Holdfast Private Beta

Security

Last updated: 7 October 2026

Holdfast is Valigator's non-custodial Solana stake manager. Your keys stay on your hardware wallet, and we take the security of everything around them seriously. This page explains how to report a vulnerability and lists the independent audits Holdfast has completed.

Reporting a vulnerability

If you believe you have found a security vulnerability in Holdfast or any Valigator service, please email us at security@valigator.tech. Please include:

We will acknowledge your report within three business days, keep you updated as we investigate, and let you know when a fix ships.

Guidelines

To keep users safe while we investigate, we ask that you:

Security audits

Holdfast is reviewed by independent security firms. Full reports are published below.

Related

See how to verify your copy of Holdfast, reach the team on our contact page, or return to the Holdfast home page.