your 12-word recovery phrase is generated in your browser, encrypted there with a key derived from your password, and only the encrypted result is ever sent to iP2P’s servers. we cannot decrypt it — only you can, with your password.
every escrow trade uses a 2-of-3 multisig address. iP2P’s key alone can never move funds — it only becomes useful together with one of the trading parties’ keys, and only in a dispute.
before you sign a release or refund transaction, your browser independently reconstructs it from the public keys involved and shows you the real destination and amount. this check happens locally — it doesn’t depend on trusting our servers.
you can require a time-based one-time code on login, with one-time recovery codes generated for backup. disabling 2fa takes effect 48 hours after the request and is reported by email, so an attacker can’t quietly turn it off.
new device logins, password changes, 2fa changes, and recovery-phrase-based account recovery all trigger an immediate security notification — sent by email regardless of your notification settings.
revealing a wallet’s private key requires an acknowledgment step and is never available by accident.