Account security controls, review workflows, and audit logging that are actually implemented in the platform today — not marketing claims.
Passwords are hashed with bcrypt (12 rounds) — we never store or can read your plain-text password.
Enable an authenticator-app TOTP code from Profile & Security. Admin accounts require 2FA on every login.
See every active login session with its device and last-seen time, and sign any of them out from your own account.
Every withdrawal request is queued for manual admin review before funds move — nothing pays out automatically.
Every balance-changing action is recorded as a double-entry ledger movement, and sensitive admin actions are written to a separate audit log.
Spot reference prices track public market data by default. Where an admin has taken manual control of a pair's price, that pair is clearly not on the live feed on its own trading screen.
We do not currently hold any security certification, financial license, deposit insurance, or third-party security audit — and we won't claim one until it genuinely exists. Deposits and withdrawals are simulated in the current build; see our Terms of Service for the full operating status.
If you believe you've found a security vulnerability, please tell us before disclosing it publicly. Reach us through Contact.