Unguessable access keys
Each room issues two long random keys — one for the party who opened it, one single-use invite for the counterparty. Keys cannot be derived from the room address.
Security
Access control, not obscurity. Every request for deal data is authorised on the server against a key that only you hold.
Each room issues two long random keys — one for the party who opened it, one single-use invite for the counterparty. Keys cannot be derived from the room address.
Once the invite has been used, the room is closed. A second attempt to join with the same link is refused; the room is permanently limited to buyer, seller and pokz.
No browser can read deal data directly. Every read and write passes through server-side checks that validate the key before any record is returned.
All traffic runs over HTTPS. pokz collects a display name and the transaction details you write — no accounts, no passwords, no unnecessary identifiers.
No online service can promise absolute security. pokz applies proportionate technical and organisational measures and describes data handling in full in the Privacy Policy.