Security

Protection designed for financial infrastructure

Security controls are enforced by the platform itself, so your data stays scoped to your account regardless of how it is accessed.

Authentication

Credentials are hashed and never stored in plain text. Sessions are managed centrally, email verification is required, and two-factor authentication can be enabled on any account.

Transport & encryption

All traffic is served over HTTPS. Sensitive identity information is stored in a private area that is not reachable from public URLs.

Access control

Row-level access rules mean your records are only readable by you and, where legally necessary, by compliance staff. Roles separate super admin, admin, compliance, support and customer permissions.

Withdrawal protection

Withdrawal addresses can be labelled, whitelisted and set as default. Withdrawals require an explicit confirmation step, plus 2FA where enabled.

Transaction monitoring

Deposits are tracked by transaction hash and confirmation count. Statuses move from pending through confirming to completed, and every change is recorded.

Audit logging

Administrative actions write an immutable log entry with the acting administrator, the target account, timestamps, device information and previous and new values.

What we never do

  • • We never ask for your seed phrase or private keys, and we do not store them.
  • • We never publish your identity documents or expose them at a public URL.
  • • We never display fabricated balances, profits, blockchain transactions or payment confirmations.