Security
Enterprise-grade security. By default.
Institutional MPC custody, 95% cold storage, end-to-end encryption, and a real-time risk engine — every layer engineered to protect your assets and your data, around the clock.
Protection
Eight layers. All active, all the time.
Cobo MPC Custody
Institutional-grade MPC wallet custody via Cobo. Private keys are split with threshold cryptography — never reconstructed in a single location, eliminating single-point-of-failure risk.
App-Based 2FA
Two-factor authentication via TOTP authenticator app, with encrypted backup codes. SMS-based 2FA is deliberately disabled — it's the weakest link in account security.
Withdrawal OTP
Every withdrawal clears a multi-stage internal risk check, a time-sensitive one-time code, and an email confirmation. No single channel can approve a transfer alone.
95% Cold Storage
The overwhelming majority of client assets are held in air-gapped cold storage, isolated from internet-connected systems and inaccessible to live application infrastructure.
DDoS & WAF Protection
Enterprise-grade distributed denial-of-service mitigation and a web application firewall sit in front of every public endpoint, blocking volumetric attacks before they reach the platform.
24/7 Security Support
A dedicated security and support team monitors the platform around the clock. Reach a real person by live chat or email — any time, any day.
End-to-End Encryption
All data is encrypted in transit with TLS 1.3 and at rest with AES-256. Sensitive fields receive additional envelope encryption before they ever reach the database.
On-Chain Proof of Reserves
Cryptographic attestations confirm that client balances are backed 1:1 by verifiable on-chain holdings — no fractional-reserve exposure.
Standards
Institutional standards, applied rigorously.
Multi-Party Approvals
Withdrawals and sensitive configuration changes require independent sign-off from multiple credentialed signatories. No single employee can unilaterally move funds.
Penetration Testing
External red-team assessments are conducted regularly by independent security firms. Critical findings are remediated before the next release cycle.
AML / KYC Compliance
Onboarding is backed by automated identity verification, sanctions screening, and ongoing transaction monitoring in line with international AML standards.
Real-Time Risk Engine
Open positions are monitored continuously. Automated safeguards trigger warnings at 70% margin utilisation, restrictions at 85%, and force-close at 95% — protecting both the user and the platform.
Immutable Audit Logs
Every privileged action — logins, withdrawals, configuration changes — is written to append-only audit logs retained for a minimum of five years, available for regulatory review.
Vulnerability Disclosure
A responsible disclosure programme allows independent security researchers to report findings through a structured process. Valid reports receive timely acknowledgement and remediation.
Built for institutions. Open to everyone.
The same enterprise-grade custody, encryption, and compliance infrastructure used by professional trading desks — available from the moment you open an account.