Security
Protection designed for financial infrastructure
Security controls are enforced by the platform itself, so your data stays scoped to your account regardless of how it is accessed.
Authentication
Credentials are hashed and never stored in plain text. Sessions are managed centrally, email verification is required, and two-factor authentication can be enabled on any account.
Transport & encryption
All traffic is served over HTTPS. Sensitive identity information is stored in a private area that is not reachable from public URLs.
Access control
Row-level access rules mean your records are only readable by you and, where legally necessary, by compliance staff. Roles separate super admin, admin, compliance, support and customer permissions.
Withdrawal protection
Withdrawal addresses can be labelled, whitelisted and set as default. Withdrawals require an explicit confirmation step, plus 2FA where enabled.
Transaction monitoring
Deposits are tracked by transaction hash and confirmation count. Statuses move from pending through confirming to completed, and every change is recorded.
Audit logging
Administrative actions write an immutable log entry with the acting administrator, the target account, timestamps, device information and previous and new values.
What we never do
- • We never ask for your seed phrase or private keys, and we do not store them.
- • We never publish your identity documents or expose them at a public URL.
- • We never display fabricated balances, profits, blockchain transactions or payment confirmations.