Security

How we keep your account and transactions safe.

Two-factor authentication

Enable 2FA in your security settings to protect your account with a time-based one-time password (TOTP). All admin accounts require 2FA.

Encrypted credentials

Account credentials shared during a transfer are encrypted at rest using AES-256 and are only accessible to the intended recipient and our escrow system.

Rate limiting & brute-force protection

Login, registration, and sensitive API endpoints are rate-limited per IP. Repeated failed login attempts trigger a temporary lockout.

Session management

Active sessions are tracked and can be revoked from your security settings. Sessions expire automatically after 30 days of inactivity.

Device fingerprinting & risk scoring

We detect suspicious logins from new devices and unusual patterns. High-risk accounts are flagged for additional review.

KYC identity verification

Identity verification uses liveness detection and document authentication. Verified users have a lower dispute rate.

Responsible disclosure

Found a security issue? Email [email protected] with details. We investigate all reports promptly and will credit researchers who help us improve.