of — but you can exercise the other rights at any time by contacting us, and we won't discriminate against you for doing so.
If you're in the EEA or UK, you also have rights to access, rectification, erasure, restriction, portability, and objection. Our legal bases are your consent (when you contact us), our legitimate interest in running our business, and performance of our contract with you. You may lodge a complaint with your local data-protection authority.
To exercise any right, contact us using the details below. We may need to verify your identity before we act on a request.
We use reasonable technical and organizational measures to protect your information, including encryption in transit (HTTPS) and least-privilege access to submissions and client materials. No system is perfectly secure and we can't guarantee absolute security — but we don't collect more than we need, which is the strongest protection of all.
The Site and our services are intended for businesses and professional users. They are not directed to anyone under 18, and we do not knowingly collect personal information from minors.
We operate from and process data in the United States. If you contact us from another country, you are sending your information to the US.
If we change this policy, we'll update the date at the top and, for material changes, note them on this page. Continued use of the Site after a change means you accept the updated policy.
Questions or requests about privacy: Telegram @va_rinder, or email privacy@varireview.com.