Security
The controls we run today. We do not claim certifications we do not hold.
- Encrypted connections
- All traffic uses HTTPS and sessions use secure, HTTP-only cookies.
- Strong sign-in protection
- Passwords are stored with a modern one-way hash, sign-ins are rate limited, and repeated failures lock the account temporarily.
- Two-factor authentication
- Optional authenticator-app 2FA with one-time recovery codes. Withdrawals and large transfers need a confirmation code.
- Session management
- See every signed-in device and sign any of them out. Changing your password signs out the others.
- Transaction monitoring
- Withdrawals can be held for manual review based on risk signals such as new accounts or recent security changes.
- Audit logging
- Sensitive actions by users and staff are written to an append-only audit log.
- Identity verification
- Documents are scanned, stored privately and accessed only through short-lived links by authorised staff.
We will never ask for your password, one-time codes, seed phrase or private keys.