SECURITY & COMPLIANCE · HOW WE OPERATE

Built by security people. Reviewed before every go-live.

The founders come from cybersecurity; the habits show up in every project: cold storage by default, policy-based signing, least-privilege access, an external audit for anything that holds money, and a written incident process you can show your regulator.

CUSTODY
Cold storage by default
Majority of assets offline; hot balances sized to daily withdrawals; MPC or multi-sig via Fireblocks / BitGo.
KEYS
Policy-based signing
Every withdrawal passes policy checks — limits, whitelists, velocity — before a key is used.
ACCESS
Least privilege, SSO, hardware keys
Named admin users, role-based access, hardware-key MFA for operators, full audit trail.
REVIEW
Security review before go-live
Internal review plus pen-test; external audit for any contract that holds funds.
MONITORING
24/7 on-call
Real-time alerting, transaction monitoring, incident response with a written runbook.
COMPLIANCE
KYC / AML tooling
Sumsub, Onfido, Chainalysis integrated; Travel Rule connectors in compliance packs.
DATA
Encrypted, regional, backed up
Encryption at rest and in transit; data residency in your region; tested restores.
CONTINUITY
Backups & exit
Daily encrypted backups, disaster-recovery plan, and a documented exit so you are never locked in.
WHAT YOU CAN SHOW YOUR REGULATOR
A document pack with every project.
Architecture & data-flow diagrams
Custody & key-management policy
Incident response runbook
Pen-test & audit reports
Access & change-management logs
Business-continuity & backup plan
NEXT STEP
A fixed-scope proposal within a week.
Timeline, price, team — and a private demo environment if you want one.